Alerting

Can we save a search as an alert via email with a sparkline in it?

vrmandadi
Builder

Is there a way to save a sparkline in an email alert?

Tags (3)
0 Karma
1 Solution

frobinson_splun
Splunk Employee
Splunk Employee

Ok, I have an answer, @vrmandadi. Sparklines in alert emails are not currently supported. It's something we are looking into currently, though, so please stay tuned! Thank you for your question!

All best,
@frobinson_splunk

View solution in original post

frobinson_splun
Splunk Employee
Splunk Employee

Ok, I have an answer, @vrmandadi. Sparklines in alert emails are not currently supported. It's something we are looking into currently, though, so please stay tuned! Thank you for your question!

All best,
@frobinson_splunk

vrmandadi
Builder

Thank You.

0 Karma

frobinson_splun
Splunk Employee
Splunk Employee

Hi @vrmandadi,
I'm a tech writer here at Splunk and I'd like to help with your question. On first checking to see what you can do with an alert email, It looks like you can configure savedsearches.conf to include a visualization:

See the savedsearches.conf conf file's "# Visualization options" section for some more details.

Also, the spec file example for an email alert action seems to align with what you're trying to do:

"display.events.fields = ["host","source","sourcetype","latitude"]
display.page.search.mode = verbose
display.visualizations.charting.chart = area
display.visualizations.type = mapping"

Please let me know if this helps!

Best,
@frobinson_splunk

0 Karma

vrmandadi
Builder

Thanks for the quick response frobinson.I just want to know that a stats command with sparkline in it can be saved as an alert.Beacause what I heard is that we cannot save a stats command with sparkline as an alert

0 Karma

frobinson_splun
Splunk Employee
Splunk Employee

Ah, ok @vrmandadi thank you for the clarification. I'll look into this and report back!

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...