Alerting

Backgrounded jobs don't send email alerts out when completed.

davidpaper
Contributor

For a long backgrounded job, it would be really useful to be able to get an alert sent out when it is done. Doesn't appear that my Splunk instances does this.

Emails for scheduled searches that generate alerts work just fine, so I know the email server path is fully functional.

If it makes a difference, all of our user auth is done via LDAP.

Any suggestions on ways to get this to work?

Tags (3)
1 Solution

jtrucks
Splunk Employee
Splunk Employee

This works for non-LDAP instances by simply entering the email address in the user's Splunk local account profile. This automagically works in those cases.

As for LDAP, perhaps if the correct field name is proffered to Splunk from LDAP it would correctly populate the email address field.

--
Jesse Trucks
Minister of Magic

View solution in original post

jtrucks
Splunk Employee
Splunk Employee

This works for non-LDAP instances by simply entering the email address in the user's Splunk local account profile. This automagically works in those cases.

As for LDAP, perhaps if the correct field name is proffered to Splunk from LDAP it would correctly populate the email address field.

--
Jesse Trucks
Minister of Magic

antlefebvre
Communicator

I have an open case with Splunk on this. No way to currently import email via LDAP. No ETA on fix.

0 Karma

jtrucks
Splunk Employee
Splunk Employee

I'm told that LDAP configurations often don't provide splunk with the right named field for email propogation, which is the likely cause of your issue.

--
Jesse Trucks
Minister of Magic
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Index This | What travels the world but is also stuck in place?

April 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Discover New Use Cases: Unlock Greater Value from Your Existing Splunk Data

Realizing the full potential of your Splunk investment requires more than just understanding current usage; it ...

Continue Your Journey: Join Session 2 of the Data Management and Federation Bootcamp ...

As data volumes continue to grow and environments become more distributed, managing and optimizing data ...