Alerting

How to enable WARN messages in alert emails for Splunk 6.1 that were present in previous versions?

0range
Communicator

Hello everyone!

In older versions of splunk, there were WARN messages in alert emails like the following:

-- Search generated the following messages --
Message Level: WARN
1. Unable to distribute to peer named ... at uri ... because replication was unsuccessful. replicationStatus Failed
2. Unable to distribute to peer named ... at uri ... because peer has status = "Authentication Failed".

Now in 6.1 they are disabled.
Is it possible to enable it again?

Thank you in advance.

Tags (3)
0 Karma
1 Solution

0range
Communicator

Seems like we need to update the sendemail.py adding the $job.messages$ param from here

View solution in original post

0range
Communicator

Seems like we need to update the sendemail.py adding the $job.messages$ param from here

Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...