As of now when email alerts are sent, the from address is the hostname of server sending the alert.
Is it possible to change that to a generic one like the internal splunk support team.
eg: As of now the from in email alerts is
Can i get it changed to
Create a file alert_actions.conf on the system/local of the SH, and have the below config, then restart.
from = email@example.com
Note: - This was an old question, providing a direct answer, than getting into docs and investigating.