Alerting

How to enable WARN messages in alert emails for Splunk 6.1 that were present in previous versions?

0range
Communicator

Hello everyone!

In older versions of splunk, there were WARN messages in alert emails like the following:

-- Search generated the following messages --
Message Level: WARN
1. Unable to distribute to peer named ... at uri ... because replication was unsuccessful. replicationStatus Failed
2. Unable to distribute to peer named ... at uri ... because peer has status = "Authentication Failed".

Now in 6.1 they are disabled.
Is it possible to enable it again?

Thank you in advance.

Tags (3)
0 Karma
1 Solution

0range
Communicator

Seems like we need to update the sendemail.py adding the $job.messages$ param from here

View solution in original post

0range
Communicator

Seems like we need to update the sendemail.py adding the $job.messages$ param from here

Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...