<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: alert_actions.conf being ignored in Alerting</title>
    <link>https://community.splunk.com/t5/Alerting/I-have-an-alert-actions-conf-being-ignored/m-p/47589#M620</link>
    <description>&lt;P&gt;Support Case # 84640 for this issue.&lt;/P&gt;</description>
    <pubDate>Wed, 23 May 2012 15:41:55 GMT</pubDate>
    <dc:creator>cbowles</dc:creator>
    <dc:date>2012-05-23T15:41:55Z</dc:date>
    <item>
      <title>I have an alert_actions.conf being ignored</title>
      <link>https://community.splunk.com/t5/Alerting/I-have-an-alert-actions-conf-being-ignored/m-p/47585#M616</link>
      <description>&lt;P&gt;I have an alert_actions.conf file that is pushed out to our search heads via deployment server. All of the settings (hostname, mailserver, from) are being ignored when in the app context. If I move the same file into $SPLUNK_HOME/etc/system/local, everything works.&lt;/P&gt;
&lt;P&gt;I ran "splunk cmd btool alert_actions list" and the output is identical no matter where I put alert_actions.conf. In both cases, it looks like the settings are correct.&lt;/P&gt;
&lt;P&gt;Any ideas on why this doesn't work?&lt;/P&gt;</description>
      <pubDate>Wed, 09 Mar 2022 17:13:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/I-have-an-alert-actions-conf-being-ignored/m-p/47585#M616</guid>
      <dc:creator>ddeighton</dc:creator>
      <dc:date>2022-03-09T17:13:05Z</dc:date>
    </item>
    <item>
      <title>Re: alert_actions.conf being ignored</title>
      <link>https://community.splunk.com/t5/Alerting/I-have-an-alert-actions-conf-being-ignored/m-p/47586#M617</link>
      <description>&lt;P&gt;ddeighton,&lt;/P&gt;

&lt;P&gt;I found the same exact issue on my Splunk Server.  This seems to be a bug with Splunk where the Splunk Search Head only recognizes &lt;STRONG&gt;alert_actions.conf&lt;/STRONG&gt; in the local (/opt/splunk/etc/system/local) config directory.  &lt;/P&gt;

&lt;P&gt;Submitted a bug report.&lt;/P&gt;</description>
      <pubDate>Fri, 04 May 2012 20:03:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/I-have-an-alert-actions-conf-being-ignored/m-p/47586#M617</guid>
      <dc:creator>cbowles</dc:creator>
      <dc:date>2012-05-04T20:03:27Z</dc:date>
    </item>
    <item>
      <title>Re: alert_actions.conf being ignored</title>
      <link>https://community.splunk.com/t5/Alerting/I-have-an-alert-actions-conf-being-ignored/m-p/47587#M618</link>
      <description>&lt;P&gt;Thanks, cbowles, for confirming the problem and filing the bug report.&lt;/P&gt;</description>
      <pubDate>Sat, 05 May 2012 13:37:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/I-have-an-alert-actions-conf-being-ignored/m-p/47587#M618</guid>
      <dc:creator>ddeighton</dc:creator>
      <dc:date>2012-05-05T13:37:54Z</dc:date>
    </item>
    <item>
      <title>Re: alert_actions.conf being ignored</title>
      <link>https://community.splunk.com/t5/Alerting/I-have-an-alert-actions-conf-being-ignored/m-p/47588#M619</link>
      <description>&lt;P&gt;@ddeighton it might be an idea for you to also file a bug report just so Splunk are aware it is aflicting more than one user, also they may find multiple data sources on the bug helpful -&amp;gt; &lt;A href="https://www.splunk.com/page/submit_issue"&gt;https://www.splunk.com/page/submit_issue&lt;/A&gt; if @cbowles could share his support ref then you could include that within your ticket so they can link the two issues quickly.&lt;/P&gt;</description>
      <pubDate>Sat, 05 May 2012 14:13:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/I-have-an-alert-actions-conf-being-ignored/m-p/47588#M619</guid>
      <dc:creator>Drainy</dc:creator>
      <dc:date>2012-05-05T14:13:16Z</dc:date>
    </item>
    <item>
      <title>Re: alert_actions.conf being ignored</title>
      <link>https://community.splunk.com/t5/Alerting/I-have-an-alert-actions-conf-being-ignored/m-p/47589#M620</link>
      <description>&lt;P&gt;Support Case # 84640 for this issue.&lt;/P&gt;</description>
      <pubDate>Wed, 23 May 2012 15:41:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/I-have-an-alert-actions-conf-being-ignored/m-p/47589#M620</guid>
      <dc:creator>cbowles</dc:creator>
      <dc:date>2012-05-23T15:41:55Z</dc:date>
    </item>
    <item>
      <title>Re: alert_actions.conf being ignored</title>
      <link>https://community.splunk.com/t5/Alerting/I-have-an-alert-actions-conf-being-ignored/m-p/47590#M621</link>
      <description>&lt;P&gt;Splunk bug SPL-55476 was created to address this issue. Thanks everyone that continues to reference this answer post.&lt;/P&gt;</description>
      <pubDate>Fri, 31 Aug 2012 01:30:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/I-have-an-alert-actions-conf-being-ignored/m-p/47590#M621</guid>
      <dc:creator>Rob</dc:creator>
      <dc:date>2012-08-31T01:30:27Z</dc:date>
    </item>
    <item>
      <title>Re: alert_actions.conf being ignored</title>
      <link>https://community.splunk.com/t5/Alerting/I-have-an-alert-actions-conf-being-ignored/m-p/47591#M622</link>
      <description>&lt;P&gt;I don't see SPL-55476 listed on docs.splunk.com.  Has this been listed as a known issue or fixed? &lt;A href="http://docs.splunk.com/Special:SplunkSearch/docs?q=SPL-55476"&gt;http://docs.splunk.com/Special:SplunkSearch/docs?q=SPL-55476&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 24 Sep 2013 15:35:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/I-have-an-alert-actions-conf-being-ignored/m-p/47591#M622</guid>
      <dc:creator>sloshburch</dc:creator>
      <dc:date>2013-09-24T15:35:07Z</dc:date>
    </item>
    <item>
      <title>Re: alert_actions.conf being ignored</title>
      <link>https://community.splunk.com/t5/Alerting/I-have-an-alert-actions-conf-being-ignored/m-p/47592#M623</link>
      <description>&lt;P&gt;SPL-55476 was never validated and it is not a valid bug.&lt;BR /&gt;
I have it working on 5.0.5, splunk is connecting to mailserver indicated below&lt;/P&gt;

