Splunk Enterprise

Search Head Cluster email setting between different SMTP servers

kaboom1
Explorer

Hello everyone,

Here is the story, we have a search head cluster with three members, lets call them sh1, sh2, sh3. these 3 search heads are not in the same domain/vlan, so each one used to have its own config of the SMTP server. Now we are having issues sending reports from Splunk. and I noticed that all 3 search heads are using just one SMTP server so the emails will not be delivered.

I tried to put the correct config for each search head in .../system/local/alert_actions.conf but still not working.

For now I will try to allow the search heads to communicate with all SMTP servers. but i am not sure it is the best solution.

Is there a config I am missing about the email setting in a search head cluster?

Thank you.

Labels (1)
0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...