docs.splunk.com/Documentation/Splunk/6.0.1/SearchReference/Sendemail
Syntax
sendemail to= [from=] [cc=]
[bcc=] [format= (html|raw|text|csv)] [inline= (true|false)]
[sendresults=(true|false)] [sendpdf=(true|false)] [priority= (highest|
high|normal|low|lowest)] [server=] [width_sort_columns=
(true|false)] [graceful=(true|false)] [sendresults=]
[sendpdf=]
from
Syntax: from=
Description: Email address from line. Defaults to
"splunk@".
This worked for me..Is there a way to change the signature also?
You can updated savedsearches.conf (where
entry for these scheduled reports are
present) to add multiple email addresses
(comma separated).
See this
http://docs.splunk.com/Documentation/
Splunk/6.0.2/Report/Schedulereports
action.email.from =
The email address that is used as the sender's address.
Default is splunk@$LOCALHOST (or whatever is set for from in
alert_actions.conf ).