Alerting

How to reenable email alerts after they have been disabled, and is it possible to limit the type of content that is emailed (ex: no raw event data)?

IRHM73
Motivator

Hi, I wonder whether someone may be able to help me please.

Through the 'Save as Alert' process I have created a report which I want to run at a given time and email the results.

The problem I have is that I am not receiving the email containing the results.

I have only just taken over the 'admin' role within Splunk, so it's a 'steep learning curve' at the moment, but I'm told my predecessor disabled the email functionality because from a security aspect, they didn't want people to be able to email 'Raw Data'.

I have looked at the Splunk documentation and I think I've followed the 'Alert' process correctly, but could someone tell me please:

  • How do I re-enable the email functionality
  • Is it possible to limit the type of information that can be emailed, i.e. non Raw Event information.

Any help would be gratefully received.

Many thanks and kind regards

Chris

0 Karma
1 Solution

renjith_nair
Legend

Check your logs to find out any errors. Logs are available in $SPLUNK_HOME/var/log/splunk/ and splunkd.log and scheduler.log should help you.

Email configuration is available under Server settings » Email settings and make sure that all configuration is intact.

If you are admin on your search head server , make sure that mail is enabled on your server(try a mail command from your server) or ask your server admin to check that.

It is possible to limit the type of information that can be emailed, because its the result of your search which is going as email content. Restrict your search only to show required fields and schedule the search

Hope this helps!

---
What goes around comes around. If it helps, hit it with Karma 🙂

View solution in original post

renjith_nair
Legend

Check your logs to find out any errors. Logs are available in $SPLUNK_HOME/var/log/splunk/ and splunkd.log and scheduler.log should help you.

Email configuration is available under Server settings » Email settings and make sure that all configuration is intact.

If you are admin on your search head server , make sure that mail is enabled on your server(try a mail command from your server) or ask your server admin to check that.

It is possible to limit the type of information that can be emailed, because its the result of your search which is going as email content. Restrict your search only to show required fields and schedule the search

Hope this helps!

---
What goes around comes around. If it helps, hit it with Karma 🙂

IRHM73
Motivator

Hi @renjith.nair, thank you very much for the info, really very helpful.

Many thanks and kind regards

Chris

0 Karma

renjith_nair
Legend

If it helped please mark it as answer 🙂 . Did you find where the issue is now?

---
What goes around comes around. If it helps, hit it with Karma 🙂
0 Karma

IRHM73
Motivator

Hi, like I said I'm very new to the admin role, in fact there are actually a few of us sharing the role and unfortunately I'm one of the admin personnel without the hardware to search the logs. Yes I know it's a little crazy! however I'll be working with someone who has both more knowledge than I and has the correct hardware to do this.

Many thanks and kind regards

Chris

0 Karma
Get Updates on the Splunk Community!

Dashboards: Hiding charts while search is being executed and other uses for tokens

There are a couple of features of SimpleXML / Classic dashboards that can be used to enhance the user ...

Splunk Observability Cloud's AI Assistant in Action Series: Explaining Metrics and ...

This is the fourth post in the Splunk Observability Cloud’s AI Assistant in Action series that digs into how ...

Brains, Bytes, and Boston: Learn from the Best at .conf25

When you think of Boston, you might picture colonial charm, world-class universities, or even the crack of a ...