We recently migrated to Splunk Search Head Clustering. We are using a Load Balancer in front of 3 Search Heads Clustered so that the users can access the set of search heads through a single interface, without needing to specify a particular one.
Now, we notice that the email alerts we received are coming randomly from any of the 3 Search Heads Clustered. It means the email alert sender for Splunk SHC comes from any 3 Search Heads Clustered. Is there a way to make it appear the alert is being sent by the load balancer name? So that once the users receives the alerts, the email alert sender is uniform.