Alerting

Why is the Splunk email Alert link not accessible?

pkumar9610
Explorer

Hi Team,

We are on Splunk 7.1.6 Version, I have configured Splunk Alert to send email and we are getting link to the Alert but the link is not accessible. I see the link has Search Head hostname, when I replace it with Search Head IP I am able to access the link.

How can I change the setting so that I get Alert link using IP instead of hostname ?

Eg-Hostname: http://sh-46177-3-1732:8000/splunk/splunkdownAlert ----- this is not working
When I replace to IP, it works
Eg: http://10.10.39.40:8000/splunk/splunkdownAlert ------ This works

pkumar9610
Explorer

After making this change, all Jobs went into Queue for almost 12hrs and when I reverted back I see all jobs triggered back and splunk got hanged. I have went a head and restarted Search Head. Now I don't see triggered jobs in UI but the jobs are getting triggered. How can I fix this ?

0 Karma

493669
Super Champion

Hi @pkumar9610,
Go to Settings>>Server settings>>Email settings
In Link hostname add http://10.10.39.40:8000
and click Save.
It will change your hostname with ip address.

0 Karma

pkumar9610
Explorer

After making this change, all the jobs went into the queue and non of them got triggered for almost 12hours. When I reverted back they all got hanged and search is not responding. So I have restart search heads, no search is accessible but non of the Jobs (Alerts, Reports) are getting triggered.

Can you please help how to fix this ASAP, this is impacting all the customers.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

A Four-Part Event Series: Full Stack Observability For the AI Era

As AI reshapes applications, infrastructure, and the way teams operate, the traditional boundaries of ...

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Event Series: Level up your SOC: Advancing with Splunk Enterprise Security

AI has fundamentally raised the stakes for security operations, and this three-part series is your guide to ...