Alerting

alert - can I sent email from specific email address only for specific alert

net1993
Path Finder

Hello
I know I can set from email address in alert_actions.conf with attribute: from = "some@email" but this is global setting which will make that src. email for all emails sent out. Is it possible that I set the specific email address but only for specific alert?

0 Karma
1 Solution

VatsalJagani
SplunkTrust
SplunkTrust

Hello @net1993,

I don't think that is possible, as alert_actions.conf has only one property for from element. One thing that you can try is as below. I'm sure if that is feasible in your case.
Create separate Apps for those you need separate from email address, put alert actions in those with different configuration and keep it to "App only privileged" from meta file.

View solution in original post

VatsalJagani
SplunkTrust
SplunkTrust

Hello @net1993,

I don't think that is possible, as alert_actions.conf has only one property for from element. One thing that you can try is as below. I'm sure if that is feasible in your case.
Create separate Apps for those you need separate from email address, put alert actions in those with different configuration and keep it to "App only privileged" from meta file.

net1993
Path Finder

Hi. I need field "From:" not "To:"

0 Karma

VatsalJagani
SplunkTrust
SplunkTrust

I don't think that is possible, as alert_actions.conf has only one property for from element.
One thing that you can try is as below. I'm sure if that is feasible in your case.
Create separate Apps for those you need separate from email address, put alert actions in those with different configuration and keep it to "App only privileged" from meta file.

net1993
Path Finder

Yes I was considering that option as well but I was wondering if there is easier way:).
Anyway, thank you. I accept this answer because I think it will work.

0 Karma

VatsalJagani
SplunkTrust
SplunkTrust

Nice to here that you already have this in mind. If you have some limited number of "From" emails you can do this. I've updated my answer for future user's reference. Please accept it.
Thanks!!!

0 Karma

p_gurav
Champion

Please try sendemail command.

0 Karma

net1993
Path Finder

If I try to put email sending settings in the search, then I cannot control the alert threshold so I cannot see that this is an option.

0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...