<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Sheduled report- empty csv file in Reporting</title>
    <link>https://community.splunk.com/t5/Reporting/Sheduled-report-empty-csv-file/m-p/393932#M6687</link>
    <description>&lt;P&gt;@alex_kh&lt;/P&gt;

&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="image"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/5518i2FE131CB623922DC/image-size/large?v=v2&amp;amp;px=999" role="button" title="image" alt="image" /&gt;&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;how many results are excuted from that alert .what is your issue suppose 10 records in your results.It will send mail wit PDF and CSV.In PDF it contains 10 results but in CSV it didn't have ..&lt;/P&gt;</description>
    <pubDate>Tue, 07 Aug 2018 14:03:54 GMT</pubDate>
    <dc:creator>harishalipaka</dc:creator>
    <dc:date>2018-08-07T14:03:54Z</dc:date>
    <item>
      <title>Sheduled report- empty csv file</title>
      <link>https://community.splunk.com/t5/Reporting/Sheduled-report-empty-csv-file/m-p/393931#M6686</link>
      <description>&lt;P&gt;Hi folks,&lt;BR /&gt;
I am creating a sheduled report which has to perform a daily check and send the pdf &amp;amp; csv via email.&lt;BR /&gt;
Pdf is send in coreect way containing &lt;STRONG&gt;all&lt;/STRONG&gt; the fileds and  events. (&amp;gt;20)&lt;/P&gt;

&lt;P&gt;BUT&lt;/P&gt;

&lt;P&gt;csv consists only out of two lines: &lt;BR /&gt;
 A1: the names of the fields&lt;BR /&gt;
A2: one single event &lt;/P&gt;

&lt;P&gt;Questions:&lt;BR /&gt;
1)How and where to check settings for the csv report to get all the data&lt;BR /&gt;
2) How can i define the format for the csv&lt;/P&gt;

&lt;P&gt;Thank you in advance&lt;/P&gt;</description>
      <pubDate>Tue, 07 Aug 2018 07:57:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/Sheduled-report-empty-csv-file/m-p/393931#M6686</guid>
      <dc:creator>alex_kh</dc:creator>
      <dc:date>2018-08-07T07:57:50Z</dc:date>
    </item>
    <item>
      <title>Re: Sheduled report- empty csv file</title>
      <link>https://community.splunk.com/t5/Reporting/Sheduled-report-empty-csv-file/m-p/393932#M6687</link>
      <description>&lt;P&gt;@alex_kh&lt;/P&gt;

&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="image"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/5518i2FE131CB623922DC/image-size/large?v=v2&amp;amp;px=999" role="button" title="image" alt="image" /&gt;&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;how many results are excuted from that alert .what is your issue suppose 10 records in your results.It will send mail wit PDF and CSV.In PDF it contains 10 results but in CSV it didn't have ..&lt;/P&gt;</description>
      <pubDate>Tue, 07 Aug 2018 14:03:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/Sheduled-report-empty-csv-file/m-p/393932#M6687</guid>
      <dc:creator>harishalipaka</dc:creator>
      <dc:date>2018-08-07T14:03:54Z</dc:date>
    </item>
    <item>
      <title>Re: Sheduled report- empty csv file</title>
      <link>https://community.splunk.com/t5/Reporting/Sheduled-report-empty-csv-file/m-p/393933#M6688</link>
      <description>&lt;P&gt;I am working with a &lt;STRONG&gt;REPORT&lt;/STRONG&gt; not Alert! (just in case it is important)&lt;/P&gt;

&lt;P&gt;From the search- i get 38 events. &lt;BR /&gt;
PDF in the email- 38 events&lt;BR /&gt;
csv in the email- &lt;STRONG&gt;1 first event&lt;/STRONG&gt;&lt;BR /&gt;
created / replaced csv lookup file - &lt;STRONG&gt;1 first event&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 07 Aug 2018 14:59:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/Sheduled-report-empty-csv-file/m-p/393933#M6688</guid>
      <dc:creator>alex_kh</dc:creator>
      <dc:date>2018-08-07T14:59:28Z</dc:date>
    </item>
  </channel>
</rss>