&lt;P&gt;ON DS&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;/opt/SPLUNK/5.0.5-DS/splunk $ cat etc/deployment-apps/testDeployApp/local/alert_actions.conf 
[email]
auth_password = $1$d2gP+53E8tz
auth_username = myemail@mailprovider.com
mailserver = smtp.mailprovider.com:2500
reportServerURL = 
from = myemail@mailprovider.com
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;ON DC&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;   /opt/SPLUNK/5.0.5-DC/splunk/bin $ ./splunk btool alert_actions list email --debug | egrep -o 'alert_action.*' | egrep -v command
alert_actions.conf [email]
alert_actions.conf auth_password = $1$ndCtP+qYE8tz
alert_actions.conf auth_username = myemail@mailprovider.com
alert_actions.conf           bcc = 
alert_actions.conf           cc = 
alert_actions.conf           format = html
alert_actions.conf from = myemail@mailprovider.com
alert_actions.conf           hostname = 
alert_actions.conf           inline = 0
alert_actions.conf mailserver = smtp.mailprovider.com:2500
alert_actions.conf           maxresults = 10000
alert_actions.conf           maxtime = 5m
alert_actions.conf           pdfview = 
alert_actions.conf           preprocess_results = 
alert_actions.conf           reportCIDFontList = gb cns jp kor
alert_actions.conf           reportIncludeSplunkLogo = 1
alert_actions.conf           reportPaperOrientation = portrait
alert_actions.conf           reportPaperSize = letter
alert_actions.conf           reportServerEnabled = false
alert_actions.conf reportServerURL = 
alert_actions.conf           sendpdf = 0
alert_actions.conf           sendresults = 0
alert_actions.conf           subject = Splunk Alert: $name$
alert_actions.conf           to = 
alert_actions.conf           track_alert = 1
alert_actions.conf           ttl = 86400
alert_actions.conf           use_ssl = 0
alert_actions.conf           use_tls = 0
alert_actions.conf           width_sort_columns = 1
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Wed, 18 Dec 2013 15:33:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/I-have-an-alert-actions-conf-being-ignored/m-p/47592#M623</guid>
      <dc:creator>abonuccelli_spl</dc:creator>
      <dc:date>2013-12-18T15:33:46Z</dc:date>
    </item>
    <item>
      <title>Re: alert_actions.conf being ignored</title>
      <link>https://community.splunk.com/t5/Alerting/I-have-an-alert-actions-conf-being-ignored/m-p/47593#M624</link>
      <description>&lt;P&gt;Antonio (my splunk homey) went through this - the answer is in precedence and I don't think it's a bug.&lt;/P&gt;

&lt;P&gt;See&lt;BR /&gt;
docs.splunk.com/Documentation/Splunk/6.0.1/admin/Wheretofindtheconfigurationfiles&lt;/P&gt;

&lt;P&gt;alert_actions.conf is effective at app/user scope - not global.&lt;/P&gt;

&lt;P&gt;if you deliver alert_actions.conf to an instance in an app ON ITS OWN - it will have no effect.&lt;/P&gt;

&lt;P&gt;If you deliver it into an app which has search configurations (where you are generating reports you wish to email) - it works exactly as defined.&lt;/P&gt;

&lt;P&gt;The access URL tells you which scope you're in. I have put an alert_actions.conf in&lt;BR /&gt;
$SPLUNK_HOME/etc/apps/dbx/local.&lt;/P&gt;

