Splunk Search

SMTP authentication and SPLUNK database separate

wingyip
New Member

Dear sir,

I am evaluating the SPLUNK with windows version. I want to clarify the following questions:

  1. How to configure SMTP authentication
  2. I want to backup the database which is storing logs with separate partition.

Thanks!

Tags (1)
0 Karma

MarioM
Motivator
0 Karma

MarioM
Motivator

1-I think currently it's not possible to do SMTP auth but it will be in 4.2. The workaround could be to use a scripted alert where inside your script you can configure smtp auth.

2-When Splunk is indexing, the data moves through a series of stages and you have info about backup strategy here http://www.splunk.com/base/Documentation/latest/Admin/BackupIndexedData and about indexes partition http://www.splunk.com/base/Documentation/latest/Admin/HowSplunkstoresindexes

hope this help

MarioM
Motivator

no i donot know the release day of 4.2

0 Karma

wingyip
New Member

Do you have release day of the 4.2 version ?

0 Karma

MarioM
Motivator
0 Karma

MarioM
Motivator

no not the alert_actions.conf but your own script

0 Karma

wingyip
New Member

Hi, about the SMTP auth, your meaning is to edit file alert_actions.conf. And which field has to edit for the auth. Is there any examples for me to do this?

Thanks!

0 Karma
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...