Alerting

Splunk email alert not working when the owner account of the rule is disabled in AD ... expected?

gaddams
Explorer

Currently our Splunk Infrastructure is integrated with AD. I observed that a particular splunk rule which is scheduled to send email alerts was not generating any email alerts. When I created a clone of the same rule, it generated email alerts.

The only difference between the rules was the owner account of the old rule is disabled in AD whereas the owner account of the new rule is not disabled.

Could this be a reason? How to debug further here?

Thanks
Swetha

Tags (1)
0 Karma

grijhwani
Motivator

You don't say what platform you are running Splunk on, but I'll guess it is Windows. On Linux you could juggle the rules and change the ownership of existing configs. Whether there is a similar degree of freedom under Windows I don't know.

Try this search:

index=_internal "ERROR AuthenticationManagerLDAP"

Is account's ability to send e-mail (presumably through the monster that is Exchange) also tied to the AD activation? Either way it's not an unreasonable conclusion, that the inability to send the alert is a direct consequence of the deactivation of the account. If you have access to the inbound/relay logs on the mail server you could take a look to see if the mail is being rejected or simply not being seen.

To debug I would set up a dummy account, create an alert for it, see that it works, then disable the account and see what happens.

0 Karma
Get Updates on the Splunk Community!

What's new in Splunk Cloud Platform 9.1.2312?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.1.2312! Analysts can ...

What’s New in Splunk Security Essentials 3.8.0?

Splunk Security Essentials (SSE) is an app that can amplify the power of your existing Splunk Cloud Platform, ...

Let’s Get You Certified – Vegas-Style at .conf24

Are you ready to level up your Splunk game? Then, let’s get you certified live at .conf24 – our annual user ...