Splunk Enterprise Security

How to change the "From" address when an alert email is generated

vikram1583
Explorer

we are using Splunk Cloud i want to modify from address(Splunk Cloud alerts@splunkcloud.com ) and want to use custom email when an alert email is generated

0 Karma

koshyk
Super Champion

you have quite lot of configuration available , but not sure how much admin rights you got with Cloud

Please see the link for configurations : https://docs.splunk.com/Documentation/Splunk/8.0.2/Alert/Emailnotification

The specific one would be:

Send emails as  (Optional) Specify a sender identification, used in the From email header field. Use an email address or a string. Strings are concatenated with @<hostname>, using the hostname specified in alert_actions.conffor the machine sending the email notification or @localhost if no hostname is specified. Defaults to splunk@<hostname> or splunk@localhost if no hostname is specified.

Or via GUI, the base settings are
As an admin go to Settings -> Server settings -> Email settings -> Send emails as and set to proper value.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

What Is Splunk? Here’s What You Can Do with Splunk

Hey Splunk Community, we know you know Splunk. You likely leverage its unparalleled ability to ingest, index, ...

Level Up Your .conf25: Splunk Arcade Comes to Boston

With .conf25 right around the corner in Boston, there’s a lot to look forward to — inspiring keynotes, ...

Manual Instrumentation with Splunk Observability Cloud: How to Instrument Frontend ...

Although it might seem daunting, as we’ve seen in this series, manual instrumentation can be straightforward ...