Alerting

Results of Saved Search not being included/attached in email

Jason
Motivator

I have a handful of scheduled searches that a client would like emailed. They want to see the results in the email and not have to log into Splunk. However, when I go in Email Alert Settings in the WebUI set Splunk to Include Results Inline = yes, no matter what Email Format I choose they still receive no results in their email, only a link.

The search is returning results, and is emailing because it is set to email when number of events > 0.

Please let me know what settings I should check, I think this is a stock 4.1.4 install.

Tags (3)
1 Solution

Branden
Builder

In your savedsearches.conf, make sure the following is set for the search in question:

action.email.sendresults = 1

View solution in original post

0 Karma

Jason
Motivator

Haha, nope, I totally missed that checkbox. Thanks guys!

0 Karma

Branden
Builder

In your savedsearches.conf, make sure the following is set for the search in question:

action.email.sendresults = 1
0 Karma

Lowell
Super Champion

Just checking, but your sure you checked "Include results in email" on the saved search in question, right? The email format options are on a different page. In savedsearches.conf this will take the form: action.email.sendresults = 1

Get Updates on the Splunk Community!

Why You Can't Miss .conf25: Unleashing the Power of Agentic AI with Splunk & Cisco

The Defining Technology Movement of Our Lifetime The advent of agentic AI is arguably the defining technology ...

Deep Dive into Federated Analytics: Unlocking the Full Power of Your Security Data

In today’s complex digital landscape, security teams face increasing pressure to protect sprawling data across ...

Your summer travels continue with new course releases

Summer in the Northern hemisphere is in full swing, and is often a time to travel and explore. If your summer ...