<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Email Alerts behind proxy not sending proper link in Alerting</title>
    <link>https://community.splunk.com/t5/Alerting/Email-Alerts-behind-proxy-not-sending-proper-link/m-p/77464#M1081</link>
    <description>&lt;P&gt;I believe alert_action.conf is the right place, the value you want should be&lt;/P&gt;

&lt;P&gt;hostname = host.domain.com&lt;/P&gt;</description>
    <pubDate>Fri, 31 Dec 2010 06:37:39 GMT</pubDate>
    <dc:creator>jbsplunk</dc:creator>
    <dc:date>2010-12-31T06:37:39Z</dc:date>
    <item>
      <title>Email Alerts behind proxy not sending proper link</title>
      <link>https://community.splunk.com/t5/Alerting/Email-Alerts-behind-proxy-not-sending-proper-link/m-p/77461#M1078</link>
      <description>&lt;P&gt;I have Splunk configured and working behind a proxy.  The goal is to hit "https://splunk/" and have it redirect me to "https://internal.splunk:8000/".  This works fine for the web interface, but not for my email alerts.  I have configured my email settings in the GUI to use the proper hostname, but when I get my email alert, the link goes to "https://splunk:8000/".&lt;BR /&gt;
&lt;BR /&gt;
What setting do I have to change to remove the :8000 from the link Splunk sends me?&lt;/P&gt;</description>
      <pubDate>Tue, 26 Oct 2010 01:53:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Email-Alerts-behind-proxy-not-sending-proper-link/m-p/77461#M1078</guid>
      <dc:creator>mbrunetto</dc:creator>
      <dc:date>2010-10-26T01:53:39Z</dc:date>
    </item>
    <item>
      <title>Re: Email Alerts behind proxy not sending proper link</title>
      <link>https://community.splunk.com/t5/Alerting/Email-Alerts-behind-proxy-not-sending-proper-link/m-p/77462#M1079</link>
      <description>&lt;P&gt;Take a look at your &lt;A href="http://www.splunk.com/base/Documentation/latest/Admin/Alertactionsconf" rel="nofollow"&gt;alert_actions.conf&lt;/A&gt;. You can configure the URL used in the links with &lt;CODE&gt;reportServerURL = &lt;A href="http://blah:1234/" rel="nofollow"&gt;http://blah:1234/&lt;/A&gt;&lt;/CODE&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 26 Oct 2010 01:56:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Email-Alerts-behind-proxy-not-sending-proper-link/m-p/77462#M1079</guid>
      <dc:creator>ftk</dc:creator>
      <dc:date>2010-10-26T01:56:37Z</dc:date>
    </item>
    <item>
      <title>Re: Email Alerts behind proxy not sending proper link</title>
      <link>https://community.splunk.com/t5/Alerting/Email-Alerts-behind-proxy-not-sending-proper-link/m-p/77463#M1080</link>
      <description>&lt;P&gt;When I make the change as specified in ftk's answer it changes the reference to the location of my PDF server, not the "Link to results" link. This is also in alignment with the alert_actions.conf documentation.&lt;/P&gt;

&lt;P&gt;The issue is that the proxy is at link A and the Splunk server resides at link B. The "Link to results" link in the email is to link B (directly to the Splunk server) and not to Link A (the proxy).&lt;/P&gt;

&lt;P&gt;Is there a way to force the email to contain the link to the proxy server?&lt;/P&gt;</description>
      <pubDate>Thu, 30 Dec 2010 23:55:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Email-Alerts-behind-proxy-not-sending-proper-link/m-p/77463#M1080</guid>
      <dc:creator>mmaddo</dc:creator>
      <dc:date>2010-12-30T23:55:57Z</dc:date>
    </item>
    <item>
      <title>Re: Email Alerts behind proxy not sending proper link</title>
      <link>https://community.splunk.com/t5/Alerting/Email-Alerts-behind-proxy-not-sending-proper-link/m-p/77464#M1081</link>
      <description>&lt;P&gt;I believe alert_action.conf is the right place, the value you want should be&lt;/P&gt;

