Alerting

How to reenable email alerts after they have been disabled, and is it possible to limit the type of content that is emailed (ex: no raw event data)?

IRHM73
Motivator

Hi, I wonder whether someone may be able to help me please.

Through the 'Save as Alert' process I have created a report which I want to run at a given time and email the results.

The problem I have is that I am not receiving the email containing the results.

I have only just taken over the 'admin' role within Splunk, so it's a 'steep learning curve' at the moment, but I'm told my predecessor disabled the email functionality because from a security aspect, they didn't want people to be able to email 'Raw Data'.

I have looked at the Splunk documentation and I think I've followed the 'Alert' process correctly, but could someone tell me please:

  • How do I re-enable the email functionality
  • Is it possible to limit the type of information that can be emailed, i.e. non Raw Event information.

Any help would be gratefully received.

Many thanks and kind regards

Chris

0 Karma
1 Solution

renjith_nair
Legend

Check your logs to find out any errors. Logs are available in $SPLUNK_HOME/var/log/splunk/ and splunkd.log and scheduler.log should help you.

Email configuration is available under Server settings » Email settings and make sure that all configuration is intact.

If you are admin on your search head server , make sure that mail is enabled on your server(try a mail command from your server) or ask your server admin to check that.

It is possible to limit the type of information that can be emailed, because its the result of your search which is going as email content. Restrict your search only to show required fields and schedule the search

Hope this helps!

Happy Splunking!

View solution in original post

renjith_nair
Legend

Check your logs to find out any errors. Logs are available in $SPLUNK_HOME/var/log/splunk/ and splunkd.log and scheduler.log should help you.

Email configuration is available under Server settings » Email settings and make sure that all configuration is intact.

If you are admin on your search head server , make sure that mail is enabled on your server(try a mail command from your server) or ask your server admin to check that.

It is possible to limit the type of information that can be emailed, because its the result of your search which is going as email content. Restrict your search only to show required fields and schedule the search

Hope this helps!

Happy Splunking!

IRHM73
Motivator

Hi @renjith.nair, thank you very much for the info, really very helpful.

Many thanks and kind regards

Chris

0 Karma

renjith_nair
Legend

If it helped please mark it as answer 🙂 . Did you find where the issue is now?

Happy Splunking!
0 Karma

IRHM73
Motivator

Hi, like I said I'm very new to the admin role, in fact there are actually a few of us sharing the role and unfortunately I'm one of the admin personnel without the hardware to search the logs. Yes I know it's a little crazy! however I'll be working with someone who has both more knowledge than I and has the correct hardware to do this.

Many thanks and kind regards

Chris

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...