Alerting

Alert emailing PDF with "no results found", please help.

Log_wrangler
Builder

Hi,
I have read thru some other posts but I am still not sure if this is a bug or misconfig on my alert.

I have a rather simple search running to check when a certain event count > 10, for the Last 1 hour.

The alert is scheduled to "Run every hour At 15 minutes past the hour"

The alert sends an email with results inline, which I can verify are correct, but the PDF is showing "No Results Found".
The Search Head is 6.3.1 and not sure if this is a bug.
Or do I need to adjust the alert schedule to be more or less frequent than the search?
Please advise.
Thank you

0 Karma

prakash007
Builder

@Log_wrangler : did you setup your alert to have PDF as an attachment..??
I would check index=_internal source=*pdfgen.log and index=_internal source=*python.log to get more details about your scheduled report.

0 Karma

Log_wrangler
Builder

Thank you for the reply. Yes I have PDF, CSV, and inline table. The inline table and CSV show the results but just not the PDF...

0 Karma
Get Updates on the Splunk Community!

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...

Updated Team Landing Page in Splunk Observability

We’re making some changes to the team landing page in Splunk Observability, based on your feedback. The ...