Hello all!
I am trying to get a central config for smtp email config that I will deploy to my search heads. I notice when I go into the UI under Server Settings -> Email settings that I can configure smtp. I notice it created a file called alert_actions.conf in etc/system/local. So I assume (like everything else in splunk) I can deploy this as part of an app that splunk will read for its email config. The problem is that when I remove this file, the email config stays intact in splunk. Is this the only place this info is stored? What am I missing?
Hi brent_weaver, alert_actions.conf is indeed where the mailserver settings are. Here's the doc on it : http://docs.splunk.com/Documentation/Splunk/6.3.0/Admin/Alertactionsconf
Did you restart splunk after removing alert_actions.conf? Splunk will cache many config settings in memory.