<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Search Head Cluster email setting between different SMTP servers in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/Search-Head-Cluster-email-setting-between-different-SMTP-servers/m-p/667229#M17795</link>
    <description>&lt;P&gt;Hello everyone,&lt;/P&gt;&lt;P&gt;Here is the story, we have a search head cluster with three members, lets call them sh1, sh2, sh3. these 3 search heads are not in the same domain/vlan, so each one used to have its own config of the SMTP server. Now we are having issues sending reports from Splunk. and I noticed that all 3 search heads are using just one SMTP server so the emails will not be delivered.&lt;/P&gt;&lt;P&gt;I tried to put the correct config for each search head in .../system/local/alert_actions.conf but still not working.&lt;/P&gt;&lt;P&gt;For now I will try to allow the search heads to communicate with all SMTP servers. but i am not sure it is the best solution.&lt;/P&gt;&lt;P&gt;Is there a config I am missing about the email setting in a search head cluster?&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;</description>
    <pubDate>Thu, 02 Nov 2023 18:22:59 GMT</pubDate>
    <dc:creator>kaboom1</dc:creator>
    <dc:date>2023-11-02T18:22:59Z</dc:date>
    <item>
      <title>Search Head Cluster email setting between different SMTP servers</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Search-Head-Cluster-email-setting-between-different-SMTP-servers/m-p/667229#M17795</link>
      <description>&lt;P&gt;Hello everyone,&lt;/P&gt;&lt;P&gt;Here is the story, we have a search head cluster with three members, lets call them sh1, sh2, sh3. these 3 search heads are not in the same domain/vlan, so each one used to have its own config of the SMTP server. Now we are having issues sending reports from Splunk. and I noticed that all 3 search heads are using just one SMTP server so the emails will not be delivered.&lt;/P&gt;&lt;P&gt;I tried to put the correct config for each search head in .../system/local/alert_actions.conf but still not working.&lt;/P&gt;&lt;P&gt;For now I will try to allow the search heads to communicate with all SMTP servers. but i am not sure it is the best solution.&lt;/P&gt;&lt;P&gt;Is there a config I am missing about the email setting in a search head cluster?&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;</description>
      <pubDate>Thu, 02 Nov 2023 18:22:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Search-Head-Cluster-email-setting-between-different-SMTP-servers/m-p/667229#M17795</guid>
      <dc:creator>kaboom1</dc:creator>
      <dc:date>2023-11-02T18:22:59Z</dc:date>
    </item>
  </channel>
</rss>

