Dear Splunk
I have a use case to send some notification/warning alert to those users who are met with some criteria in search.
How can i send alert only to the members(identified in search) in BCC list as the alert configuration have a mandatory TO list (for at least one member ) which do not required in the use case.
simple , i want to set up an alert only with bcc'd users not anyone in "to" list
Set up a "fake" to address and use that. However, you should consider that while Splunk may be able (to attempt) to send the email, the email system, either the senders or receivers, may deem a message with no real to address and only bcc address as spam and will junk the messages.
Thanks for reply , keeping a fake email id spamming the mail box.