<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: using sendemail in a dashboard in Reporting</title>
    <link>https://community.splunk.com/t5/Reporting/using-sendemail-in-a-dashboard/m-p/321880#M5821</link>
    <description>&lt;PRE&gt;&lt;CODE&gt;&amp;lt;dashboard&amp;gt;
  &amp;lt;label&amp;gt;test sendemail&amp;lt;/label&amp;gt;
  &amp;lt;row&amp;gt;
    &amp;lt;panel&amp;gt;
      &amp;lt;title&amp;gt;inline search&amp;lt;/title&amp;gt;
      &amp;lt;table&amp;gt;
        &amp;lt;search&amp;gt;
          &amp;lt;query&amp;gt;| metasearch index=* OR index=_* 
| stats count by index, host
| sendemail to=&amp;amp;quot;me@domain.com&amp;amp;quot; sendcsv=false subject=&amp;amp;quot;index host&amp;amp;quot;
          &amp;lt;/query&amp;gt;
          &amp;lt;earliest&amp;gt;-24h@h&amp;lt;/earliest&amp;gt;
          &amp;lt;latest&amp;gt;now&amp;lt;/latest&amp;gt;
          &amp;lt;sampleRatio&amp;gt;1&amp;lt;/sampleRatio&amp;gt;
        &amp;lt;/search&amp;gt;
        &amp;lt;option name="count"&amp;gt;20&amp;lt;/option&amp;gt;
        &amp;lt;option name="dataOverlayMode"&amp;gt;none&amp;lt;/option&amp;gt;
        &amp;lt;option name="drilldown"&amp;gt;none&amp;lt;/option&amp;gt;
        &amp;lt;option name="percentagesRow"&amp;gt;false&amp;lt;/option&amp;gt;
        &amp;lt;option name="rowNumbers"&amp;gt;false&amp;lt;/option&amp;gt;
        &amp;lt;option name="totalsRow"&amp;gt;false&amp;lt;/option&amp;gt;
        &amp;lt;option name="wrap"&amp;gt;true&amp;lt;/option&amp;gt;
      &amp;lt;/table&amp;gt;
    &amp;lt;/panel&amp;gt;
  &amp;lt;/row&amp;gt;
  &amp;lt;search id="base"&amp;gt;
    &amp;lt;query&amp;gt;| metasearch index=* OR index=_* 
| stats count by index, host
| fields count index host 
    &amp;lt;/query&amp;gt;
    &amp;lt;earliest&amp;gt;-24h@h&amp;lt;/earliest&amp;gt;
    &amp;lt;latest&amp;gt;now&amp;lt;/latest&amp;gt;
    &amp;lt;sampleRatio&amp;gt;1&amp;lt;/sampleRatio&amp;gt;
  &amp;lt;/search&amp;gt;
  &amp;lt;row&amp;gt;
    &amp;lt;panel&amp;gt;
      &amp;lt;title&amp;gt;post search host&amp;lt;/title&amp;gt;
      &amp;lt;table&amp;gt;
        &amp;lt;search base="base"&amp;gt;
          &amp;lt;query&amp;gt;
| stats sum(count) as count by host
| sendemail to=&amp;amp;quot;me@domain.com&amp;amp;quot; sendcsv=false subject=&amp;amp;quot;post host&amp;amp;quot;
          &amp;lt;/query&amp;gt;
        &amp;lt;/search&amp;gt;
        &amp;lt;option name="count"&amp;gt;20&amp;lt;/option&amp;gt;
        &amp;lt;option name="dataOverlayMode"&amp;gt;none&amp;lt;/option&amp;gt;
        &amp;lt;option name="drilldown"&amp;gt;none&amp;lt;/option&amp;gt;
        &amp;lt;option name="percentagesRow"&amp;gt;false&amp;lt;/option&amp;gt;
        &amp;lt;option name="rowNumbers"&amp;gt;false&amp;lt;/option&amp;gt;
        &amp;lt;option name="totalsRow"&amp;gt;false&amp;lt;/option&amp;gt;
        &amp;lt;option name="wrap"&amp;gt;true&amp;lt;/option&amp;gt;
      &amp;lt;/table&amp;gt;
    &amp;lt;/panel&amp;gt;
    &amp;lt;panel&amp;gt;
      &amp;lt;title&amp;gt;post search index&amp;lt;/title&amp;gt;
      &amp;lt;table&amp;gt;
        &amp;lt;search base="base"&amp;gt;
          &amp;lt;query&amp;gt;
| stats sum(count) as count by index
| sendemail to=&amp;amp;quot;me@domain.com&amp;amp;quot; sendcsv=false subject=&amp;amp;quot;post index&amp;amp;quot;
          &amp;lt;/query&amp;gt;
        &amp;lt;/search&amp;gt;
        &amp;lt;option name="count"&amp;gt;20&amp;lt;/option&amp;gt;
        &amp;lt;option name="dataOverlayMode"&amp;gt;none&amp;lt;/option&amp;gt;
