Splunk Enterprise

Search Head Cluster email setting between different SMTP servers

kaboom1
Explorer

Hello everyone,

Here is the story, we have a search head cluster with three members, lets call them sh1, sh2, sh3. these 3 search heads are not in the same domain/vlan, so each one used to have its own config of the SMTP server. Now we are having issues sending reports from Splunk. and I noticed that all 3 search heads are using just one SMTP server so the emails will not be delivered.

I tried to put the correct config for each search head in .../system/local/alert_actions.conf but still not working.

For now I will try to allow the search heads to communicate with all SMTP servers. but i am not sure it is the best solution.

Is there a config I am missing about the email setting in a search head cluster?

Thank you.

Labels (1)
0 Karma
Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Get the T-shirt to Prove You Survived Splunk University Bootcamp

As if Splunk University, in Las Vegas, in-person, with three days of bootcamps and labs weren’t enough, now ...

Wondering How to Build Resiliency in the Cloud?

IT leaders are choosing Splunk Cloud as an ideal cloud transformation platform to drive business resilience,  ...