Alerting

How to fix the formatting of a scheduled report received via email?

a548506
Path Finder

Hello,

I am receiving a schedule report via email from my dev environment and prod environment. Same report, but the email format is not the same coming from my prod env. The email from dev env has a nice format with the name of my Report ... whereas the one coming from my prod env shows the link.

It doesn't look nice and clean like the one coming from my dev. We are running 6.4.1 on both env.

Any thoughts on how to fix this?

0 Karma
1 Solution

somesoni2
Revered Legend

Check if the "Include" section is different for the alert in both environmennt (most probably it is). Go you SPlunk-> You app which contains your alert -> Alerts, open the alert and under Send email action, see what all checkboxes are selected for Include.
http://docs.splunk.com/Documentation/Splunk/6.5.0/Alert/Emailnotification#Configure_email_notificati...
(see step3- Include)

View solution in original post

somesoni2
Revered Legend

Check if the "Include" section is different for the alert in both environmennt (most probably it is). Go you SPlunk-> You app which contains your alert -> Alerts, open the alert and under Send email action, see what all checkboxes are selected for Include.
http://docs.splunk.com/Documentation/Splunk/6.5.0/Alert/Emailnotification#Configure_email_notificati...
(see step3- Include)

a548506
Path Finder

Hi,

Thanks for the input. I'm sorry that i wasn't more clear, but my issue is with a scheduled search report. Would that still apply to that as well?

Thanks!

0 Karma

somesoni2
Revered Legend

Yup... just go to Reports, instead of Alerts... The email Action is same for both.

0 Karma

a548506
Path Finder

Awesome, thanks for the help. We solved the issue.

0 Karma

sloshburch
Splunk Employee
Splunk Employee

Nice! Glad @somesoni2 was able to help! @a548506, since it sounds like this solved the problem, would you mark the answer as "accepted"?

Get Updates on the Splunk Community!

.conf24 | Day 0

Hello Splunk Community! My name is Chris, and I'm based in Canberra, Australia's capital, and I travelled for ...

Enhance Security Visibility with Splunk Enterprise Security 7.1 through Threat ...

 (view in My Videos)Struggling with alert fatigue, lack of context, and prioritization around security ...

Troubleshooting the OpenTelemetry Collector

  In this tech talk, you’ll learn how to troubleshoot the OpenTelemetry collector - from checking the ...