Splunk Enterprise Security

How to change the "From" address when an alert email is generated

vikram1583
Explorer

we are using Splunk Cloud i want to modify from address(Splunk Cloud alerts@splunkcloud.com ) and want to use custom email when an alert email is generated

0 Karma

koshyk
Super Champion

you have quite lot of configuration available , but not sure how much admin rights you got with Cloud

Please see the link for configurations : https://docs.splunk.com/Documentation/Splunk/8.0.2/Alert/Emailnotification

The specific one would be:

Send emails as  (Optional) Specify a sender identification, used in the From email header field. Use an email address or a string. Strings are concatenated with @<hostname>, using the hostname specified in alert_actions.conffor the machine sending the email notification or @localhost if no hostname is specified. Defaults to splunk@<hostname> or splunk@localhost if no hostname is specified.

Or via GUI, the base settings are
As an admin go to Settings -> Server settings -> Email settings -> Send emails as and set to proper value.

0 Karma
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.


Introducing Unified TDIR with the New Enterprise Security 8.2

Read the blog
Get Updates on the Splunk Community!

[Live Demo] Watch SOC transformation in action with the reimagined Splunk Enterprise ...

Overwhelmed SOC? Splunk ES Has Your Back Tool sprawl, alert fatigue, and endless context switching are making ...

What’s New & Next in Splunk SOAR

Security teams today are dealing with more alerts, more tools, and more pressure than ever.  Join us on ...

Your Voice Matters! Help Us Shape the New Splunk Lantern Experience

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...