All of my Splunk alerts and reports are getting quarantined by Microsoft's spam filter, the reason being: "Quarantine reason:
Phish". The alerts are simply sent from "splunk" with no email address associated with it, so I can't even add it to "Safe Senders/Recipients".
You can change your Splunk email settings to have alerts and reports come from an email address.
You can change your Splunk email settings to have alerts and reports come from an email address.
Yes, that did work. On the SH, I went to Settings > Server settings > Email settings > edited the Send emails as field to a proper email address.
As an FYI, you may have to edit savedsearches.conf, specifically the line: "action.email.from = "