<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How to set up an Email Report after Alert? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-to-set-up-an-Email-Report-after-Alert/m-p/607094#M105431</link>
    <description>&lt;P&gt;I would like to have a report emailed to me a few minutes after an alert goes off.&amp;nbsp; While the alert can include the results, it is based on something specific and will not have all the information I need.&amp;nbsp; Let's say the alert is set up to catch too many host communication&amp;nbsp; errors to a specific endpoint.&amp;nbsp; Errors&amp;gt;100.&amp;nbsp; Currently I either go to the alert and alter it to make a time chart to see any trends, or go to a specific dashboard that shows communication errors with other endpoints, network status, response times, etc.&amp;nbsp; When the problem goes away I take all the Splunk graphs and make an incident report.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I would like to have a report with graphs and other info based on the dashboard emailed to me at the time of the alert and 10 minutes after.&amp;nbsp; &amp;nbsp;Sometimes I can get to my email, but not to Splunk.&amp;nbsp; &amp;nbsp;This would also help with the incident report and make them more uniform.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Is this possible?&amp;nbsp; I have not worked with reports much.&amp;nbsp; Can a report be triggered by a separate search?&amp;nbsp; I could not find that answer online so I believe it can't.&amp;nbsp; I could write a query that looks at the last time an alert went off and have that trigger the associated report if possible.&amp;nbsp; I would like some type of PDF that I can just attach to the incident report.&amp;nbsp; More importantly I would like to have much more detail emailed to me after an alert.&amp;nbsp; I'm not even sure what an emailed report looks like.&amp;nbsp; I could google that, but If I can't trigger it there is no need for the report.&amp;nbsp; Although in reading about reports I want to use them more with dashboards.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 26 Jul 2022 20:51:24 GMT</pubDate>
    <dc:creator>MScottFoley</dc:creator>
    <dc:date>2022-07-26T20:51:24Z</dc:date>
    <item>
      <title>How to set up an Email Report after Alert?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-set-up-an-Email-Report-after-Alert/m-p/607094#M105431</link>
      <description>&lt;P&gt;I would like to have a report emailed to me a few minutes after an alert goes off.&amp;nbsp; While the alert can include the results, it is based on something specific and will not have all the information I need.&amp;nbsp; Let's say the alert is set up to catch too many host communication&amp;nbsp; errors to a specific endpoint.&amp;nbsp; Errors&amp;gt;100.&amp;nbsp; Currently I either go to the alert and alter it to make a time chart to see any trends, or go to a specific dashboard that shows communication errors with other endpoints, network status, response times, etc.&amp;nbsp; When the problem goes away I take all the Splunk graphs and make an incident report.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I would like to have a report with graphs and other info based on the dashboard emailed to me at the time of the alert and 10 minutes after.&amp;nbsp; &amp;nbsp;Sometimes I can get to my email, but not to Splunk.&amp;nbsp; &amp;nbsp;This would also help with the incident report and make them more uniform.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Is this possible?&amp;nbsp; I have not worked with reports much.&amp;nbsp; Can a report be triggered by a separate search?&amp;nbsp; I could not find that answer online so I believe it can't.&amp;nbsp; I could write a query that looks at the last time an alert went off and have that trigger the associated report if possible.&amp;nbsp; I would like some type of PDF that I can just attach to the incident report.&amp;nbsp; More importantly I would like to have much more detail emailed to me after an alert.&amp;nbsp; I'm not even sure what an emailed report looks like.&amp;nbsp; I could google that, but If I can't trigger it there is no need for the report.&amp;nbsp; Although in reading about reports I want to use them more with dashboards.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 26 Jul 2022 20:51:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-set-up-an-Email-Report-after-Alert/m-p/607094#M105431</guid>
      <dc:creator>MScottFoley</dc:creator>
      <dc:date>2022-07-26T20:51:24Z</dc:date>
    </item>
  </channel>
</rss>

