Splunk Cloud Platform

About warning showing in Splunk Cloud message box

Anurag
Engager

Recently, I observed a message in Splunk Cloud (version 9.2.2403.105) stating, "Found an empty value in 'allowedDomainList' in alert_actions.conf." However, when I check the "Allowed Domain" setting in the UI by navigating to "Settings > Server settings > Email," it indicates "Leave empty for no restrictions." Despite this, I am still seeing the warning message.

Anurag_0-1724170851761.png

Anurag_1-1724170859538.png

 

#splunkcloud  #splunk

0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

The bulletin message is trying to help you avoid data exfiltration by saying content in alert actions can go anywhere in the world.  It will appear if the allowedDomainList is empty.  If you are OK with that then you can ignore the message.

If you prefer to limit alert actions to your own domain (and/or others) then update the allowedDomainList and the bulletin messages will stop.

I'm not aware of a way to have an empty allowedDomainList and not get the warning message.

---
If this reply helps you, Karma would be appreciated.

View solution in original post

JyPl4wNYu7GV1uL
Explorer

I just upgraded to 9.3.1 and was also getting that warning.  I set a value for allowedDomainList in system/local/alert_actions.conf, restarted the daemon, but I still get the message.

Just wanted to post in case other experience the same behavior.

0 Karma

JyPl4wNYu7GV1uL
Explorer

Disregard.  I had put the setting in the [default] stanza, moved it to the [email] stanza, now the warning has resolved.

richgalloway
SplunkTrust
SplunkTrust

The bulletin message is trying to help you avoid data exfiltration by saying content in alert actions can go anywhere in the world.  It will appear if the allowedDomainList is empty.  If you are OK with that then you can ignore the message.

If you prefer to limit alert actions to your own domain (and/or others) then update the allowedDomainList and the bulletin messages will stop.

I'm not aware of a way to have an empty allowedDomainList and not get the warning message.

---
If this reply helps you, Karma would be appreciated.

LS1
Loves-to-Learn Lots

Hello,

I have this instance on my personal computer and am a little confused about how to protect myself. I do not know which (or how to determine) allowedDomainList I should use. Where do I find the necessary information to fill that field in?

Sorry, still a beginner.. 

 

0 Karma

richgalloway
SplunkTrust
SplunkTrust

The allowedDomainList setting can be in any alert_actions.conf file on your search head(s).  Precedence rules apply, however.  See https://docs.splunk.com/Documentation/Splunk/9.4.2/Admin/Wheretofindtheconfigurationfiles

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Fall Into Learning with New Splunk Education Courses

Every month, Splunk Education releases new courses to help you branch out, strengthen your data science roots, ...

Super Optimize your Splunk Stats Searches: Unlocking the Power of tstats, TERM, and ...

By Martin Hettervik, Senior Consultant and Team Leader at Accelerate at Iver, Splunk MVPThe stats command is ...

How Splunk Observability Cloud Prevented a Major Payment Crisis in Minutes

Your bank's payment processing system is humming along during a busy afternoon, handling millions in hourly ...