Alerting

Splunk email alert not working when the owner account of the rule is disabled in AD ... expected?

gaddams
Explorer

Currently our Splunk Infrastructure is integrated with AD. I observed that a particular splunk rule which is scheduled to send email alerts was not generating any email alerts. When I created a clone of the same rule, it generated email alerts.

The only difference between the rules was the owner account of the old rule is disabled in AD whereas the owner account of the new rule is not disabled.

Could this be a reason? How to debug further here?

Thanks
Swetha

Tags (1)
0 Karma

grijhwani
Motivator

You don't say what platform you are running Splunk on, but I'll guess it is Windows. On Linux you could juggle the rules and change the ownership of existing configs. Whether there is a similar degree of freedom under Windows I don't know.

Try this search:

index=_internal "ERROR AuthenticationManagerLDAP"

Is account's ability to send e-mail (presumably through the monster that is Exchange) also tied to the AD activation? Either way it's not an unreasonable conclusion, that the inability to send the alert is a direct consequence of the deactivation of the account. If you have access to the inbound/relay logs on the mail server you could take a look to see if the mail is being rejected or simply not being seen.

To debug I would set up a dummy account, create an alert for it, see that it works, then disable the account and see what happens.

0 Karma
Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Wondering How to Build Resiliency in the Cloud?

IT leaders are choosing Splunk Cloud as an ideal cloud transformation platform to drive business resilience,  ...

Updated Data Management and AWS GDI Inventory in Splunk Observability

We’re making some changes to Data Management and Infrastructure Inventory for AWS. The Data Management page, ...