Alerting

Unable to send scheduled search results by email

anthonycopus
Path Finder

Hi,

I'm currently trying to schedule a search which sends the results by pdf to a few emails.
However, in the splunk ui the settings appear correct but won't send.

I have alert condition set to 'always'
Send email is ticket to 'enabled'
Include results in email as pdf is selected
Valid email addresses and email subject are entered.

But this appears to all be ignored. The savedsearch is valid and I'm sure email settings are correct as I can add instruction to inline queries to send results to email. It's simply these alert settings that inexplicably (to me) won't work.

Any ideas?

Also, I would like the graph to have stacked results rather than side by side (as it's a timechart span=1d count by variable). Is this possible easily?

Thanks
Anthony

0 Karma
1 Solution

anthonycopus
Path Finder

After speaking with Splunk support, it turns out the issue was the alert_actions.conf file in the local folder.

This was not needed after upgrading to splunk 6.0.1 (previously splunk 4.0). Removing this file from the directory permitted alerts to go ahead as per normal.

View solution in original post

0 Karma

anthonycopus
Path Finder

After speaking with Splunk support, it turns out the issue was the alert_actions.conf file in the local folder.

This was not needed after upgrading to splunk 6.0.1 (previously splunk 4.0). Removing this file from the directory permitted alerts to go ahead as per normal.

0 Karma
Get Updates on the Splunk Community!

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Your Voice Matters! Help Us Shape the New Splunk Lantern Experience

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Building Momentum: Splunk Developer Program at .conf25

At Splunk, developers are at the heart of innovation. That’s why this year at .conf25, we officially launched ...