The user 'nobody' is supposed to be for 'configuration items' that aren't assigned a user.
I'm experiencing the same errors, and I would also like to know why it occurs, and how to stop it.
... View more
Sorry to revive an old post, but I was doing some searches, and came across this question...
You could just set the URL to go to by editing /opt/splunk/etc/system/local/alert_actions.conf
[email]
from = Splunk Platform
hostname = http://indexer1:8000
reportPaperSize = a4
reportServerURL =
subject = Analytics Alert: \$name\$
mailserver = x.y.z.a
... View more