Alerting

Results of Saved Search not being included/attached in email

Jason
Motivator

I have a handful of scheduled searches that a client would like emailed. They want to see the results in the email and not have to log into Splunk. However, when I go in Email Alert Settings in the WebUI set Splunk to Include Results Inline = yes, no matter what Email Format I choose they still receive no results in their email, only a link.

The search is returning results, and is emailing because it is set to email when number of events > 0.

Please let me know what settings I should check, I think this is a stock 4.1.4 install.

Tags (3)
1 Solution

Branden
Builder

In your savedsearches.conf, make sure the following is set for the search in question:

action.email.sendresults = 1

View solution in original post

0 Karma

Jason
Motivator

Haha, nope, I totally missed that checkbox. Thanks guys!

0 Karma

Branden
Builder

In your savedsearches.conf, make sure the following is set for the search in question:

action.email.sendresults = 1
0 Karma

Lowell
Super Champion

Just checking, but your sure you checked "Include results in email" on the saved search in question, right? The email format options are on a different page. In savedsearches.conf this will take the form: action.email.sendresults = 1

Get Updates on the Splunk Community!

Accelerate Service Onboarding, Decomposition, Troubleshooting - and more with ITSI’s ...

Accelerate Service Onboarding, Decomposition, Troubleshooting - and more! Faster Time to ValueManaging and ...

New Release | Splunk Enterprise 9.3

Admins and Analyst can benefit from:  Seamlessly route data to your local file system to save on storage ...

2024 Splunk Career Impact Survey | Earn a $20 gift card for participating!

Hear ye, hear ye! The time has come again for Splunk's annual Career Impact Survey!  We need your help by ...