<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Alert Messages Coming from localhost@localdomain in Alerting</title>
    <link>https://community.splunk.com/t5/Alerting/Alert-Messages-Coming-from-localhost-localdomain/m-p/86166#M1205</link>
    <description>&lt;P&gt;I've recently brought up one additional pooled search head to join my original two.  All my search head are version 4.3.4, build 136012.&lt;/P&gt;

&lt;P&gt;Splunk e-mail alerts coming from the new search head have the format "From: &lt;A href="mailto:splunk@localhost.localdomain"&gt;splunk@localhost.localdomain&lt;/A&gt;", while the other two show "From: Splunk Daemon User [&lt;A href="mailto:splunk@searchhead01.full.name.com"&gt;splunk@searchhead01.full.name.com&lt;/A&gt;]". (Or '@searchhead02.' depending on source.  You get the idea.)  &lt;/P&gt;

&lt;P&gt;I do not like &lt;EM&gt;localhost@localdomain&lt;/EM&gt; in the header.  I would rather have the more informative, real name included in the mail header.  My users agree with me, for once.  &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;I've looked through the GUI and not found differences in Manager &amp;gt; System Setting &amp;gt; {General Setting or Email alert settings}.  I've run "find . -type f -exec grep localdomain {} ; -print" and nothing obvious has jumped out at me.  I'll admit I haven't compared everything in all the files, however.&lt;/P&gt;

&lt;P&gt;All three have the same content in .../etc/system/local/alert_actions.conf  (Non-pooled directory, no such file in the pooled area).&lt;/P&gt;

&lt;P&gt;Additionally, I brought up a new search head, that is &lt;EM&gt;not&lt;/EM&gt; pooled, at the same time as the new pooled search head.  (I have a total of four search heads.)  Same version and build.  It also uses the unpreferred "From: &lt;A href="mailto:splunk@localhost.localdomain"&gt;splunk@localhost.localdomain&lt;/A&gt;".  Same settings and version as the new pooled search head.  It is just not pooled.&lt;/P&gt;

&lt;P&gt;All are RHEL 5.7.  All respond correctly to the hostname(1).  hosts(5) files are correct.  /etc/sysconfig/network have "HOSTNAME=" set correctly.  &lt;/P&gt;

&lt;P&gt;I've used mailx(P) on all four to send test messages, from the Splunk user, using the command line. The headers &lt;STRONG&gt;&lt;EM&gt;all&lt;/EM&gt;&lt;/STRONG&gt; come through with the preferred format of "From: Splunk Daemon User [&lt;A href="mailto:splunk@searchhead01.full.name.com"&gt;splunk@searchhead01.full.name.com&lt;/A&gt;]" so I'm convinced it's not sendmail(8) or the operating system causing the problem.  I am not convinced some interaction between the OS and Splunk couldn't cause the problem, however.  But I really believe I've missed something in the Splunk configuration on the new boxes.&lt;/P&gt;

&lt;P&gt;What am I missing?&lt;/P&gt;</description>
    <pubDate>Fri, 05 Apr 2013 16:06:37 GMT</pubDate>
    <dc:creator>I_am_Jeff</dc:creator>
    <dc:date>2013-04-05T16:06:37Z</dc:date>
    <item>
      <title>Alert Messages Coming from localhost@localdomain</title>
      <link>https://community.splunk.com/t5/Alerting/Alert-Messages-Coming-from-localhost-localdomain/m-p/86166#M1205</link>
      <description>&lt;P&gt;I've recently brought up one additional pooled search head to join my original two.  All my search head are version 4.3.4, build 136012.&lt;/P&gt;

&lt;P&gt;Splunk e-mail alerts coming from the new search head have the format "From: &lt;A href="mailto:splunk@localhost.localdomain"&gt;splunk@localhost.localdomain&lt;/A&gt;", while the other two show "From: Splunk Daemon User [&lt;A href="mailto:splunk@searchhead01.full.name.com"&gt;splunk@searchhead01.full.name.com&lt;/A&gt;]". (Or '@searchhead02.' depending on source.  You get the idea.)  &lt;/P&gt;

&lt;P&gt;I do not like &lt;EM&gt;localhost@localdomain&lt;/EM&gt; in the header.  I would rather have the more informative, real name included in the mail header.  My users agree with me, for once.  &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;I've looked through the GUI and not found differences in Manager &amp;gt; System Setting &amp;gt; {General Setting or Email alert settings}.  I've run "find . -type f -exec grep localdomain {} ; -print" and nothing obvious has jumped out at me.  I'll admit I haven't compared everything in all the files, however.&lt;/P&gt;

&lt;P&gt;All three have the same content in .../etc/system/local/alert_actions.conf  (Non-pooled directory, no such file in the pooled area).&lt;/P&gt;

