Hi
We have lot of alert where we need to change alert.email.to recipients to new one. Those alerts are in SHC and those are done within years directly with GUI. So I cannot manually edit those f...
Hi All, Long time lurker, first time poster. I'm the admin of our Splunk instance and I can't see an alert my colleague (of a lesser permission'ed role) created. AFAIK, the alert is set to p...
Hello!
We are working in an environment with extremely locked down permissions that are not under any of the standard user/admin accounts. The requirement for the environment is that all c...
Hi all,
following up on https://answers.splunk.com/answers/808200/splunk-alerts-not-sending-e-mail.html?childToView=810356#answer-810356.
I wanted to figure out if there were any permissions n...
We're trying to set up some searches/alerts when someone makes a change to mailboxes on Exchange Online. I'm still learning SPL, but I'm having some issues with this particular one.
Splunk gets t...
Hello fellow Splunkers,
One of our end users was attempting to investigate a Splunk Alert. When they attempted to access the URL contained in the email. They received a permissions d...
...nvoking modular alert action=logevent for search="6005"
I feel like it is a permission issue but not sure what else I can change.
Splunk Enterprise V7.0 and also on V7.1.3
Hello plp,
I am making an alert, that export a csv , the problem here is when this .csv is exported, only have rw permissions and i want to have rw-r. I make a script that convert this file w...
I have just added 2 new alert actions in Splunk. I verified that the permissions on the alert action are read for everyone, and the app for that alert action is shared to everything. I am unable to s...