As of now when email alerts are sent, the from address is the hostname of server sending the alert.
Is it possible to change that to a generic one like the internal splunk support team.
eg: As of now the from in email alerts is
Can i get it changed to
Create a file alert_actions.conf on the system/local of the SH, and have the below config, then restart.
from = email@example.com
Note: - This was an old question, providing a direct answer, than getting into docs and investigating.
@snethala_splunk Thankyou, I had to struggle a lot before getting to this,
You can simply change sender's email address in below configuration and it worked for me.
mailserver = localhost
pdf.header_left = none
pdf.header_right = none
from = Splunk@companyname.com
Before making config changes, you can test it out first to see its a valid email/company domain combination,
<your Search>| sendemail to= <your email> from= Splunk@companyname.com