I am trying to output the results of the SPL query to lookup file via OUTPUTLOOKUP command in query itself using SPLUNK Alerts.
(I am not using the alert function to send the data to CSV as I have conditional state to output the data to CSV)
It works intermittently and there are times that when data is not getting added to CSV unless manual run of query.
Can someone please assist or share some inputs?
Can you share your query?
Also, When you say data is not added to CSV intermittently, do you get alert emails always? I am asking this to ensure your scheduled reports are not skipped.
Is this in Search Head Cluster, distributed setup or a single instance of Splunk?
cheers, MuS
This looks to me as Distributed Setup. Still, I will confirm if any change.
I have tried Reports too - Experiencing same behavior.