        &amp;lt;option name="drilldown"&amp;gt;none&amp;lt;/option&amp;gt;
        &amp;lt;option name="percentagesRow"&amp;gt;false&amp;lt;/option&amp;gt;
        &amp;lt;option name="rowNumbers"&amp;gt;false&amp;lt;/option&amp;gt;
        &amp;lt;option name="totalsRow"&amp;gt;false&amp;lt;/option&amp;gt;
        &amp;lt;option name="wrap"&amp;gt;true&amp;lt;/option&amp;gt;
      &amp;lt;/table&amp;gt;
    &amp;lt;/panel&amp;gt;
  &amp;lt;/row&amp;gt;
&amp;lt;/dashboard&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;</description>
    <pubDate>Fri, 27 Oct 2017 12:44:09 GMT</pubDate>
    <dc:creator>fk319</dc:creator>
    <dc:date>2017-10-27T12:44:09Z</dc:date>
    <item>
      <title>using sendemail in a dashboard</title>
      <link>https://community.splunk.com/t5/Reporting/using-sendemail-in-a-dashboard/m-p/321873#M5814</link>
      <description>&lt;P&gt;I have a dashboard that I want to send an e-mail when the search finishes.  When I do the search in the search dashboard, all works fine.  When I do the search in the dashboard, I get several copies of the e-mail.&lt;BR /&gt;
Has anyone experienced this and is there a way to fix this behavior?&lt;/P&gt;</description>
      <pubDate>Fri, 20 Oct 2017 13:35:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/using-sendemail-in-a-dashboard/m-p/321873#M5814</guid>
      <dc:creator>fk319</dc:creator>
      <dc:date>2017-10-20T13:35:01Z</dc:date>
    </item>
    <item>
      <title>Re: using sendemail in a dashboard</title>
      <link>https://community.splunk.com/t5/Reporting/using-sendemail-in-a-dashboard/m-p/321874#M5815</link>
      <description>&lt;P&gt;Curious.  Please post the dash code snippet for the search and for the email send.&lt;/P&gt;</description>
      <pubDate>Fri, 20 Oct 2017 17:30:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/using-sendemail-in-a-dashboard/m-p/321874#M5815</guid>
      <dc:creator>DalJeanis</dc:creator>
      <dc:date>2017-10-20T17:30:46Z</dc:date>
    </item>
    <item>
      <title>Re: using sendemail in a dashboard</title>
      <link>https://community.splunk.com/t5/Reporting/using-sendemail-in-a-dashboard/m-p/321875#M5816</link>
      <description>&lt;PRE&gt;&lt;CODE&gt;    &amp;lt;panel&amp;gt;
      &amp;lt;title&amp;gt;inline search&amp;lt;/title&amp;gt;
      &amp;lt;table&amp;gt;
        &amp;lt;search&amp;gt;
          &amp;lt;query&amp;gt;| metasearch index=* OR index=_* 
| stats count by index, host
| sendemail to=&amp;amp;quot;me@domain.com&amp;amp;quot; sendcsv=false subject=&amp;amp;quot;index host&amp;amp;quot;
          &amp;lt;/query&amp;gt;
          &amp;lt;earliest&amp;gt;-24h@h&amp;lt;/earliest&amp;gt;
          &amp;lt;latest&amp;gt;now&amp;lt;/latest&amp;gt;
          &amp;lt;sampleRatio&amp;gt;1&amp;lt;/sampleRatio&amp;gt;
        &amp;lt;/search&amp;gt;
        &amp;lt;option name="count"&amp;gt;20&amp;lt;/option&amp;gt;
        &amp;lt;option name="dataOverlayMode"&amp;gt;none&amp;lt;/option&amp;gt;
        &amp;lt;option name="drilldown"&amp;gt;none&amp;lt;/option&amp;gt;
        &amp;lt;option name="percentagesRow"&amp;gt;false&amp;lt;/option&amp;gt;
        &amp;lt;option name="rowNumbers"&amp;gt;false&amp;lt;/option&amp;gt;
        &amp;lt;option name="totalsRow"&amp;gt;false&amp;lt;/option&amp;gt;
        &amp;lt;option name="wrap"&amp;gt;true&amp;lt;/option&amp;gt;
      &amp;lt;/table&amp;gt;
