Reporting

In GUI, I cannot see email settings, which was deployed by Deployment Server, in the GUI

Masa
Splunk Employee
Splunk Employee

I deployed alert_actions.conf to a search head through a Deployment Server.
The email alert works. But I cannot see the setting in the WebGUI. It shows no settings.

In splunkd.log, there is no error or warning message.
A btool output shows the correct email settings.

Why can I see the settings through GUI?
How I can make it available through GUI, too?

0 Karma
1 Solution

Masa
Splunk Employee
Splunk Employee

It is related to a permission for an App which was deployed by a deployment server.

Usually you do not encounter this situation because Splunk Web can still shows each apps configuration per app.

But, "email" setting must be "global". So, you need local.meta to set "export = system".

- local.meta
[]
# This stanza is to make all the app's configuration to "global"
export = system

Or, if it's only for email.

- local.meta
[alert_actions/email]
export = system
owner = nobody

View solution in original post

thambisetty
SplunkTrust
SplunkTrust

could u tell me how did u configured email settings?

————————————
If this helps, give a like below.
0 Karma

Masa
Splunk Employee
Splunk Employee

It is related to a permission for an App which was deployed by a deployment server.

Usually you do not encounter this situation because Splunk Web can still shows each apps configuration per app.

But, "email" setting must be "global". So, you need local.meta to set "export = system".

- local.meta
[]
# This stanza is to make all the app's configuration to "global"
export = system

Or, if it's only for email.

- local.meta
[alert_actions/email]
export = system
owner = nobody
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

A Four-Part Event Series: Full Stack Observability For the AI Era

As AI reshapes applications, infrastructure, and the way teams operate, the traditional boundaries of ...

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Event Series: Level up your SOC: Advancing with Splunk Enterprise Security

AI has fundamentally raised the stakes for security operations, and this three-part series is your guide to ...