Alerting

How to check permissions required to send an alert

golcondar
Explorer

Hi all,

following up on https://answers.splunk.com/answers/808200/splunk-alerts-not-sending-e-mail.html?childToView=810356#a....

I wanted to figure out if there were any permissions needed to enable a splunk alert from my account. Is there a way I can check the permissions needed to create a working splunk alert (that sends out an email)?

Not sure if i'm providing enough information, so please let me know if i need to provide more.

Tags (2)
0 Karma
1 Solution

manjunathmeti
Champion

You need below capabilities set to user role under which alert are triggered.

schedule_search = enabled
list_settings = enabled
admin_all_objects = enabled
(This capability is required if the mail host requires login credentials. It is for PDF mail delivery only.)

https://docs.splunk.com/Documentation/Splunk/8.0.2/Alert/Emailnotification#User_role_configuration_f...

View solution in original post

0 Karma

manjunathmeti
Champion

You need below capabilities set to user role under which alert are triggered.

schedule_search = enabled
list_settings = enabled
admin_all_objects = enabled
(This capability is required if the mail host requires login credentials. It is for PDF mail delivery only.)

https://docs.splunk.com/Documentation/Splunk/8.0.2/Alert/Emailnotification#User_role_configuration_f...

0 Karma

golcondar
Explorer

I believe this worked, thank you!

0 Karma

rkyadav
Path Finder

@golcondar ,

Sometime email ID would have an issue with exchange servers which does not allow to recieve any emails.
Just my 2 cents here :

try adding - @exchange.domain.com

For xample - First.lastname@exchange.org.com , where org could be your organizational name

0 Karma
Get Updates on the Splunk Community!

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Shape the Future of Splunk: Join the Product Research Lab!

Join the Splunk Product Research Lab and connect with us in the Slack channel #product-research-lab to get ...