What's the best practice to configure email settings on Splunk Cloud Enterprise Security (ES) and Adhoc search head to send alerts to email?
Splunk Cloud is configured by default to allow outbound emails. So when you say best practices, what exactly are you asking about? In the alert actions, you can enter your destination email address. This will send based on the criteria of your searches...
Check here as a starting point : http://docs.splunk.com/Documentation/Splunk/6.5.2/Alert/Emailnotification
Hello,
Can you tell me if it's possible to modify the "mail host" on splunk cloud?
I can't modify the mail host
Splunk Cloud is configured by default to allow outbound emails. So when you say best practices, what exactly are you asking about? In the alert actions, you can enter your destination email address. This will send based on the criteria of your searches...
Check here as a starting point : http://docs.splunk.com/Documentation/Splunk/6.5.2/Alert/Emailnotification