&lt;P&gt;I can configure it from the GUI if I want from this url:&lt;BR /&gt;
h-t-t-p://instance:8000/en-US/manager/dbx/admin/alert_actions/email?action=edit&lt;/P&gt;

&lt;P&gt;If I want to email searches from within the search app - I must place the file in&lt;BR /&gt;
$SPLUNK_HOME/etc/apps/search/local&lt;/P&gt;

&lt;P&gt;and i configure it from the gui using this URL:&lt;BR /&gt;
h-t-t-p://instance:8000/en-US/manager/search/admin/alert_actions/email?action=edit&lt;/P&gt;

&lt;P&gt;Its scope of effect is 'app/user', not global.&lt;/P&gt;

&lt;P&gt;A user can provide his own alert_actions.conf - but again, it's in the userdir for a specific app, not for all apps.&lt;/P&gt;

&lt;P&gt;Gavs&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 15:45:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/I-have-an-alert-actions-conf-being-ignored/m-p/47593#M624</guid>
      <dc:creator>gavin1_davenpor</dc:creator>
      <dc:date>2020-09-28T15:45:03Z</dc:date>
    </item>
    <item>
      <title>Re: alert_actions.conf being ignored</title>
      <link>https://community.splunk.com/t5/Alerting/I-have-an-alert-actions-conf-being-ignored/m-p/47594#M625</link>
      <description>&lt;P&gt;That may be for 6*, but is it different for 5*?&lt;/P&gt;</description>
      <pubDate>Wed, 29 Jan 2014 18:35:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/I-have-an-alert-actions-conf-being-ignored/m-p/47594#M625</guid>
      <dc:creator>sloshburch</dc:creator>
      <dc:date>2014-01-29T18:35:02Z</dc:date>
    </item>
    <item>
      <title>Re: alert_actions.conf being ignored</title>
      <link>https://community.splunk.com/t5/Alerting/I-have-an-alert-actions-conf-being-ignored/m-p/47595#M626</link>
      <description>&lt;P&gt;It is highly unlikely splunk changed the precedence rules for that file between releases. Antonio tested it on 5.* and saw the same behaviour...&lt;/P&gt;</description>
      <pubDate>Thu, 30 Jan 2014 09:11:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/I-have-an-alert-actions-conf-being-ignored/m-p/47595#M626</guid>
      <dc:creator>gavin1_davenpor</dc:creator>
      <dc:date>2014-01-30T09:11:48Z</dc:date>
    </item>
    <item>
      <title>Re: alert_actions.conf being ignored</title>
      <link>https://community.splunk.com/t5/Alerting/I-have-an-alert-actions-conf-being-ignored/m-p/47596#M627</link>
      <description>&lt;P&gt;Any thoughts on if it can be made global using an export = system in the default.meta of a custom app?&lt;/P&gt;</description>
      <pubDate>Mon, 07 Jul 2014 18:24:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/I-have-an-alert-actions-conf-being-ignored/m-p/47596#M627</guid>
      <dc:creator>sloshburch</dc:creator>
      <dc:date>2014-07-07T18:24:11Z</dc:date>
    </item>
    <item>
      <title>Re: alert_actions.conf being ignored</title>
      <link>https://community.splunk.com/t5/Alerting/I-have-an-alert-actions-conf-being-ignored/m-p/47597#M628</link>
      <description>&lt;P&gt;Add a local.meta file to "alertactionappname/metadata" with the following stanza:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[]
export = system
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;this will do the job and solve the problem&lt;/P&gt;</description>
      <pubDate>Fri, 12 Jan 2018 13:38:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/I-have-an-alert-actions-conf-being-ignored/m-p/47597#M628</guid>
      <dc:creator>claudio_manig</dc:creator>
      <dc:date>2018-01-12T13:38:08Z</dc:date>
    </item>
    <item>
      <title>Re: alert_actions.conf being ignored</title>
      <link>https://community.splunk.com/t5/Alerting/I-have-an-alert-actions-conf-being-ignored/m-p/588280#M13559</link>
      <description>&lt;P&gt;Don't forget to do SHC rolling restart, you can also put in default.meta&lt;/P&gt;</description>
      <pubDate>Wed, 09 Mar 2022 17:00:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/I-have-an-alert-actions-conf-being-ignored/m-p/588280#M13559</guid>
      <dc:creator>splunkreal</dc:creator>
      <dc:date>2022-03-09T17:00:52Z</dc:date>
    </item>
    <item>
      <title>Re: alert_actions.conf being ignored</title>
      <link>https://community.splunk.com/t5/Alerting/I-have-an-alert-actions-conf-being-ignored/m-p/682656#M15869</link>
      <description>&lt;P&gt;Still good after all these years&lt;/P&gt;</description>
      <pubDate>Mon, 01 Apr 2024 19:47:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/I-have-an-alert-actions-conf-being-ignored/m-p/682656#M15869</guid>
      <dc:creator>millarma</dc:creator>
      <dc:date>2024-04-01T19:47:30Z</dc:date>
    </item>
  </channel>
</rss>