    &amp;lt;/panel&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Fri, 20 Oct 2017 18:28:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/using-sendemail-in-a-dashboard/m-p/321875#M5816</guid>
      <dc:creator>fk319</dc:creator>
      <dc:date>2017-10-20T18:28:35Z</dc:date>
    </item>
    <item>
      <title>Re: using sendemail in a dashboard</title>
      <link>https://community.splunk.com/t5/Reporting/using-sendemail-in-a-dashboard/m-p/321876#M5817</link>
      <description>&lt;P&gt;@fk319, &lt;/P&gt;

&lt;P&gt;Can you try with the following &lt;CODE&gt;tstats&lt;/CODE&gt; based SPL:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;        &amp;lt;search&amp;gt;
          &amp;lt;query&amp;gt;| tstats count WHERE index=* OR index=_* BY index, host
| sendemail to="abc@def.com" subject="index host" sendcsv=false sendresults=true
          &amp;lt;earliest&amp;gt;-24h@h&amp;lt;/earliest&amp;gt;
          &amp;lt;latest&amp;gt;now&amp;lt;/latest&amp;gt;
          &amp;lt;sampleRatio&amp;gt;1&amp;lt;/sampleRatio&amp;gt;
        &amp;lt;/search&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;You can also try another option to enable &lt;CODE&gt;schedule PDF delivery&lt;/CODE&gt; of Dashboard via email instead of sendemail command, so that emails are sent out as per predefined schedule(frequency), rather than an email everytune Dashboard is loaded.. You should configure &lt;CODE&gt;Schedule PDF delivery&lt;/CODE&gt; option following Splunk documenation: &lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/Report/GeneratePDFsofyourreportsanddashboards"&gt;http://docs.splunk.com/Documentation/Splunk/latest/Report/GeneratePDFsofyourreportsanddashboards&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 21 Oct 2017 00:13:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/using-sendemail-in-a-dashboard/m-p/321876#M5817</guid>
      <dc:creator>niketn</dc:creator>
      <dc:date>2017-10-21T00:13:48Z</dc:date>
    </item>
    <item>
      <title>Re: using sendemail in a dashboard</title>
      <link>https://community.splunk.com/t5/Reporting/using-sendemail-in-a-dashboard/m-p/321877#M5818</link>
      <description>&lt;P&gt;Try changing it to a savedsearch and referring to that report instead of using an inline search. As a panel it could be getting reloaded or loaded by a few folks or in a few tabs.&lt;/P&gt;</description>
      <pubDate>Thu, 26 Oct 2017 13:39:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/using-sendemail-in-a-dashboard/m-p/321877#M5818</guid>
      <dc:creator>sloshburch</dc:creator>
      <dc:date>2017-10-26T13:39:56Z</dc:date>
    </item>
    <item>
      <title>Re: using sendemail in a dashboard</title>
      <link>https://community.splunk.com/t5/Reporting/using-sendemail-in-a-dashboard/m-p/321878#M5819</link>
      <description>&lt;P&gt;a saved search would work as does each panel with its own search.  The problem is in my original problem I have 4 panels using the a base search and this is the case where I get multiple e-mails. &lt;/P&gt;</description>
      <pubDate>Thu, 26 Oct 2017 13:54:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/using-sendemail-in-a-dashboard/m-p/321878#M5819</guid>
      <dc:creator>fk319</dc:creator>
      <dc:date>2017-10-26T13:54:42Z</dc:date>
    </item>
    <item>
      <title>Re: using sendemail in a dashboard</title>
      <link>https://community.splunk.com/t5/Reporting/using-sendemail-in-a-dashboard/m-p/321879#M5820</link>
