Having duplicate "Send Email" options on Splunk 7 Enterprise, not sure what causing it:
PFB the screenshot
Any pointers are highly appreciated.
- Best,
- Splunkdivya
Hi @splunkdivya,
Seems like you have a duplicate configuration for your send email modular alert action.
Have a read here in case you don't know how modular alerts work :
https://docs.splunk.com/Documentation/SplunkCloud/latest/AdvancedDev/ModAlertsIntro
In order to resolve this, search on your SH for alert_actions.conf
and identify the location of the duplicate send email action. Once that's done all you have to do is get rid of it and you'll be back to a single action.
Let me know if that helps.
Cheers,
David