Alerting

Alert emailing PDF with "no results found", please help.

Log_wrangler
Builder

Hi,
I have read thru some other posts but I am still not sure if this is a bug or misconfig on my alert.

I have a rather simple search running to check when a certain event count > 10, for the Last 1 hour.

The alert is scheduled to "Run every hour At 15 minutes past the hour"

The alert sends an email with results inline, which I can verify are correct, but the PDF is showing "No Results Found".
The Search Head is 6.3.1 and not sure if this is a bug.
Or do I need to adjust the alert schedule to be more or less frequent than the search?
Please advise.
Thank you

0 Karma

prakash007
Builder

@Log_wrangler : did you setup your alert to have PDF as an attachment..??
I would check index=_internal source=*pdfgen.log and index=_internal source=*python.log to get more details about your scheduled report.

0 Karma

Log_wrangler
Builder

Thank you for the reply. Yes I have PDF, CSV, and inline table. The inline table and CSV show the results but just not the PDF...

0 Karma
Get Updates on the Splunk Community!

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer at Splunk .conf24 ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...

Combine Multiline Logs into a Single Event with SOCK: a Step-by-Step Guide for ...

Combine multiline logs into a single event with SOCK - a step-by-step guide for newbies Olga Malita The ...