<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Alert to Report in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Alert-to-Report/m-p/559237#M158893</link>
    <description>&lt;P&gt;can you put the search here? the issue should be there&lt;/P&gt;</description>
    <pubDate>Tue, 13 Jul 2021 08:57:48 GMT</pubDate>
    <dc:creator>Joannna</dc:creator>
    <dc:date>2021-07-13T08:57:48Z</dc:date>
    <item>
      <title>Alert to Report</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Alert-to-Report/m-p/558386#M158615</link>
      <description>&lt;P&gt;Hi ,&lt;/P&gt;&lt;P&gt;I have some alerts which i want to change as report . the reason is , if there are no events then alert is not sending any data/email where in case of report we can receive atleast one blank csv attacehed report/email&amp;nbsp; if there is no data .. so as per business requirement we want to change allalert to report .. how can we do that ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 06 Jul 2021 11:43:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Alert-to-Report/m-p/558386#M158615</guid>
      <dc:creator>Susha</dc:creator>
      <dc:date>2021-07-06T11:43:19Z</dc:date>
    </item>
    <item>
      <title>Re: Alert to Report</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Alert-to-Report/m-p/558410#M158619</link>
      <description>&lt;P&gt;Hello ,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So basically , an alert is based on a scheduled saved search that whenever certain conditions are overcome, generates one or more actions to be executed.&lt;/P&gt;&lt;P&gt;A report is scheduled by you at an specific time, example everyday at 9 am , or 2 times a day one at 7 other at 4. So this would be your first issue changing to a report.&lt;/P&gt;&lt;P&gt;It should be fairy easy just copy the search and put it on a report , or save as report, if you need futher assistance on that you can add the code here.&lt;/P&gt;</description>
      <pubDate>Tue, 06 Jul 2021 13:56:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Alert-to-Report/m-p/558410#M158619</guid>
      <dc:creator>Joannna</dc:creator>
      <dc:date>2021-07-06T13:56:35Z</dc:date>
    </item>
    <item>
      <title>Re: Alert to Report</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Alert-to-Report/m-p/558442#M158633</link>
      <description>&lt;P&gt;thanks&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/235950"&gt;@Joannna&lt;/a&gt;&amp;nbsp; for quick revert ..&lt;/P&gt;&lt;P&gt;please consider condition here as a alert which will trigger the events everyday at 9 and it will send that data in CSV .. here problem is i am getting nothing if no data .. if i will convert this in report then it will sent report/email will blank data no matter if data is there or not..&lt;/P&gt;</description>
      <pubDate>Tue, 06 Jul 2021 15:43:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Alert-to-Report/m-p/558442#M158633</guid>
      <dc:creator>Susha</dc:creator>
      <dc:date>2021-07-06T15:43:10Z</dc:date>
    </item>
    <item>
      <title>Re: Alert to Report</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Alert-to-Report/m-p/559237#M158893</link>
      <description>&lt;P&gt;can you put the search here? the issue should be there&lt;/P&gt;</description>
      <pubDate>Tue, 13 Jul 2021 08:57:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Alert-to-Report/m-p/559237#M158893</guid>
      <dc:creator>Joannna</dc:creator>
      <dc:date>2021-07-13T08:57:48Z</dc:date>
    </item>
  </channel>
</rss>

