Alerting

Duplicate "Send Email" option in Splunk Enterprise 7

splunkdivya
Explorer

Having duplicate "Send Email" options on Splunk 7 Enterprise, not sure what causing it:
PFB the screenshot
alt text

Any pointers are highly appreciated.
- Best,
- Splunkdivya

0 Karma

DavidHourani
Super Champion

Hi @splunkdivya,

Seems like you have a duplicate configuration for your send email modular alert action.

Have a read here in case you don't know how modular alerts work :
https://docs.splunk.com/Documentation/SplunkCloud/latest/AdvancedDev/ModAlertsIntro

In order to resolve this, search on your SH for alert_actions.conf and identify the location of the duplicate send email action. Once that's done all you have to do is get rid of it and you'll be back to a single action.

Let me know if that helps.

Cheers,
David

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In January, the Splunk Threat Research Team had one release of new security content via the Splunk ES Content ...

Expert Tips from Splunk Professional Services, Ensuring Compliance, and More New ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Observability Release Update: AI Assistant, AppD + Observability Cloud Integrations & ...

This month’s releases across the Splunk Observability portfolio deliver earlier detection and faster ...