- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Recently, I observed a message in Splunk Cloud (version 9.2.2403.105) stating, "Found an empty value in 'allowedDomainList' in alert_actions.conf." However, when I check the "Allowed Domain" setting in the UI by navigating to "Settings > Server settings > Email," it indicates "Leave empty for no restrictions." Despite this, I am still seeing the warning message.
#splunkcloud #splunk
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content


The bulletin message is trying to help you avoid data exfiltration by saying content in alert actions can go anywhere in the world. It will appear if the allowedDomainList is empty. If you are OK with that then you can ignore the message.
If you prefer to limit alert actions to your own domain (and/or others) then update the allowedDomainList and the bulletin messages will stop.
I'm not aware of a way to have an empty allowedDomainList and not get the warning message.
If this reply helps you, Karma would be appreciated.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I just upgraded to 9.3.1 and was also getting that warning. I set a value for allowedDomainList in system/local/alert_actions.conf, restarted the daemon, but I still get the message.
Just wanted to post in case other experience the same behavior.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Disregard. I had put the setting in the [default] stanza, moved it to the [email] stanza, now the warning has resolved.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content


The bulletin message is trying to help you avoid data exfiltration by saying content in alert actions can go anywhere in the world. It will appear if the allowedDomainList is empty. If you are OK with that then you can ignore the message.
If you prefer to limit alert actions to your own domain (and/or others) then update the allowedDomainList and the bulletin messages will stop.
I'm not aware of a way to have an empty allowedDomainList and not get the warning message.
If this reply helps you, Karma would be appreciated.
