<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Sendemail command in Reporting</title>
    <link>https://community.splunk.com/t5/Reporting/Sendemail-command/m-p/176055#M3840</link>
    <description>&lt;P&gt;something like result of chart command execution but it is empty and has legend with specified field names which I used in my search (user host source).&lt;/P&gt;</description>
    <pubDate>Thu, 06 Mar 2014 11:13:16 GMT</pubDate>
    <dc:creator>andrey2007</dc:creator>
    <dc:date>2014-03-06T11:13:16Z</dc:date>
    <item>
      <title>Sendemail command</title>
      <link>https://community.splunk.com/t5/Reporting/Sendemail-command/m-p/176051#M3836</link>
      <description>&lt;P&gt;I use sendemail command in scheduled search which runs every 5 minutes .&lt;BR /&gt;
search looks like&lt;BR /&gt;
index=myindex user=* | table user host source| sendemail.py to="&lt;A href="mailto:me@company.com"&gt;me@company.com&lt;/A&gt;" subject="SPLUNK  alert" sendresults=true server=1.1.1.1&lt;/P&gt;

&lt;P&gt;Even there are no results i receive message with text "No results".&lt;/P&gt;

&lt;P&gt;Is it possible to exclude such messages?&lt;/P&gt;</description>
      <pubDate>Thu, 06 Mar 2014 10:29:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/Sendemail-command/m-p/176051#M3836</guid>
      <dc:creator>andrey2007</dc:creator>
      <dc:date>2014-03-06T10:29:45Z</dc:date>
    </item>
    <item>
      <title>Re: Sendemail command</title>
      <link>https://community.splunk.com/t5/Reporting/Sendemail-command/m-p/176052#M3837</link>
      <description>&lt;P&gt;You could change your search to a regular alert and remove the sendemail command from the search. Then you get features such as filtering for number of results &amp;gt; 0 through the alert configuration.&lt;/P&gt;</description>
      <pubDate>Thu, 06 Mar 2014 10:37:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/Sendemail-command/m-p/176052#M3837</guid>
      <dc:creator>martin_mueller</dc:creator>
      <dc:date>2014-03-06T10:37:07Z</dc:date>
    </item>
    <item>
      <title>Re: Sendemail command</title>
      <link>https://community.splunk.com/t5/Reporting/Sendemail-command/m-p/176053#M3838</link>
      <description>&lt;P&gt;Sure but when I make it i receive on email table with my results and empty graph above it. I do not know where does this graph originates from? So I tried sendemail command.&lt;/P&gt;</description>
      <pubDate>Thu, 06 Mar 2014 10:47:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/Sendemail-command/m-p/176053#M3838</guid>
      <dc:creator>andrey2007</dc:creator>
      <dc:date>2014-03-06T10:47:16Z</dc:date>
    </item>
    <item>
      <title>Re: Sendemail command</title>
      <link>https://community.splunk.com/t5/Reporting/Sendemail-command/m-p/176054#M3839</link>
      <description>&lt;P&gt;What do you mean by empty graph above it?&lt;/P&gt;</description>
      <pubDate>Thu, 06 Mar 2014 10:52:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/Sendemail-command/m-p/176054#M3839</guid>
      <dc:creator>martin_mueller</dc:creator>
      <dc:date>2014-03-06T10:52:30Z</dc:date>
    </item>
    <item>
      <title>Re: Sendemail command</title>
      <link>https://community.splunk.com/t5/Reporting/Sendemail-command/m-p/176055#M3840</link>
      <description>&lt;P&gt;something like result of chart command execution but it is empty and has legend with specified field names which I used in my search (user host source).&lt;/P&gt;</description>
      <pubDate>Thu, 06 Mar 2014 11:13:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/Sendemail-command/m-p/176055#M3840</guid>
      <dc:creator>andrey2007</dc:creator>
      <dc:date>2014-03-06T11:13:16Z</dc:date>
    </item>
    <item>
      <title>Re: Sendemail command</title>
      <link>https://community.splunk.com/t5/Reporting/Sendemail-command/m-p/176056#M3841</link>
      <description>&lt;P&gt;Is that delivered as a PDF attachment?&lt;/P&gt;</description>
      <pubDate>Thu, 06 Mar 2014 20:15:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/Sendemail-command/m-p/176056#M3841</guid>
      <dc:creator>martin_mueller</dc:creator>
      <dc:date>2014-03-06T20:15:19Z</dc:date>
    </item>
    <item>
      <title>Re: Sendemail command</title>
      <link>https://community.splunk.com/t5/Reporting/Sendemail-command/m-p/176057#M3842</link>
      <description>&lt;P&gt;yes, it is pdf attachment. My main goal is to get only table without message headers(alert name, link to results and etc.)&lt;/P&gt;</description>
      <pubDate>Fri, 07 Mar 2014 09:38:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/Sendemail-command/m-p/176057#M3842</guid>
      <dc:creator>andrey2007</dc:creator>
      <dc:date>2014-03-07T09:38:08Z</dc:date>
    </item>
    <item>
      <title>Re: Sendemail command</title>
      <link>https://community.splunk.com/t5/Reporting/Sendemail-command/m-p/176058#M3843</link>
      <description>&lt;P&gt;Turn off PDF delivery then, you won't get an empty graph anymore.&lt;/P&gt;</description>
      <pubDate>Fri, 07 Mar 2014 10:14:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/Sendemail-command/m-p/176058#M3843</guid>
      <dc:creator>martin_mueller</dc:creator>
      <dc:date>2014-03-07T10:14:11Z</dc:date>
    </item>
    <item>
      <title>Re: Sendemail command</title>
      <link>https://community.splunk.com/t5/Reporting/Sendemail-command/m-p/176059#M3844</link>
      <description>&lt;P&gt;But i will get alert name, link to results and etc. even if i turn off pdf delivery and include inline results(&lt;/P&gt;</description>
      <pubDate>Fri, 07 Mar 2014 12:02:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/Sendemail-command/m-p/176059#M3844</guid>
      <dc:creator>andrey2007</dc:creator>
      <dc:date>2014-03-07T12:02:38Z</dc:date>
    </item>
    <item>
      <title>Re: Sendemail command</title>
      <link>https://community.splunk.com/t5/Reporting/Sendemail-command/m-p/176060#M3845</link>
      <description>&lt;P&gt;Yup, those are hardcoded into the sendemail command. You can copy that python file and add your own command to splunk, say "mysendemail", and use that in alert_actions.conf. In there you can change how you'd like your mails to look.&lt;/P&gt;</description>
      <pubDate>Fri, 07 Mar 2014 12:34:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/Sendemail-command/m-p/176060#M3845</guid>
      <dc:creator>martin_mueller</dc:creator>
      <dc:date>2014-03-07T12:34:03Z</dc:date>
    </item>
    <item>
      <title>Re: Sendemail command</title>
      <link>https://community.splunk.com/t5/Reporting/Sendemail-command/m-p/176061#M3846</link>
      <description>&lt;P&gt;Yes I had to choose this way and now i am modifying sendemail.py in search app.&lt;/P&gt;</description>
      <pubDate>Fri, 07 Mar 2014 12:55:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/Sendemail-command/m-p/176061#M3846</guid>
      <dc:creator>andrey2007</dc:creator>
      <dc:date>2014-03-07T12:55:48Z</dc:date>
    </item>
  </channel>
</rss>

