Reporting

How can I get Splunk to accept "internal" email addresses for scheduled reports?

Builder

We have a large number of internal email addresses that use our internal domain - eg. address@domain.foo.local. These addresses do not always have an equivalent address with our external domain eg. address@igindex.co.uk.

When I attempt to add addresses like "address@domain.foo.local" to the list of email addresses for a scheduled search/report, I get the following error message:

Encountered the following error while trying to update: In handler 'savedsearch': One of the email addresses in 'action.email.to' is invalid

Addresses like "address@igindex.co.uk" are accepted.

What does Splunk use to validate the format of these email addresses?

How do I get it to accept these valid internal domain addresses?

0 Karma
1 Solution

Builder

Apparently (according to Splunk support), this is possible in Splunk version 4.2.3 at least, but not possible in version 4.1.5. SO I guess the answer is to upgrade to a more recent version of Splunk.

View solution in original post

0 Karma

Builder

Apparently (according to Splunk support), this is possible in Splunk version 4.2.3 at least, but not possible in version 4.1.5. SO I guess the answer is to upgrade to a more recent version of Splunk.

View solution in original post

0 Karma