<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Why are the reports not sending email of more than ~70 events in Suse Linux enterprise? in Reporting</title>
    <link>https://community.splunk.com/t5/Reporting/Why-are-the-reports-not-sending-email-of-more-than-70-events-in/m-p/351427#M6179</link>
    <description>&lt;P&gt;Reports and sendemail not sending an email of more than about 70 events - The maximum number of events varies depending of how much data per event. What I see is that  sendemail.py is failing.&lt;BR /&gt;&lt;BR /&gt;
Sendemail in the search line is doing the same, and the error is: &lt;STRONG&gt;&lt;EM&gt;External search command 'sendemail' returned error code 1.&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;

&lt;P&gt;I tried to add an increase several parameters in the .conf files like indicated on the groups but it did not make a difference &lt;BR /&gt;
&lt;A href="https://answers.splunk.com/answers/542862/how-to-overcome-csv-max-results-to-email.html"&gt;https://answers.splunk.com/answers/542862/how-to-overcome-csv-max-results-to-email.html&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Here is the splunkd.log filtered by the scheduler and sendemail events examples:&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;Scheduler:&lt;/STRONG&gt; &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;04-18-2018 15:00:00.780 -0300 ERROR ScriptRunner - stderr from '/opt/splunk/bin/python /opt/splunk/etc/apps/search/bin/sendemail.py "results_link=https://quebec:8000/app/search/@go?sid=scheduler__admin__search__RMD5305669048a8da3b1_at_1524074400_13" "ssname=R4_TEST" "graceful=True" "trigger_time=1524074400" results_file="/opt/splunk/var/run/splunk/dispatch/scheduler__admin__search__RMD5305669048a8da3b1_at_1524074400_13/results.csv.gz"':      for line in csvr:
04-18-2018 15:00:00.780 -0300 ERROR ScriptRunner - stderr from '/opt/splunk/bin/python /opt/splunk/etc/apps/search/bin/sendemail.py "results_link=https://quebec:8000/app/search/@go?sid=scheduler__admin__search__RMD5305669048a8da3b1_at_1524074400_13" "ssname=R4_TEST" "graceful=True" "trigger_time=1524074400" results_file="/opt/splunk/var/run/splunk/dispatch/scheduler__admin__search__RMD5305669048a8da3b1_at_1524074400_13/results.csv.gz"':  _csv.Error: line contains NULL byte
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;&lt;STRONG&gt;Sendemail&lt;/STRONG&gt;&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;04-12-2018 12:00:05.484 -0300 ERROR script - sid:scheduler__admin__search__RMD5bf6f3132e2acfda9_at_1523545200_31 External search command 'sendemail' returned error code 1.
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Appreciate your help, thanks&lt;/P&gt;</description>
    <pubDate>Fri, 20 Apr 2018 11:53:55 GMT</pubDate>
    <dc:creator>hugohctint</dc:creator>
    <dc:date>2018-04-20T11:53:55Z</dc:date>
    <item>
      <title>Why are the reports not sending email of more than ~70 events in Suse Linux enterprise?</title>
      <link>https://community.splunk.com/t5/Reporting/Why-are-the-reports-not-sending-email-of-more-than-70-events-in/m-p/351427#M6179</link>
      <description>&lt;P&gt;Reports and sendemail not sending an email of more than about 70 events - The maximum number of events varies depending of how much data per event. What I see is that  sendemail.py is failing.&lt;BR /&gt;&lt;BR /&gt;
Sendemail in the search line is doing the same, and the error is: &lt;STRONG&gt;&lt;EM&gt;External search command 'sendemail' returned error code 1.&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;

&lt;P&gt;I tried to add an increase several parameters in the .conf files like indicated on the groups but it did not make a difference &lt;BR /&gt;
&lt;A href="https://answers.splunk.com/answers/542862/how-to-overcome-csv-max-results-to-email.html"&gt;https://answers.splunk.com/answers/542862/how-to-overcome-csv-max-results-to-email.html&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Here is the splunkd.log filtered by the scheduler and sendemail events examples:&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;Scheduler:&lt;/STRONG&gt; &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;04-18-2018 15:00:00.780 -0300 ERROR ScriptRunner - stderr from '/opt/splunk/bin/python /opt/splunk/etc/apps/search/bin/sendemail.py "results_link=https://quebec:8000/app/search/@go?sid=scheduler__admin__search__RMD5305669048a8da3b1_at_1524074400_13" "ssname=R4_TEST" "graceful=True" "trigger_time=1524074400" results_file="/opt/splunk/var/run/splunk/dispatch/scheduler__admin__search__RMD5305669048a8da3b1_at_1524074400_13/results.csv.gz"':      for line in csvr:
04-18-2018 15:00:00.780 -0300 ERROR ScriptRunner - stderr from '/opt/splunk/bin/python /opt/splunk/etc/apps/search/bin/sendemail.py "results_link=https://quebec:8000/app/search/@go?sid=scheduler__admin__search__RMD5305669048a8da3b1_at_1524074400_13" "ssname=R4_TEST" "graceful=True" "trigger_time=1524074400" results_file="/opt/splunk/var/run/splunk/dispatch/scheduler__admin__search__RMD5305669048a8da3b1_at_1524074400_13/results.csv.gz"':  _csv.Error: line contains NULL byte
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;&lt;STRONG&gt;Sendemail&lt;/STRONG&gt;&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;04-12-2018 12:00:05.484 -0300 ERROR script - sid:scheduler__admin__search__RMD5bf6f3132e2acfda9_at_1523545200_31 External search command 'sendemail' returned error code 1.
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Appreciate your help, thanks&lt;/P&gt;</description>
      <pubDate>Fri, 20 Apr 2018 11:53:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/Why-are-the-reports-not-sending-email-of-more-than-70-events-in/m-p/351427#M6179</guid>
      <dc:creator>hugohctint</dc:creator>
      <dc:date>2018-04-20T11:53:55Z</dc:date>
    </item>
  </channel>
</rss>

