Splunk Search

Why do the links to searches sent as part of alert emails have the wrong base URL and do not work?

Champion

Hi,

We've noticed that the link to searches that are sent as part of the alert email are wrong.

The link to the search has "http://mysplunk.com:8000/..."

when it should be "https://mysplunk.com/en-US/..."

As a result, none of the links that are sent with the alert are working.

Tags (4)
0 Karma

Builder

The documentation on the hostname parameter in alert alertactions.conf is a bit ambiguous on behavior for default ports on http or https but based on the documentation you can use the [protocol://]host.domain.com[:port] format to set the link base, in alertactions.conf which is presumably what gets edited as Link hostname when you go to settings->general settings->email settings in splunk web.

I would try there or in the config and specify the deisred base in protocol://host.comain.tld format. (e.g. https://splunk.mydomain.com )

See http://docs.splunk.com/Documentation/Splunk/6.2.1/Admin/Alertactionsconf

0 Karma

Champion

Thanks. I changed them on each server in ../system/local and bounced splunkweb, but it did not take. I use SHP - would it need to be changed somewhere else?

0 Karma

Champion

Anyone?

0 Karma

Builder

Try running this on your indexers and look for hostname to confirm that alert_actions.conf has been reloaded and that no other location is clobbering your setting :

$SPLUNKHOME/bin/splunk btool alertactions list --debug

0 Karma