<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Why are we getting alerts for a disabled user? in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/Why-are-we-getting-alerts-for-a-disabled-user/m-p/591061#M11937</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/244319"&gt;@Mohanveera1&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Login with admin account.&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Go To &lt;STRONG&gt;setting&lt;/STRONG&gt;&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;Server Setting&lt;/STRONG&gt; (under System)&lt;/LI&gt;&lt;LI&gt;Click on&amp;nbsp;&lt;STRONG&gt;Email settings&lt;/STRONG&gt;&lt;/LI&gt;&lt;LI&gt;Check value for&lt;STRONG&gt; "Send emails as" &lt;/STRONG&gt;(under&amp;nbsp;Email Format)&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;You can also disable Alert by doing this:&lt;/P&gt;&lt;P&gt;Setting -&amp;gt;&amp;nbsp;&lt;STRONG&gt;Searches, reports, and alerts&lt;/STRONG&gt;&amp;nbsp;-&amp;gt; &amp;lt;Search alert&amp;gt; -&amp;gt; under ACTION tab -&amp;gt; disable&lt;/P&gt;</description>
    <pubDate>Mon, 28 Mar 2022 11:08:06 GMT</pubDate>
    <dc:creator>dhirendra761</dc:creator>
    <dc:date>2022-03-28T11:08:06Z</dc:date>
    <item>
      <title>Why are we getting alerts for a disabled user?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Why-are-we-getting-alerts-for-a-disabled-user/m-p/591022#M11933</link>
      <description>&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;P&gt;Hi there,&lt;/P&gt;&lt;P&gt;One of my colleague having admin access has created a dashboard for audit to know that who logged into Splunk and how many times does the user login into Splunk for the last 7 days for all the users. One of the users left the organization in January and we deleted the account with admin login and transferred all the knowledge objects to the other user also but Now we are seeing his name in the dashboard and alerts were triggering on his name also. We have again checked the user list but his name was not available, but we are still seeing his name in the alerts and dashboard. Can anyone help me with it…&amp;nbsp;&lt;/P&gt;&lt;P&gt;the search query used for creating the dashboard is&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;index=_internal sourcetype=splunkd_access&amp;nbsp; | timechart span=6h count by user&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The Raw Event displaying while searching the query is:&lt;/P&gt;&lt;P&gt;127.0.0.1 - name of the user* [28/Mar/2022:05:28:17.505 +0000] "POST /servicesNS/nobody/search/saved/searches/Single%20User%20Failed%20Attempt/notify?trigger.condition_state=1 HTTP/1.1" 200 1933 "-" "Splunk/8.1.0 (Linux 4.15.0-1023-azure; arch=x86_64)" - 2ms&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please help me to resolve it and thanks in advance......&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Mon, 28 Mar 2022 07:37:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Why-are-we-getting-alerts-for-a-disabled-user/m-p/591022#M11933</guid>
      <dc:creator>Mohanveera1</dc:creator>
      <dc:date>2022-03-28T07:37:39Z</dc:date>
    </item>
    <item>
      <title>Re: Why are we getting alerts for a disabled user?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Why-are-we-getting-alerts-for-a-disabled-user/m-p/591061#M11937</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/244319"&gt;@Mohanveera1&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Login with admin account.&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Go To &lt;STRONG&gt;setting&lt;/STRONG&gt;&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;Server Setting&lt;/STRONG&gt; (under System)&lt;/LI&gt;&lt;LI&gt;Click on&amp;nbsp;&lt;STRONG&gt;Email settings&lt;/STRONG&gt;&lt;/LI&gt;&lt;LI&gt;Check value for&lt;STRONG&gt; "Send emails as" &lt;/STRONG&gt;(under&amp;nbsp;Email Format)&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;You can also disable Alert by doing this:&lt;/P&gt;&lt;P&gt;Setting -&amp;gt;&amp;nbsp;&lt;STRONG&gt;Searches, reports, and alerts&lt;/STRONG&gt;&amp;nbsp;-&amp;gt; &amp;lt;Search alert&amp;gt; -&amp;gt; under ACTION tab -&amp;gt; disable&lt;/P&gt;</description>
      <pubDate>Mon, 28 Mar 2022 11:08:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Why-are-we-getting-alerts-for-a-disabled-user/m-p/591061#M11937</guid>
      <dc:creator>dhirendra761</dc:creator>
      <dc:date>2022-03-28T11:08:06Z</dc:date>
    </item>
    <item>
      <title>Re: Why are we getting alerts for a disabled user?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Why-are-we-getting-alerts-for-a-disabled-user/m-p/591078#M11942</link>
      <description>&lt;P&gt;hi &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/127036"&gt;@dhirendra761&lt;/a&gt;&lt;/P&gt;&lt;P&gt;Thank you for responding to my query. As per your instruction, i have checked the &lt;STRONG&gt;Send emails as&lt;/STRONG&gt; in Email Settings, and previously we have set a mail id i.e *****@***. For every alerts that is triggered we have given the triggered action as send mail to the receipts. so if an alert triggers we will receive the mail from mail address *****@*** . if i remove the&amp;nbsp;&lt;STRONG&gt;Send emails as (Value)&lt;/STRONG&gt; from the Email settings then we cannot receive the mail. And in the &lt;STRONG&gt;Send emails as (value)&lt;/STRONG&gt; in Email Settings also the mail id is not the user that left the organization its other mail id and there is no relation between these two.&lt;/P&gt;&lt;P&gt;And Next step is to disable the alert, i have reassigned all the knowledge objects of the user that left the organization to my name. And there is no alert on his name to disable it also....&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please help me to get it resolved, Thanks in advance...&lt;/P&gt;</description>
      <pubDate>Mon, 28 Mar 2022 12:07:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Why-are-we-getting-alerts-for-a-disabled-user/m-p/591078#M11942</guid>
      <dc:creator>Mohanveera1</dc:creator>
      <dc:date>2022-03-28T12:07:36Z</dc:date>
    </item>
    <item>
      <title>Re: Why are we getting alerts for a disabled user?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Why-are-we-getting-alerts-for-a-disabled-user/m-p/591082#M11943</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/244319"&gt;@Mohanveera1&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What do you want exactly with alert?&lt;/P&gt;</description>
      <pubDate>Mon, 28 Mar 2022 12:26:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Why-are-we-getting-alerts-for-a-disabled-user/m-p/591082#M11943</guid>
      <dc:creator>dhirendra761</dc:creator>
      <dc:date>2022-03-28T12:26:14Z</dc:date>
    </item>
    <item>
      <title>Re: Why are we getting alerts for a disabled user?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Why-are-we-getting-alerts-for-a-disabled-user/m-p/591084#M11944</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/244319"&gt;@Mohanveera1&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;if you don't want to see his name in the dashboard then change in&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;&amp;lt;SPLUNK_HOME&amp;gt;/etc/apps/&amp;lt;APP_NAME&amp;gt;/default/data/ui/views/*.xml&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;and if you don't want to see alerts were triggering on his name then change in :&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;savedsearches.conf&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;&amp;lt;SPLUNK_HOME&amp;gt;/etc/apps/&amp;lt;APP_NAME&amp;gt;/default/savedsearches.conf &lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;That's it.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Mar 2022 12:31:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Why-are-we-getting-alerts-for-a-disabled-user/m-p/591084#M11944</guid>
      <dc:creator>dhirendra761</dc:creator>
      <dc:date>2022-03-28T12:31:01Z</dc:date>
    </item>
  </channel>
</rss>

