Splunk Cloud Platform

Configure "From" Email Address for Email trigger actions

dwong-rtr
Explorer

We currently have email as a trigger action for Searches, Reports and Alerts. The issue arises when we try to email certain company email addresses because the address is configured to only allow internal email messages (like a distribution list type email address). The email coming from Splunk Cloud is from  alerts@splunkcloud.com. We would prefer not to make internal email addresses allow receipt of external emails. There is no way to configure the "From" address in the Triggered Actions section.

Ideally what was proposed was that we somehow configure Splunk to send the email as if it came from an internal service email address for our company. I found some documentation on Email configuration however where I would insert an internal email address to be the "FROM", the documentation states "Send email as: This value is set by your Splunk Cloud Platform implementation and cannot be changed. Entering a value in this field has no effect." 

Any suggestions on how to accomplish this without too much time investment?

Labels (1)
0 Karma
1 Solution

PrewinThomas
Motivator

@dwong-rtr 

Splunk Cloud restricts customization of the “From” address for triggered alert emails. The default sender (alerts@splunkcloud.com) is hardcoded and cannot be changed via the UI or configuration files.


But you can consider an option to set up an internal SMTP relay that receives emails from Splunk Cloud and re-sends them using your internal service address.

Regards,
Prewin
Splunk Enthusiast | Always happy to help! If this answer helped you, please consider marking it as the solution or giving a Karma. Thanks!

View solution in original post

0 Karma

dwong-rtr
Explorer

Thank you all for confirming and your various suggestions!!

0 Karma

PrewinThomas
Motivator

@dwong-rtr 

Splunk Cloud restricts customization of the “From” address for triggered alert emails. The default sender (alerts@splunkcloud.com) is hardcoded and cannot be changed via the UI or configuration files.


But you can consider an option to set up an internal SMTP relay that receives emails from Splunk Cloud and re-sends them using your internal service address.

Regards,
Prewin
Splunk Enthusiast | Always happy to help! If this answer helped you, please consider marking it as the solution or giving a Karma. Thanks!

0 Karma

livehybrid
SplunkTrust
SplunkTrust

Hi @dwong-rtr 

In Splunk Cloud Platform, you cannot customise the "From" email address for triggered alert emails; emails are always sent from alerts@splunkcloud.com and this cannot be changed due to how Splunk Cloud manages outbound mail for security and deliverability reasons. The "Send email as" option is intentionally disabled on Splunk Cloud.

🌟 Did this answer help you? If so, please consider:

  • Adding karma to show it was useful
  • Marking it as the solution if it resolved your issue
  • Commenting if you need any clarification

Your feedback encourages the volunteers in this community to continue contributing

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Since Splunk cannot be changed, you will have to change your email policy to allow messages from the specified email address.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

.conf25 Community Recap

Hello Splunkers, And just like that, .conf25 is in the books! What an incredible few days — full of learning, ...

Splunk App Developers | .conf25 Recap & What’s Next

If you stopped by the Builder Bar at .conf25 this year, thank you! The retro tech beer garden vibes were ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...