Splunk Cloud Platform

Configure "From" Email Address for Email trigger actions

dwong-rtr
Explorer

We currently have email as a trigger action for Searches, Reports and Alerts. The issue arises when we try to email certain company email addresses because the address is configured to only allow internal email messages (like a distribution list type email address). The email coming from Splunk Cloud is from  alerts@splunkcloud.com. We would prefer not to make internal email addresses allow receipt of external emails. There is no way to configure the "From" address in the Triggered Actions section.

Ideally what was proposed was that we somehow configure Splunk to send the email as if it came from an internal service email address for our company. I found some documentation on Email configuration however where I would insert an internal email address to be the "FROM", the documentation states "Send email as: This value is set by your Splunk Cloud Platform implementation and cannot be changed. Entering a value in this field has no effect." 

Any suggestions on how to accomplish this without too much time investment?

Labels (1)
0 Karma
1 Solution

PrewinThomas
Motivator

@dwong-rtr 

Splunk Cloud restricts customization of the “From” address for triggered alert emails. The default sender (alerts@splunkcloud.com) is hardcoded and cannot be changed via the UI or configuration files.


But you can consider an option to set up an internal SMTP relay that receives emails from Splunk Cloud and re-sends them using your internal service address.

Regards,
Prewin
Splunk Enthusiast | Always happy to help! If this answer helped you, please consider marking it as the solution or giving a Karma. Thanks!

View solution in original post

0 Karma

dwong-rtr
Explorer

Thank you all for confirming and your various suggestions!!

0 Karma

PrewinThomas
Motivator

@dwong-rtr 

Splunk Cloud restricts customization of the “From” address for triggered alert emails. The default sender (alerts@splunkcloud.com) is hardcoded and cannot be changed via the UI or configuration files.


But you can consider an option to set up an internal SMTP relay that receives emails from Splunk Cloud and re-sends them using your internal service address.

Regards,
Prewin
Splunk Enthusiast | Always happy to help! If this answer helped you, please consider marking it as the solution or giving a Karma. Thanks!

0 Karma

livehybrid
SplunkTrust
SplunkTrust

Hi @dwong-rtr 

In Splunk Cloud Platform, you cannot customise the "From" email address for triggered alert emails; emails are always sent from alerts@splunkcloud.com and this cannot be changed due to how Splunk Cloud manages outbound mail for security and deliverability reasons. The "Send email as" option is intentionally disabled on Splunk Cloud.

🌟 Did this answer help you? If so, please consider:

  • Adding karma to show it was useful
  • Marking it as the solution if it resolved your issue
  • Commenting if you need any clarification

Your feedback encourages the volunteers in this community to continue contributing

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Since Splunk cannot be changed, you will have to change your email policy to allow messages from the specified email address.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...