Create a file alert_actions.conf on the system/local of the SH, and have the below config, then restart.
cat /opt/splunk/etc/system/local/alert_actions.conf
[email]
from = splunksupport@company.com
Note: - This was an old question, providing a direct answer, than getting into docs and investigating.
... View more