Alerting

Splunk email alert not working when the owner account of the rule is disabled in AD ... expected?

gaddams
Explorer

Currently our Splunk Infrastructure is integrated with AD. I observed that a particular splunk rule which is scheduled to send email alerts was not generating any email alerts. When I created a clone of the same rule, it generated email alerts.

The only difference between the rules was the owner account of the old rule is disabled in AD whereas the owner account of the new rule is not disabled.

Could this be a reason? How to debug further here?

Thanks
Swetha

Tags (1)
0 Karma

grijhwani
Motivator

You don't say what platform you are running Splunk on, but I'll guess it is Windows. On Linux you could juggle the rules and change the ownership of existing configs. Whether there is a similar degree of freedom under Windows I don't know.

Try this search:

index=_internal "ERROR AuthenticationManagerLDAP"

Is account's ability to send e-mail (presumably through the monster that is Exchange) also tied to the AD activation? Either way it's not an unreasonable conclusion, that the inability to send the alert is a direct consequence of the deactivation of the account. If you have access to the inbound/relay logs on the mail server you could take a look to see if the mail is being rejected or simply not being seen.

To debug I would set up a dummy account, create an alert for it, see that it works, then disable the account and see what happens.

0 Karma
Get Updates on the Splunk Community!

Join Us for Splunk University and Get Your Bootcamp Game On!

If you know, you know! Splunk University is the vibe this summer so register today for bootcamps galore ...

.conf24 | Learning Tracks for Security, Observability, Platform, and Developers!

.conf24 is taking place at The Venetian in Las Vegas from June 11 - 14. Continue reading to learn about the ...

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...