Alerting

Alert csv has extra blank lines when sent via email but not when viewed in Job manager

anthonyfry
Explorer

After reloading Splunk enterprise version 8.0.3, csv files emailed out via alerts have an extra line between rows of data.  Prior to the reload they did not. If the result of the alert is downloaded via the Job Manager, the file is as expected.  If the two versions of csv are opened with notepad++ I can see that the file normally has "CRLF" at the end of each line and the incorrect one has "CRCRLF"

The alerts are the result from a simple |table type search and have worked for months without issue.  The server was reloaded by out IT people due to unrelated issues with the kv store

SPLUNK is set to use python 3, which I believe is the same as before the reload. Any help would be appreciated as the automation fed by these csv's is failing due to the additional blank lines

Labels (2)
0 Karma
1 Solution

anthonyfry
Explorer

The issue was fixed by changing to Python 2

View solution in original post

0 Karma

anthonyfry
Explorer

The issue was fixed by changing to Python 2

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Submit a support request with Splunk.  I wouldn't expect a resolution soon, however, so be prepared to change your automation.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Threat Hunting Unlocked: How to Uplevel Your Threat Hunting With the PEAK Framework ...

WATCH NOWAs AI starts tackling low level alerts, it's more critical than ever to uplevel your threat hunting ...

Splunk APM: New Product Features + Community Office Hours Recap!

Howdy Splunk Community! Over the past few months, we’ve had a lot going on in the world of Splunk Application ...

Index This | Forward, I’m heavy; backward, I’m not. What am I?

April 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...