Alerting

Why is scheduled alert not generating report?

keen
Loves-to-Learn Lots

I have a dashboard that is based on a scheduled report, the report is schedule to run at 06:00 every day and every day the job shows as done with success status however they is nothing in the report.

When I run the report manually it takes 1 hour for the report to complete with lot of search result (events) however when scheduled it’s show “Done” after 1 hour (sometime couple of minutes) with an empty report (0 events)

Why is the report not generation result, can you help troubleshoot the problem?

Labels (1)
Tags (1)
0 Karma
Get Updates on the Splunk Community!

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...

Cloud Monitoring Console - Unlocking Greater Visibility in SVC Usage Reporting

For Splunk Cloud customers, understanding and optimizing Splunk Virtual Compute (SVC) usage and resource ...

Automatic Discovery Part 3: Practical Use Cases

If you’ve enabled Automatic Discovery in your install of the Splunk Distribution of the OpenTelemetry ...