<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Using Wildcards in allowedDomainList in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/Using-Wildcards-in-allowedDomainList/m-p/747221#M22331</link>
    <description>&lt;P&gt;After upgrade to version 9.4 I have attempted to configure a list of acceptable domains for the alert_actions.conf.&amp;nbsp;&lt;/P&gt;&lt;P&gt;My environment has a *wide* variety of acceptable email sub-domains which have the same base.&amp;nbsp;&lt;/P&gt;&lt;P&gt;However, the domain matching appears to the strict and wildcards are not matching. For example, users may have emails like:&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="mailto:a@temp.mydomain.com" target="_blank" rel="noopener"&gt;a@temp.mydomain.com&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="mailto:b@perm.mydomain.com" target="_blank" rel="noopener"&gt;b@perm.mydomain.com&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Setting an allow domain like *.mydomain.com&amp;nbsp; &amp;nbsp;does not match the users and they are removed from alerts and reports.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Does any one have a workaround other than adding every possible sub-domain?&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 29 May 2025 17:53:56 GMT</pubDate>
    <dc:creator>drodman29</dc:creator>
    <dc:date>2025-05-29T17:53:56Z</dc:date>
    <item>
      <title>Using Wildcards in allowedDomainList</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Using-Wildcards-in-allowedDomainList/m-p/747221#M22331</link>
      <description>&lt;P&gt;After upgrade to version 9.4 I have attempted to configure a list of acceptable domains for the alert_actions.conf.&amp;nbsp;&lt;/P&gt;&lt;P&gt;My environment has a *wide* variety of acceptable email sub-domains which have the same base.&amp;nbsp;&lt;/P&gt;&lt;P&gt;However, the domain matching appears to the strict and wildcards are not matching. For example, users may have emails like:&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="mailto:a@temp.mydomain.com" target="_blank" rel="noopener"&gt;a@temp.mydomain.com&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="mailto:b@perm.mydomain.com" target="_blank" rel="noopener"&gt;b@perm.mydomain.com&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Setting an allow domain like *.mydomain.com&amp;nbsp; &amp;nbsp;does not match the users and they are removed from alerts and reports.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Does any one have a workaround other than adding every possible sub-domain?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 29 May 2025 17:53:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Using-Wildcards-in-allowedDomainList/m-p/747221#M22331</guid>
      <dc:creator>drodman29</dc:creator>
      <dc:date>2025-05-29T17:53:56Z</dc:date>
    </item>
    <item>
      <title>Re: Using Wildcards in allowedDomainList</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Using-Wildcards-in-allowedDomainList/m-p/747223#M22332</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/154655"&gt;@drodman29&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/170906"&gt;@livehybrid&lt;/a&gt;&amp;nbsp;has already been explained in the community post linked below — kindly take a look.&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.splunk.com/t5/Splunk-Enterprise/Why-does-my-Email-Allowed-Domain-List-in-Alert-Actions-not-show/m-p/745105" target="_blank" rel="noopener"&gt;Solved: Why does my Email Allowed Domain List in Alert Act... - Splunk Community&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 29 May 2025 18:06:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Using-Wildcards-in-allowedDomainList/m-p/747223#M22332</guid>
      <dc:creator>kiran_panchavat</dc:creator>
      <dc:date>2025-05-29T18:06:40Z</dc:date>
    </item>
    <item>
      <title>Re: Using Wildcards in allowedDomainList</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Using-Wildcards-in-allowedDomainList/m-p/747226#M22333</link>
      <description>&lt;P&gt;Does not answer the question. I know how to set this. I don't want to explicitly list every possible domain. I want a wildcard for the sake of maintenance.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 29 May 2025 18:31:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Using-Wildcards-in-allowedDomainList/m-p/747226#M22333</guid>
      <dc:creator>drodman29</dc:creator>
      <dc:date>2025-05-29T18:31:05Z</dc:date>
    </item>
    <item>
      <title>Re: Using Wildcards in allowedDomainList</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Using-Wildcards-in-allowedDomainList/m-p/747233#M22334</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/154655"&gt;@drodman29&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Unfortunately it isnt possible to use wildcards in the allowedDomainList for emails, check out the following snippet of code where the checks are made:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;        domains.extend(sec.EMAIL_DELIM.split(ssContent['action.email.allowedDomainList']))
        domains = [d.strip() for d in domains]
        domains = [d.lower() for d in domains]
        recipients = [r.lower() for r in recipients]
        for recipient in recipients:
            dom = recipient.partition("@")[2]
            if not dom in domains:
                logger.error("For subject=%s, email recipient=%s is not among the allowedDomainList=%s &amp;gt;
                             % (ssContent.get('action.email.subject'), recipient, ssContent.get('action&amp;gt;
            else:
                validRecipients.append(recipient)&lt;/LI-CODE&gt;&lt;P&gt;This takes the value of&amp;nbsp;allowedDomainList, splits it and converts to lowercase then checks if the second half (the domain) is in the list of domains. There is no regex matching etc so wildcarding isnt possible.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":glowing_star:"&gt;🌟&lt;/span&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Did this answer help you?&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;If so, please consider:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Adding karma to show it was useful&lt;/LI&gt;&lt;LI&gt;Marking it as the solution if it resolved your issue&lt;/LI&gt;&lt;LI&gt;Commenting if you need any clarification&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Your feedback encourages the volunteers in this community to continue contributing&lt;/P&gt;</description>
      <pubDate>Thu, 29 May 2025 19:19:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Using-Wildcards-in-allowedDomainList/m-p/747233#M22334</guid>
      <dc:creator>livehybrid</dc:creator>
      <dc:date>2025-05-29T19:19:01Z</dc:date>
    </item>
    <item>
      <title>Re: Using Wildcards in allowedDomainList</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Using-Wildcards-in-allowedDomainList/m-p/747247#M22335</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/154655"&gt;@drodman29&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;As mentioned by everyone,&amp;nbsp;&lt;/P&gt;&lt;P&gt;The action.email.domain_allowlist setting in alert_actions.conf performs a strict, literal string match against the domain part of the email address. It does not natively support wildcards like *.mydomain.com&lt;/P&gt;&lt;P&gt;So, when you set action.email.domain_allowlist = *.mydomain.com, Splunk is literally looking for an email address like user@*.mydomain.com, which is not a valid email domain format and thus won't match a@temp.mydomain.com or b@perm.mydomain.com&lt;/P&gt;&lt;P&gt;So i believe &lt;STRONG&gt;possible workaround&lt;/STRONG&gt; you can do is Scripted Alert Action options.&lt;BR /&gt;Instead of using the built-in sendemail alert action directly from the Splunk UI for these specific alerts, you configure the alert to trigger a custom script.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Regards&lt;/STRONG&gt;,&lt;BR /&gt;Prewin&lt;BR /&gt;Splunk Enthusiast | Always happy to help! If this answer helped you, please consider marking it as the solution or giving a kudos/Karma. Thanks!&lt;/P&gt;</description>
      <pubDate>Fri, 30 May 2025 04:27:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Using-Wildcards-in-allowedDomainList/m-p/747247#M22335</guid>
      <dc:creator>PrewinThomas</dc:creator>
      <dc:date>2025-05-30T04:27:03Z</dc:date>
    </item>
  </channel>
</rss>

