Alerting

Splunk email alert not working when the owner account of the rule is disabled in AD ... expected?

gaddams
Explorer

Currently our Splunk Infrastructure is integrated with AD. I observed that a particular splunk rule which is scheduled to send email alerts was not generating any email alerts. When I created a clone of the same rule, it generated email alerts.

The only difference between the rules was the owner account of the old rule is disabled in AD whereas the owner account of the new rule is not disabled.

Could this be a reason? How to debug further here?

Thanks
Swetha

Tags (1)
0 Karma

grijhwani
Motivator

You don't say what platform you are running Splunk on, but I'll guess it is Windows. On Linux you could juggle the rules and change the ownership of existing configs. Whether there is a similar degree of freedom under Windows I don't know.

Try this search:

index=_internal "ERROR AuthenticationManagerLDAP"

Is account's ability to send e-mail (presumably through the monster that is Exchange) also tied to the AD activation? Either way it's not an unreasonable conclusion, that the inability to send the alert is a direct consequence of the deactivation of the account. If you have access to the inbound/relay logs on the mail server you could take a look to see if the mail is being rejected or simply not being seen.

To debug I would set up a dummy account, create an alert for it, see that it works, then disable the account and see what happens.

0 Karma
Get Updates on the Splunk Community!

Combine Multiline Logs into a Single Event with SOCK - a Guide for Advanced Users

This article is the continuation of the “Combine multiline logs into a single event with SOCK - a step-by-step ...

Everything Community at .conf24!

You may have seen mention of the .conf Community Zone 'round these parts and found yourself wondering what ...

Index This | I’m short for "configuration file.” What am I?

May 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with a Special ...