Alerting

Email alert changes

pratapa
Explorer

Hi,

In our environment, email ID in the TO field has changed for one of the alerts.

How to know when the email ID has changed. What was the previous email ID. Will this be logged in any log file.

Pratapa

Tags (1)
0 Karma

soumyasaha25
Contributor

have a look in index=_internal source=*python.log* there you can have a look at the subject field that shows the alert name and the recipients filed shows the list of email ids.
you can compare by dunning the search over different times and see the difference in the recipients to find out which email ids were changed.

Get Updates on the Splunk Community!

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...

Updated Team Landing Page in Splunk Observability

We’re making some changes to the team landing page in Splunk Observability, based on your feedback. The ...

New! Splunk Observability Search Enhancements for Splunk APM Services/Traces and ...

Regardless of where you are in Splunk Observability, you can search for relevant APM targets including service ...