Alerting

How can I configure Alerts not to send blank/empty reports in PDF?

denisevw
Path Finder

I've configured about 75 Alerts to email reports on a daily basis. Some of these reports will have no data. I don't want the Alert to send out the report if it is blank or empty.

I did configure the Alert Condition:

(from savedsearches.conf)

quantity = 1

relation = greater than

The blank/empty report still gets emailed...

Tags (2)
0 Karma

chris_knott
New Member

Hello,

Do you have it to report on each search or per result? When importing my alerts from v5 into a new v6 cluster the option default to each search so any real time alerts were sending blank reports. Once I switched to per result I only get the alert email if there is a matching result.

Thanks,

Chris

0 Karma
Get Updates on the Splunk Community!

Splunk Training for All: Meet Aspiring Cybersecurity Analyst, Marc Alicea

Splunk Education believes in the value of training and certification in today’s rapidly-changing data-driven ...

Investigate Security and Threat Detection with VirusTotal and Splunk Integration

As security threats and their complexities surge, security analysts deal with increased challenges and ...

Observability Highlights | January 2023 Newsletter

 January 2023New Product Releases Splunk Network Explorer for Infrastructure MonitoringSplunk unveils Network ...