Alerting

Duplicate "Send Email" option in Splunk Enterprise 7

splunkdivya
Explorer

Having duplicate "Send Email" options on Splunk 7 Enterprise, not sure what causing it:
PFB the screenshot
alt text

Any pointers are highly appreciated.
- Best,
- Splunkdivya

0 Karma

DavidHourani
Super Champion

Hi @splunkdivya,

Seems like you have a duplicate configuration for your send email modular alert action.

Have a read here in case you don't know how modular alerts work :
https://docs.splunk.com/Documentation/SplunkCloud/latest/AdvancedDev/ModAlertsIntro

In order to resolve this, search on your SH for alert_actions.conf and identify the location of the duplicate send email action. Once that's done all you have to do is get rid of it and you'll be back to a single action.

Let me know if that helps.

Cheers,
David

0 Karma
Get Updates on the Splunk Community!

Splunk MCP & Agentic AI: Machine Data Without Limits

  Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization ...

Finding Based Detections General Availability

Overview  We’ve come a long way, folks, but here in Enterprise Security 8.4 I’m happy to announce Finding ...

Get Your Hands Dirty (and Your Shoes Comfy): The Splunk Experience

Hands-On Learning and Technical Seminars  Sometimes, you just need to see the code. For those looking for a ...