<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to use action.email.reportFileName to remove the automatic timestamp from the csv output filename attached to emails? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-to-use-action-email-reportFileName-to-remove-the-automatic/m-p/271875#M52231</link>
    <description>&lt;P&gt;Did you replace &lt;CODE&gt;$name$-$time:%Y-%m-%d$&lt;/CODE&gt; with &lt;CODE&gt;.csv&lt;/CODE&gt;? The .csv extension is added automatically, you should just remove the timestamp ports which is &lt;CODE&gt;-$time:%Y-%m-%d$&lt;/CODE&gt;.&lt;/P&gt;</description>
    <pubDate>Fri, 09 Sep 2016 20:11:21 GMT</pubDate>
    <dc:creator>somesoni2</dc:creator>
    <dc:date>2016-09-09T20:11:21Z</dc:date>
    <item>
      <title>How to use action.email.reportFileName to remove the automatic timestamp from the csv output filename attached to emails?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-use-action-email-reportFileName-to-remove-the-automatic/m-p/271874#M52230</link>
      <description>&lt;P&gt;I'm looking for an option to remove the automatic timestamp from the csv output filename attached to emails.&lt;/P&gt;

&lt;P&gt;According to both the doco (&lt;A href="http://docs.splunk.com/Documentation/Splunk/6.4.3/Admin/Alertactionsconf"&gt;http://docs.splunk.com/Documentation/Splunk/6.4.3/Admin/Alertactionsconf&lt;/A&gt;)&lt;BR /&gt;
and this answer:  &lt;A href="https://answers.splunk.com/answers/439644/removing-time-stamp-from-the-emailed-csv-file.html"&gt;https://answers.splunk.com/answers/439644/removing-time-stamp-from-the-emailed-csv-file.html&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;It sounds like it should be as simple as going into Advanced Edit and adjusting action.email.reportFileName so that the default ($name$-$time:%Y-%m-%d$) is removed and putting in .csv... which I've done.&lt;/P&gt;

&lt;P&gt;Any ideas why I'm still getting the default : Searchname-yyyy-mm-dd&lt;/P&gt;

&lt;P&gt;We do have a search cluster that I'm not 100% familiar with but I have verified that the Advanced Edit setting replicated to each node. I've even looked at the savedsearches.conf on in the CLI for each node and verified that it has the &lt;BR /&gt;
action.email.reportFileName =.csv&lt;/P&gt;

&lt;P&gt;Thanks in advance for your assistance!&lt;/P&gt;</description>
      <pubDate>Fri, 09 Sep 2016 18:47:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-use-action-email-reportFileName-to-remove-the-automatic/m-p/271874#M52230</guid>
      <dc:creator>kearaspoor</dc:creator>
      <dc:date>2016-09-09T18:47:45Z</dc:date>
    </item>
    <item>
      <title>Re: How to use action.email.reportFileName to remove the automatic timestamp from the csv output filename attached to emails?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-use-action-email-reportFileName-to-remove-the-automatic/m-p/271875#M52231</link>
      <description>&lt;P&gt;Did you replace &lt;CODE&gt;$name$-$time:%Y-%m-%d$&lt;/CODE&gt; with &lt;CODE&gt;.csv&lt;/CODE&gt;? The .csv extension is added automatically, you should just remove the timestamp ports which is &lt;CODE&gt;-$time:%Y-%m-%d$&lt;/CODE&gt;.&lt;/P&gt;</description>
      <pubDate>Fri, 09 Sep 2016 20:11:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-use-action-email-reportFileName-to-remove-the-automatic/m-p/271875#M52231</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2016-09-09T20:11:21Z</dc:date>
    </item>
    <item>
      <title>Re: How to use action.email.reportFileName to remove the automatic timestamp from the csv output filename attached to emails?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-use-action-email-reportFileName-to-remove-the-automatic/m-p/271876#M52232</link>
      <description>&lt;P&gt;Sorry! Didn't realize that my original post cut out some information regarding the file name.&lt;/P&gt;

&lt;P&gt;I've tried removing the -$time:%Y-%m-d$ as  you recommend, leaving just $name$&lt;BR /&gt;
I've also tried removing the entire default ($name$-$time:%Y-%m-%d$) and manually entering just a filename without the .csv at the end.&lt;BR /&gt;
And I've also tried removing the entire default, manually entering the filename with the .csv at the end.&lt;/P&gt;

&lt;P&gt;All of them end up with the default ($name$-$time:%Y-%m-%d$) as the results.&lt;/P&gt;</description>
      <pubDate>Fri, 09 Sep 2016 20:15:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-use-action-email-reportFileName-to-remove-the-automatic/m-p/271876#M52232</guid>
      <dc:creator>kearaspoor</dc:creator>
      <dc:date>2016-09-09T20:15:49Z</dc:date>
    </item>
    <item>
      <title>Re: How to use action.email.reportFileName to remove the automatic timestamp from the csv output filename attached to emails?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-use-action-email-reportFileName-to-remove-the-automatic/m-p/271877#M52233</link>
      <description>&lt;P&gt;Received word from vendor support that this issue is an official bug that should be resolved in version 6.5.1&lt;/P&gt;</description>
      <pubDate>Mon, 07 Nov 2016 16:11:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-use-action-email-reportFileName-to-remove-the-automatic/m-p/271877#M52233</guid>
      <dc:creator>kearaspoor</dc:creator>
      <dc:date>2016-11-07T16:11:40Z</dc:date>
    </item>
  </channel>
</rss>