&lt;P&gt;Additionally, I brought up a new search head, that is &lt;EM&gt;not&lt;/EM&gt; pooled, at the same time as the new pooled search head.  (I have a total of four search heads.)  Same version and build.  It also uses the unpreferred "From: &lt;A href="mailto:splunk@localhost.localdomain"&gt;splunk@localhost.localdomain&lt;/A&gt;".  Same settings and version as the new pooled search head.  It is just not pooled.&lt;/P&gt;

&lt;P&gt;All are RHEL 5.7.  All respond correctly to the hostname(1).  hosts(5) files are correct.  /etc/sysconfig/network have "HOSTNAME=" set correctly.  &lt;/P&gt;

&lt;P&gt;I've used mailx(P) on all four to send test messages, from the Splunk user, using the command line. The headers &lt;STRONG&gt;&lt;EM&gt;all&lt;/EM&gt;&lt;/STRONG&gt; come through with the preferred format of "From: Splunk Daemon User [&lt;A href="mailto:splunk@searchhead01.full.name.com"&gt;splunk@searchhead01.full.name.com&lt;/A&gt;]" so I'm convinced it's not sendmail(8) or the operating system causing the problem.  I am not convinced some interaction between the OS and Splunk couldn't cause the problem, however.  But I really believe I've missed something in the Splunk configuration on the new boxes.&lt;/P&gt;

&lt;P&gt;What am I missing?&lt;/P&gt;</description>
      <pubDate>Fri, 05 Apr 2013 16:06:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Alert-Messages-Coming-from-localhost-localdomain/m-p/86166#M1205</guid>
      <dc:creator>I_am_Jeff</dc:creator>
      <dc:date>2013-04-05T16:06:37Z</dc:date>
    </item>
    <item>
      <title>Re: Alert Messages Coming from localhost@localdomain</title>
      <link>https://community.splunk.com/t5/Alerting/Alert-Messages-Coming-from-localhost-localdomain/m-p/86167#M1206</link>
      <description>&lt;P&gt;All four do not have $LOCALHOST set. (echo $LOCALHOST returns nothing on any of them.) All four alert_actions.conf look like this, just 3 lines.&lt;/P&gt;

&lt;P&gt;[email]&lt;BR /&gt;
reportServerEnabled = 1&lt;BR /&gt;
reportServerURL =&lt;/P&gt;</description>
      <pubDate>Fri, 05 Apr 2013 16:46:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Alert-Messages-Coming-from-localhost-localdomain/m-p/86167#M1206</guid>
      <dc:creator>I_am_Jeff</dc:creator>
      <dc:date>2013-04-05T16:46:55Z</dc:date>
    </item>
    <item>
      <title>Re: Alert Messages Coming from localhost@localdomain</title>
      <link>https://community.splunk.com/t5/Alerting/Alert-Messages-Coming-from-localhost-localdomain/m-p/86168#M1207</link>
      <description>&lt;P&gt;I believe that will either be set in the conf file or with scripting. So I'd check to see if there is a $SPLUNK_HOME/etc/system/local/alert_actions.conf on the SH where it works as you prefer.&lt;/P&gt;

&lt;P&gt;I haven't tested this much, but that would be the first thing I'd check...&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 13:40:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Alert-Messages-Coming-from-localhost-localdomain/m-p/86168#M1207</guid>
      <dc:creator>rsennett_splunk</dc:creator>
      <dc:date>2020-09-28T13:40:54Z</dc:date>
    </item>
    <item>
      <title>Re: Alert Messages Coming from localhost@localdomain</title>
      <link>https://community.splunk.com/t5/Alerting/Alert-Messages-Coming-from-localhost-localdomain/m-p/86169#M1208</link>
      <description>&lt;P&gt;Try setting it on your Searchhead as an admin user:&lt;/P&gt;

&lt;P&gt;&lt;IMG src="http://splunk-base.splunk.com//storage/Screen_Shot_2013-07-18_at_1.12.28_PM.png" alt="alt text" /&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 18 Jul 2013 20:13:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Alert-Messages-Coming-from-localhost-localdomain/m-p/86169#M1208</guid>
      <dc:creator>the_wolverine</dc:creator>
      <dc:date>2013-07-18T20:13:10Z</dc:date>
    </item>
    <item>
      <title>Re: Alert Messages Coming from localhost@localdomain</title>
      <link>https://community.splunk.com/t5/Alerting/Alert-Messages-Coming-from-localhost-localdomain/m-p/86170#M1209</link>
      <description>&lt;P&gt;I have no doubt this will work.  But still would like to know where I went wrong with my original install.&lt;/P&gt;</description>
      <pubDate>Thu, 08 Aug 2013 21:41:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Alert-Messages-Coming-from-localhost-localdomain/m-p/86170#M1209</guid>
      <dc:creator>I_am_Jeff</dc:creator>
      <dc:date>2013-08-08T21:41:59Z</dc:date>
    </item>
  </channel>
</rss>

