Alert emailing PDF with "no results found", please help.


I have read thru some other posts but I am still not sure if this is a bug or misconfig on my alert.

I have a rather simple search running to check when a certain event count > 10, for the Last 1 hour.

The alert is scheduled to "Run every hour At 15 minutes past the hour"

The alert sends an email with results inline, which I can verify are correct, but the PDF is showing "No Results Found".
The Search Head is 6.3.1 and not sure if this is a bug.
Or do I need to adjust the alert schedule to be more or less frequent than the search?
Please advise.
Thank you

0 Karma


@Log_wrangler : did you setup your alert to have PDF as an attachment..??
I would check index=_internal source=*pdfgen.log and index=_internal source=*python.log to get more details about your scheduled report.

0 Karma


Thank you for the reply. Yes I have PDF, CSV, and inline table. The inline table and CSV show the results but just not the PDF...

0 Karma
*NEW* Splunk Love Promo!
Snag a $25 Visa Gift Card for Giving Your Review!

It's another Splunk Love Special! For a limited time, you can review one of our select Splunk products through Gartner Peer Insights and receive a $25 Visa gift card!


Or Learn More in Our Blog >>