Hi there, I've spent 2 days trying to configure the Splunk emails. Not sure what the settings in alert_actions.conf file are but by default the sender is set to"splunk_sender" or something like that....so in order to send an email you have to specify the "from" property. Also you can change it in Settings > Searches, reports and alerts. Find your search or alert (if you want to use the alert email action) click Edit > Advanced edit and then change the value of "action.email.from". Also trying to send an email using gmail's smtp is a bit tricky as probably you have 2-layer authentication. I would recommend you to change the server.
... View more