      <description>&lt;P&gt;Oh! This is a post-processing situation? Hook us up with the whole page so we get the full context and we'll see what we can do. Fair? The snippet you provided earlier seems like a one panel page. Or maybe I've just gotten confused on the problem.&lt;/P&gt;</description>
      <pubDate>Fri, 27 Oct 2017 12:21:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/using-sendemail-in-a-dashboard/m-p/321879#M5820</guid>
      <dc:creator>sloshburch</dc:creator>
      <dc:date>2017-10-27T12:21:45Z</dc:date>
    </item>
    <item>
      <title>Re: using sendemail in a dashboard</title>
      <link>https://community.splunk.com/t5/Reporting/using-sendemail-in-a-dashboard/m-p/321880#M5821</link>
      <description>&lt;PRE&gt;&lt;CODE&gt;&amp;lt;dashboard&amp;gt;
  &amp;lt;label&amp;gt;test sendemail&amp;lt;/label&amp;gt;
  &amp;lt;row&amp;gt;
    &amp;lt;panel&amp;gt;
      &amp;lt;title&amp;gt;inline search&amp;lt;/title&amp;gt;
      &amp;lt;table&amp;gt;
        &amp;lt;search&amp;gt;
          &amp;lt;query&amp;gt;| metasearch index=* OR index=_* 
| stats count by index, host
| sendemail to=&amp;amp;quot;me@domain.com&amp;amp;quot; sendcsv=false subject=&amp;amp;quot;index host&amp;amp;quot;
          &amp;lt;/query&amp;gt;
          &amp;lt;earliest&amp;gt;-24h@h&amp;lt;/earliest&amp;gt;
          &amp;lt;latest&amp;gt;now&amp;lt;/latest&amp;gt;
          &amp;lt;sampleRatio&amp;gt;1&amp;lt;/sampleRatio&amp;gt;
        &amp;lt;/search&amp;gt;
        &amp;lt;option name="count"&amp;gt;20&amp;lt;/option&amp;gt;
        &amp;lt;option name="dataOverlayMode"&amp;gt;none&amp;lt;/option&amp;gt;
        &amp;lt;option name="drilldown"&amp;gt;none&amp;lt;/option&amp;gt;
        &amp;lt;option name="percentagesRow"&amp;gt;false&amp;lt;/option&amp;gt;
        &amp;lt;option name="rowNumbers"&amp;gt;false&amp;lt;/option&amp;gt;
        &amp;lt;option name="totalsRow"&amp;gt;false&amp;lt;/option&amp;gt;
        &amp;lt;option name="wrap"&amp;gt;true&amp;lt;/option&amp;gt;
      &amp;lt;/table&amp;gt;
    &amp;lt;/panel&amp;gt;
  &amp;lt;/row&amp;gt;
  &amp;lt;search id="base"&amp;gt;
    &amp;lt;query&amp;gt;| metasearch index=* OR index=_* 
| stats count by index, host
| fields count index host 
    &amp;lt;/query&amp;gt;
    &amp;lt;earliest&amp;gt;-24h@h&amp;lt;/earliest&amp;gt;
    &amp;lt;latest&amp;gt;now&amp;lt;/latest&amp;gt;
    &amp;lt;sampleRatio&amp;gt;1&amp;lt;/sampleRatio&amp;gt;
  &amp;lt;/search&amp;gt;
  &amp;lt;row&amp;gt;
    &amp;lt;panel&amp;gt;
      &amp;lt;title&amp;gt;post search host&amp;lt;/title&amp;gt;
      &amp;lt;table&amp;gt;
        &amp;lt;search base="base"&amp;gt;
          &amp;lt;query&amp;gt;
| stats sum(count) as count by host
| sendemail to=&amp;amp;quot;me@domain.com&amp;amp;quot; sendcsv=false subject=&amp;amp;quot;post host&amp;amp;quot;
          &amp;lt;/query&amp;gt;
        &amp;lt;/search&amp;gt;
        &amp;lt;option name="count"&amp;gt;20&amp;lt;/option&amp;gt;
        &amp;lt;option name="dataOverlayMode"&amp;gt;none&amp;lt;/option&amp;gt;
        &amp;lt;option name="drilldown"&amp;gt;none&amp;lt;/option&amp;gt;
        &amp;lt;option name="percentagesRow"&amp;gt;false&amp;lt;/option&amp;gt;
        &amp;lt;option name="rowNumbers"&amp;gt;false&amp;lt;/option&amp;gt;
        &amp;lt;option name="totalsRow"&amp;gt;false&amp;lt;/option&amp;gt;
        &amp;lt;option name="wrap"&amp;gt;true&amp;lt;/option&amp;gt;
      &amp;lt;/table&amp;gt;
    &amp;lt;/panel&amp;gt;
    &amp;lt;panel&amp;gt;
      &amp;lt;title&amp;gt;post search index&amp;lt;/title&amp;gt;
      &amp;lt;table&amp;gt;
