Alerting

Splunk email alert not working when the owner account of the rule is disabled in AD ... expected?

gaddams
Explorer

Currently our Splunk Infrastructure is integrated with AD. I observed that a particular splunk rule which is scheduled to send email alerts was not generating any email alerts. When I created a clone of the same rule, it generated email alerts.

The only difference between the rules was the owner account of the old rule is disabled in AD whereas the owner account of the new rule is not disabled.

Could this be a reason? How to debug further here?

Thanks
Swetha

Tags (1)
0 Karma

grijhwani
Motivator

You don't say what platform you are running Splunk on, but I'll guess it is Windows. On Linux you could juggle the rules and change the ownership of existing configs. Whether there is a similar degree of freedom under Windows I don't know.

Try this search:

index=_internal "ERROR AuthenticationManagerLDAP"

Is account's ability to send e-mail (presumably through the monster that is Exchange) also tied to the AD activation? Either way it's not an unreasonable conclusion, that the inability to send the alert is a direct consequence of the deactivation of the account. If you have access to the inbound/relay logs on the mail server you could take a look to see if the mail is being rejected or simply not being seen.

To debug I would set up a dummy account, create an alert for it, see that it works, then disable the account and see what happens.

0 Karma
Get Updates on the Splunk Community!

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer Certification at ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...