All Apps and Add-ons

Splunk empy report email

julian0125
Explorer

Hello Splunkers.

I am in doubt i hope you can help me, i just updated my Splunk to version 7.2.6, and suddenly the alert email stopped sending empty reports. I need to recieve the reports even if they're empy. what can i do to resolve this issue? Thanks

0 Karma

solarboyz1
Builder

The easiest way, is to disable the currently configured alert, and re-create it as a scheduled report.

Alerts are dependent on trigger conditions to take action (email), reports are not.
https://docs.splunk.com/Documentation/Splunk/latest/Alert/Emailnotification

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

How much can you really learn in 3 minutes?

Observability can certainly be hard to understand – there's a lot of jargon and buzzwords and it seems to ...

Event Series: The Agentic SOC: Trust Before Autonomy

AI is fundamentally changing security operations, but true progress requires more than just automation—it ...

Free Professional Services for .conf26 Attendees

This year at .conf26, we are doing something a little different. We are bringing the best minds from ...