Alerting

How to check permissions required to send an alert

golcondar
Explorer

Hi all,

following up on https://answers.splunk.com/answers/808200/splunk-alerts-not-sending-e-mail.html?childToView=810356#a....

I wanted to figure out if there were any permissions needed to enable a splunk alert from my account. Is there a way I can check the permissions needed to create a working splunk alert (that sends out an email)?

Not sure if i'm providing enough information, so please let me know if i need to provide more.

Tags (2)
0 Karma
1 Solution

manjunathmeti
Champion

You need below capabilities set to user role under which alert are triggered.

schedule_search = enabled
list_settings = enabled
admin_all_objects = enabled
(This capability is required if the mail host requires login credentials. It is for PDF mail delivery only.)

https://docs.splunk.com/Documentation/Splunk/8.0.2/Alert/Emailnotification#User_role_configuration_f...

View solution in original post

0 Karma

manjunathmeti
Champion

You need below capabilities set to user role under which alert are triggered.

schedule_search = enabled
list_settings = enabled
admin_all_objects = enabled
(This capability is required if the mail host requires login credentials. It is for PDF mail delivery only.)

https://docs.splunk.com/Documentation/Splunk/8.0.2/Alert/Emailnotification#User_role_configuration_f...

0 Karma

golcondar
Explorer

I believe this worked, thank you!

0 Karma

rkyadav
Path Finder

@golcondar ,

Sometime email ID would have an issue with exchange servers which does not allow to recieve any emails.
Just my 2 cents here :

try adding - @exchange.domain.com

For xample - First.lastname@exchange.org.com , where org could be your organizational name

0 Karma
Get Updates on the Splunk Community!

Preparing your Splunk Environment for OpenSSL3

The Splunk platform will transition to OpenSSL version 3 in a future release. Actions are required to prepare ...

Unleash Unified Security and Observability with Splunk Cloud Platform

     Now Available on Microsoft AzureThursday, March 27, 2025  |  11AM PST / 2PM EST | Register NowStep boldly ...

Splunk AppDynamics with Cisco Secure Application

Web applications unfortunately present a target rich environment for security vulnerabilities and attacks. ...