<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic combining alerts into one daily email report in Reporting</title>
    <link>https://community.splunk.com/t5/Reporting/combining-alerts-into-one-daily-email-report/m-p/441440#M7128</link>
    <description>&lt;P&gt;I want to generate one daily email showing ALL DMC alerts that have been produced in the last 12 or 24 hours, and wondered if it is possible?&lt;/P&gt;

&lt;P&gt;alerts are generated individually for each of the 8 main DMC alerts, and we currently receive individual emails for these.&lt;BR /&gt;
I would like to be presented with one email at the start of the day showing me alerts which have been reported out in the last 12 or 24hrs&lt;/P&gt;

&lt;P&gt;thanks&lt;/P&gt;</description>
    <pubDate>Tue, 07 May 2019 14:56:42 GMT</pubDate>
    <dc:creator>vincenp2</dc:creator>
    <dc:date>2019-05-07T14:56:42Z</dc:date>
    <item>
      <title>combining alerts into one daily email report</title>
      <link>https://community.splunk.com/t5/Reporting/combining-alerts-into-one-daily-email-report/m-p/441440#M7128</link>
      <description>&lt;P&gt;I want to generate one daily email showing ALL DMC alerts that have been produced in the last 12 or 24 hours, and wondered if it is possible?&lt;/P&gt;

&lt;P&gt;alerts are generated individually for each of the 8 main DMC alerts, and we currently receive individual emails for these.&lt;BR /&gt;
I would like to be presented with one email at the start of the day showing me alerts which have been reported out in the last 12 or 24hrs&lt;/P&gt;

&lt;P&gt;thanks&lt;/P&gt;</description>
      <pubDate>Tue, 07 May 2019 14:56:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/combining-alerts-into-one-daily-email-report/m-p/441440#M7128</guid>
      <dc:creator>vincenp2</dc:creator>
      <dc:date>2019-05-07T14:56:42Z</dc:date>
    </item>
    <item>
      <title>Re: combining alerts into one daily email report</title>
      <link>https://community.splunk.com/t5/Reporting/combining-alerts-into-one-daily-email-report/m-p/441441#M7129</link>
      <description>&lt;P&gt;Hi @vincenp2,&lt;/P&gt;

&lt;P&gt;Sure, it's pretty easy, have a look in your internal logs for your scheduled searches something like &lt;CODE&gt;index=_internal sourcetype=scheduler&lt;/CODE&gt; should do the trick. From there pick out the searches you want to monitor and then simply add that to your search and make a daily schedule.&lt;/P&gt;

&lt;P&gt;Let me know if that helps.&lt;/P&gt;

&lt;P&gt;Cheers,&lt;BR /&gt;
David&lt;/P&gt;</description>
      <pubDate>Tue, 07 May 2019 15:06:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/combining-alerts-into-one-daily-email-report/m-p/441441#M7129</guid>
      <dc:creator>DavidHourani</dc:creator>
      <dc:date>2019-05-07T15:06:02Z</dc:date>
    </item>
  </channel>
</rss>

