I've make this alert configuration
$SPLUNK_HOME/etc/apps/My_config/local/alert_actions.conf
[email]
auth_password =
auth_username =
from = splunk.test
hostname = 10.1.1.1
mailserver = smtp.mytesting.com:465
use_ssl = 1
use_tls = 0
footer.text = My tailor-made footer
Upon testing, only saved searches under My_config app be able to use this configration. Saved search in other apps cannot use this configuration.
By default, alert_actions.conf scope to its own app.
Add the following stanza and you should be able to make it global.
Go to $SPLUNK_HOME/etc/apps/My_config/metadata/local.meta
[alert_actions/email]
version = 6.2.0
export = system