Alerting

Custom Email From Address for Alerts

griggsy
New Member

Hello,

I have an alert setup that I would like to send to end users however I want to change the from address in the email alert. Are you able to change the from field for specific alerts?

Ta.
Pete.

Tags (1)
0 Karma

shivanshu1593
Builder

For anyone looking how to do this for your report/alert already created:

1. Edit savedsearches.conf on your search head. Find the name of the alert, for which you want to use the new email address to send emails to the recipients and add the following:

action.email.from = your_email_address
action.email.mailserver = your_smtp_server_name

2. Restart Splunkd. 

Works like a charm. The best part is that all of your other alerts will still use the default email address, supplied in the server settings of your search head. Hope  this helps.

Thank you,
Shiv
###If you found the answer helpful, kindly consider upvoting/accepting it as the answer as it helps other Splunkers find the solutions to similar issues###

renjith_nair
Legend

Hi @griggsy ,

You could change the From email address in Mail Server Settings in Email Settings : http://docs.splunk.com/Documentation/SplunkCloud/7.0.3/Alert/Emailnotification#Configure_email_notif...

If you want to send each mail from a different "from" address, then probably sendemail command or a Configuring scripted alerts might be an option

Happy Splunking!
0 Karma

griggsy
New Member

Thanks, Just seems annoying you can't set the from address per alert.

0 Karma

chrisboy68
Contributor

I know this a bit old, but I agree it would be great to have this open. It could default to the system from or we can default to the alert owner. Managing bounced email for over thousands of email alerts is cumbersome. Sending the bounce back to the alert owner and they can handle it.

Chris

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...