Splunk Enterprise

Search Head Cluster email setting between different SMTP servers

kaboom1
Explorer

Hello everyone,

Here is the story, we have a search head cluster with three members, lets call them sh1, sh2, sh3. these 3 search heads are not in the same domain/vlan, so each one used to have its own config of the SMTP server. Now we are having issues sending reports from Splunk. and I noticed that all 3 search heads are using just one SMTP server so the emails will not be delivered.

I tried to put the correct config for each search head in .../system/local/alert_actions.conf but still not working.

For now I will try to allow the search heads to communicate with all SMTP servers. but i am not sure it is the best solution.

Is there a config I am missing about the email setting in a search head cluster?

Thank you.

Labels (1)
0 Karma
Get Updates on the Splunk Community!

Join Us for Splunk University and Get Your Bootcamp Game On!

If you know, you know! Splunk University is the vibe this summer so register today for bootcamps galore ...

.conf24 | Learning Tracks for Security, Observability, Platform, and Developers!

.conf24 is taking place at The Venetian in Las Vegas from June 11 - 14. Continue reading to learn about the ...

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...