<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Why does 'Alert Action: Send Email' use a different search head in Alerting</title>
    <link>https://community.splunk.com/t5/Alerting/Why-does-Alert-Action-Send-Email-use-a-different-search-head/m-p/441471#M7722</link>
    <description>&lt;P&gt;is it a Search Head Cluster?&lt;BR /&gt;
read here and apply opposite logic:&lt;BR /&gt;
&lt;A href="https://docs.splunk.com/Documentation/Splunk/7.1.2/DistSearch/Adhocclustermember"&gt;https://docs.splunk.com/Documentation/Splunk/7.1.2/DistSearch/Adhocclustermember&lt;/A&gt;&lt;BR /&gt;
i am doubtful that you will have access to this as you mentioned you have no access to set mail server.&lt;BR /&gt;
i think that a quick note to your admin will do, takes less than a minute to fix&lt;/P&gt;</description>
    <pubDate>Tue, 17 Jul 2018 17:17:56 GMT</pubDate>
    <dc:creator>adonio</dc:creator>
    <dc:date>2018-07-17T17:17:56Z</dc:date>
    <item>
      <title>Why does 'Alert Action: Send Email' use a different search head</title>
      <link>https://community.splunk.com/t5/Alerting/Why-does-Alert-Action-Send-Email-use-a-different-search-head/m-p/441468#M7719</link>
      <description>&lt;P&gt;&lt;STRONG&gt;When I run the 'sendemail' command from a search I can successfully send out an email to *****@gmail.com:&lt;/STRONG&gt;&lt;BR /&gt;
INFO sendemail:134 - Sending email. subject="test", results_link="None", recipients="[u'*****@gmail.com']", &lt;BR /&gt;
server="127.0.0.1"&lt;BR /&gt;
host = sh01&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;But when I attempt to use an alert (created on SH01), python.log shows an 'ERROR' from 'SH02'&lt;/STRONG&gt;&lt;BR /&gt;
ERROR sendemail:452 - [Errno 111] Connection refused while sending mail to: *****@gmail.com&lt;BR /&gt;
host = sh02&lt;/P&gt;

&lt;P&gt;ERROR sendemail:137 - Sending email. subject="Splunk Alert: toot test", results_link="https://****&lt;EM&gt;:8000/app/search/search?q=%7Cloadjob%20rt_scheduler_am9uYXRoYW4ucGh1bmc_&lt;EM&gt;search&lt;/EM&gt;_RMD5a4567364310f5ab7_at_1531841295_42380.1152_A796D57B-F1E3-44CF-B9F2-EBA799BB1E72%20%7C%20head%2032%20%7C%20tail%201&amp;amp;earliest=0⪭st=now", recipients="[u'\&lt;/EM&gt;****@gmail.com']", server="127.0.0.1"&lt;BR /&gt;
host = sh02&lt;/P&gt;

&lt;P&gt;Can anyone explain why this log is coming from sh02 and if I can make it such that an alert action happens on sh01 instead?&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 20:28:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Why-does-Alert-Action-Send-Email-use-a-different-search-head/m-p/441468#M7719</guid>
      <dc:creator>jphung</dc:creator>
      <dc:date>2020-09-29T20:28:07Z</dc:date>
    </item>
    <item>
      <title>Re: Why does 'Alert Action: Send Email' use a different search head</title>
      <link>https://community.splunk.com/t5/Alerting/Why-does-Alert-Action-Send-Email-use-a-different-search-head/m-p/441469#M7720</link>
      <description>&lt;P&gt;do you have the email server configured on SH02?&lt;/P&gt;</description>
      <pubDate>Tue, 17 Jul 2018 17:09:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Why-does-Alert-Action-Send-Email-use-a-different-search-head/m-p/441469#M7720</guid>
      <dc:creator>adonio</dc:creator>
      <dc:date>2018-07-17T17:09:22Z</dc:date>
    </item>
    <item>
      <title>Re: Why does 'Alert Action: Send Email' use a different search head</title>
      <link>https://community.splunk.com/t5/Alerting/Why-does-Alert-Action-Send-Email-use-a-different-search-head/m-p/441470#M7721</link>
      <description>&lt;P&gt;I do not, and I do not have permission to, is there a way to make it such that sh01 always attempts the alert action?&lt;/P&gt;</description>
      <pubDate>Tue, 17 Jul 2018 17:13:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Why-does-Alert-Action-Send-Email-use-a-different-search-head/m-p/441470#M7721</guid>
      <dc:creator>jphung</dc:creator>
      <dc:date>2018-07-17T17:13:09Z</dc:date>
    </item>
    <item>
      <title>Re: Why does 'Alert Action: Send Email' use a different search head</title>
      <link>https://community.splunk.com/t5/Alerting/Why-does-Alert-Action-Send-Email-use-a-different-search-head/m-p/441471#M7722</link>
      <description>&lt;P&gt;is it a Search Head Cluster?&lt;BR /&gt;
read here and apply opposite logic:&lt;BR /&gt;
&lt;A href="https://docs.splunk.com/Documentation/Splunk/7.1.2/DistSearch/Adhocclustermember"&gt;https://docs.splunk.com/Documentation/Splunk/7.1.2/DistSearch/Adhocclustermember&lt;/A&gt;&lt;BR /&gt;
i am doubtful that you will have access to this as you mentioned you have no access to set mail server.&lt;BR /&gt;
i think that a quick note to your admin will do, takes less than a minute to fix&lt;/P&gt;</description>
      <pubDate>Tue, 17 Jul 2018 17:17:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Why-does-Alert-Action-Send-Email-use-a-different-search-head/m-p/441471#M7722</guid>
      <dc:creator>adonio</dc:creator>
      <dc:date>2018-07-17T17:17:56Z</dc:date>
    </item>
    <item>
      <title>Re: Why does 'Alert Action: Send Email' use a different search head</title>
      <link>https://community.splunk.com/t5/Alerting/Why-does-Alert-Action-Send-Email-use-a-different-search-head/m-p/441472#M7723</link>
      <description>&lt;P&gt;it is a search head cluster of sh01, sh02, sh03&lt;/P&gt;

&lt;P&gt;changing the captain role didn't seem to do anything&lt;/P&gt;

&lt;P&gt;sh02 and sh03 are the hosts where the email ERROR log appears&lt;/P&gt;

&lt;P&gt;the alert never goes off from sh01&lt;/P&gt;

&lt;P&gt;This might not be a problem I can resolve alone, thank you&lt;/P&gt;</description>
      <pubDate>Tue, 17 Jul 2018 17:24:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Why-does-Alert-Action-Send-Email-use-a-different-search-head/m-p/441472#M7723</guid>
      <dc:creator>jphung</dc:creator>
      <dc:date>2018-07-17T17:24:28Z</dc:date>
    </item>
  </channel>
</rss>

