Hello everyone,
Here is the story, we have a search head cluster with three members, lets call them sh1, sh2, sh3. these 3 search heads are not in the same domain/vlan, so each one used to have its own config of the SMTP server. Now we are having issues sending reports from Splunk. and I noticed that all 3 search heads are using just one SMTP server so the emails will not be delivered.
I tried to put the correct config for each search head in .../system/local/alert_actions.conf but still not working.
For now I will try to allow the search heads to communicate with all SMTP servers. but i am not sure it is the best solution.
Is there a config I am missing about the email setting in a search head cluster?
Thank you.