&lt;P&gt;hostname = host.domain.com&lt;/P&gt;</description>
      <pubDate>Fri, 31 Dec 2010 06:37:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Email-Alerts-behind-proxy-not-sending-proper-link/m-p/77464#M1081</guid>
      <dc:creator>jbsplunk</dc:creator>
      <dc:date>2010-12-31T06:37:39Z</dc:date>
    </item>
    <item>
      <title>Re: Email Alerts behind proxy not sending proper link</title>
      <link>https://community.splunk.com/t5/Alerting/Email-Alerts-behind-proxy-not-sending-proper-link/m-p/77465#M1082</link>
      <description>&lt;P&gt;This still seems to add the port at the end of it.&lt;/P&gt;</description>
      <pubDate>Wed, 26 Jan 2011 22:51:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Email-Alerts-behind-proxy-not-sending-proper-link/m-p/77465#M1082</guid>
      <dc:creator>adamw</dc:creator>
      <dc:date>2011-01-26T22:51:48Z</dc:date>
    </item>
    <item>
      <title>Re: Email Alerts behind proxy not sending proper link</title>
      <link>https://community.splunk.com/t5/Alerting/Email-Alerts-behind-proxy-not-sending-proper-link/m-p/77466#M1083</link>
      <description>&lt;P&gt;I just had the same issue, and the only way I could figure it out is to use the following in alert_action.conf:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;hostname=host.domain.com:80 
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;or &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;hostname=host.domain.com:
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;When the URL gets added to the email, you get the following (depending on which one you use):&lt;/P&gt;

&lt;P&gt;&lt;A href="http://host.domain.com:80/app/" rel="nofollow"&gt;http://host.domain.com:80/app/&lt;/A&gt;...
or
&lt;A href="http://host.domain.com:/app/" rel="nofollow"&gt;http://host.domain.com:/app/&lt;/A&gt;...&lt;/P&gt;

&lt;P&gt;Either way, the browsers interpret the URL correctly, but it just doesn't look pretty.&lt;/P&gt;

&lt;P&gt;Hope that helps.&lt;/P&gt;

&lt;P&gt;Cheers,
Ash&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jan 2011 15:46:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Email-Alerts-behind-proxy-not-sending-proper-link/m-p/77466#M1083</guid>
      <dc:creator>herbie</dc:creator>
      <dc:date>2011-01-27T15:46:19Z</dc:date>
    </item>
    <item>
      <title>Re: Email Alerts behind proxy not sending proper link</title>
      <link>https://community.splunk.com/t5/Alerting/Email-Alerts-behind-proxy-not-sending-proper-link/m-p/77467#M1084</link>
      <description>&lt;P&gt;Excellent!  This worked, except I had to use :443 for SSL. Thanks!&lt;/P&gt;</description>
      <pubDate>Fri, 28 Jan 2011 00:04:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Email-Alerts-behind-proxy-not-sending-proper-link/m-p/77467#M1084</guid>
      <dc:creator>mbrunetto</dc:creator>
      <dc:date>2011-01-28T00:04:25Z</dc:date>
    </item>
    <item>
      <title>Re: Email Alerts behind proxy not sending proper link</title>
      <link>https://community.splunk.com/t5/Alerting/Email-Alerts-behind-proxy-not-sending-proper-link/m-p/77468#M1085</link>
      <description>&lt;P&gt;I found a bit of a problem with this, the alerts work perfectly, however for some reason when I have the port set to :80 it makes the Scheduled PDF Reports fail when it tries to generate the PDF. I can't figure out why as the moment, but just thought I'd let you know in case you run into this issue as well.&lt;/P&gt;</description>
      <pubDate>Mon, 14 Feb 2011 10:06:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Email-Alerts-behind-proxy-not-sending-proper-link/m-p/77468#M1085</guid>
      <dc:creator>herbie</dc:creator>
      <dc:date>2011-02-14T10:06:30Z</dc:date>
    </item>
    <item>
      <title>Re: Email Alerts behind proxy not sending proper link</title>
      <link>https://community.splunk.com/t5/Alerting/Email-Alerts-behind-proxy-not-sending-proper-link/m-p/77469#M1086</link>
      <description>&lt;P&gt;hostnames were not properly configured on alerts_actions.conf file that failed to display results for email link results, This was corrected by adding stanza in /opt/splunk/etc/system/local/alert_action.conf:&lt;/P&gt;

&lt;P&gt;[email]&lt;BR /&gt;
hostname = &lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 17:41:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Email-Alerts-behind-proxy-not-sending-proper-link/m-p/77469#M1086</guid>
      <dc:creator>bkondakindi</dc:creator>
      <dc:date>2020-09-28T17:41:18Z</dc:date>
    </item>
  </channel>
</rss>

