I created an email alert, but my result comes back with the query and error code or it says "A PDF snapshot has been generatedm for the view" I would like to get a table or a chart in the email. I'm using Splunk Enterprise 5.0.5. this is for Failed Login Alert, below you see the query I wrote. I get the right result on splunk but not in my email.
(eventtype=msad-failed-user-logons | fields srchost,srcip,srcntdomain,user | eval srcip=replace(srcip,"::ffff:","") |
ip-to-host | stats values(srcntdomain) AS "Domain(s)", count AS Count, values(srchost) AS "Host(s)", values(srcip) AS "IP(s)", sparkline AS "Failure activity" by user | sort -Count | rename user as "Username"