        &amp;lt;search base="base"&amp;gt;
          &amp;lt;query&amp;gt;
| stats sum(count) as count by index
| sendemail to=&amp;amp;quot;me@domain.com&amp;amp;quot; sendcsv=false subject=&amp;amp;quot;post index&amp;amp;quot;
          &amp;lt;/query&amp;gt;
        &amp;lt;/search&amp;gt;
        &amp;lt;option name="count"&amp;gt;20&amp;lt;/option&amp;gt;
        &amp;lt;option name="dataOverlayMode"&amp;gt;none&amp;lt;/option&amp;gt;
        &amp;lt;option name="drilldown"&amp;gt;none&amp;lt;/option&amp;gt;
        &amp;lt;option name="percentagesRow"&amp;gt;false&amp;lt;/option&amp;gt;
        &amp;lt;option name="rowNumbers"&amp;gt;false&amp;lt;/option&amp;gt;
        &amp;lt;option name="totalsRow"&amp;gt;false&amp;lt;/option&amp;gt;
        &amp;lt;option name="wrap"&amp;gt;true&amp;lt;/option&amp;gt;
      &amp;lt;/table&amp;gt;
    &amp;lt;/panel&amp;gt;
  &amp;lt;/row&amp;gt;
&amp;lt;/dashboard&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Fri, 27 Oct 2017 12:44:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/using-sendemail-in-a-dashboard/m-p/321880#M5821</guid>
      <dc:creator>fk319</dc:creator>
      <dc:date>2017-10-27T12:44:09Z</dc:date>
    </item>
    <item>
      <title>Re: using sendemail in a dashboard</title>
      <link>https://community.splunk.com/t5/Reporting/using-sendemail-in-a-dashboard/m-p/321881#M5822</link>
      <description>&lt;P&gt;@fk319, the above dashboard has three &lt;CODE&gt;sendemail&lt;/CODE&gt; searches. If you get three email each time dashboard loads (refreshes), then that is expected behavior. What is the behavior that you are seeing?&lt;/P&gt;</description>
      <pubDate>Fri, 27 Oct 2017 14:59:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/using-sendemail-in-a-dashboard/m-p/321881#M5822</guid>
      <dc:creator>niketn</dc:creator>
      <dc:date>2017-10-27T14:59:12Z</dc:date>
    </item>
    <item>
      <title>Re: using sendemail in a dashboard</title>
      <link>https://community.splunk.com/t5/Reporting/using-sendemail-in-a-dashboard/m-p/321882#M5823</link>
      <description>&lt;P&gt;That would be expected, but I am getting 10-12 e-mails.&lt;/P&gt;</description>
      <pubDate>Fri, 27 Oct 2017 15:38:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/using-sendemail-in-a-dashboard/m-p/321882#M5823</guid>
      <dc:creator>fk319</dc:creator>
      <dc:date>2017-10-27T15:38:30Z</dc:date>
    </item>
    <item>
      <title>Re: using sendemail in a dashboard</title>
      <link>https://community.splunk.com/t5/Reporting/using-sendemail-in-a-dashboard/m-p/321883#M5824</link>
      <description>&lt;P&gt;Thank you for sharing the full page. The only other things I would test it I were you is if that behavior changes on different releases (in case it's a bug that was addressed) and if btool shows that the alert_actions.conf has some settings in it causing silliness.&lt;/P&gt;

&lt;P&gt;All that said, I'm pessimistic those will produce promising answers for you so I'd suggest opening a support case since it appears feature/functionality is not working as documented. Make sure to outline the key points of this thread so as to expedite your case by reducing support's interest in asking questions we addressed here.&lt;/P&gt;</description>
      <pubDate>Mon, 30 Oct 2017 12:28:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/using-sendemail-in-a-dashboard/m-p/321883#M5824</guid>
      <dc:creator>sloshburch</dc:creator>
      <dc:date>2017-10-30T12:28:39Z</dc:date>
    </item>
  </channel>
</rss>

