Alerting

Results of Saved Search not being included/attached in email

Jason
Motivator

I have a handful of scheduled searches that a client would like emailed. They want to see the results in the email and not have to log into Splunk. However, when I go in Email Alert Settings in the WebUI set Splunk to Include Results Inline = yes, no matter what Email Format I choose they still receive no results in their email, only a link.

The search is returning results, and is emailing because it is set to email when number of events > 0.

Please let me know what settings I should check, I think this is a stock 4.1.4 install.

Tags (3)
1 Solution

Branden
Builder

In your savedsearches.conf, make sure the following is set for the search in question:

action.email.sendresults = 1

View solution in original post

0 Karma

Jason
Motivator

Haha, nope, I totally missed that checkbox. Thanks guys!

0 Karma

Branden
Builder

In your savedsearches.conf, make sure the following is set for the search in question:

action.email.sendresults = 1
0 Karma

Lowell
Super Champion

Just checking, but your sure you checked "Include results in email" on the saved search in question, right? The email format options are on a different page. In savedsearches.conf this will take the form: action.email.sendresults = 1

Get Updates on the Splunk Community!

.conf24 | Day 0

Hello Splunk Community! My name is Chris, and I'm based in Canberra, Australia's capital, and I travelled for ...

Enhance Security Visibility with Splunk Enterprise Security 7.1 through Threat ...

 (view in My Videos)Struggling with alert fatigue, lack of context, and prioritization around security ...

Troubleshooting the OpenTelemetry Collector

  In this tech talk, you’ll learn how to troubleshoot the OpenTelemetry collector - from checking the ...