Alerting

Email alert changes

pratapa
Explorer

Hi,

In our environment, email ID in the TO field has changed for one of the alerts.

How to know when the email ID has changed. What was the previous email ID. Will this be logged in any log file.

Pratapa

Tags (1)
0 Karma

soumyasaha25
Contributor

have a look in index=_internal source=*python.log* there you can have a look at the subject field that shows the alert name and the recipients filed shows the list of email ids.
you can compare by dunning the search over different times and see the difference in the recipients to find out which email ids were changed.

Get Updates on the Splunk Community!

Splunk Education - Fast Start Program!

Welcome to Splunk Education! Splunk training programs are designed to enable you to get started quickly and ...

Five Subtly Different Ways of Adding Manual Instrumentation in Java

You can find the code of this example on GitHub here. Please feel free to star the repository to keep in ...

New Splunk APM Enhancements Help Troubleshoot Your MySQL and NoSQL Databases Faster

Splunk Observability has two new enhancements to make it quicker and easier to troubleshoot slow or frequently ...