Hi all,
Splunk newbie here, I've searched the answers but can't find an answer...
I have saved a series of searches as reports and scheduled them to run periodically and to e-mail me the output. The reports, schedule and e-mail all work perfectly - EXCEPT for that the csv filenames have been suffixed with a timestamp, which I do not want (it has also truncated some of the filenames - which need to be picked up by a VBA script for another process)
Is there any way to stop the timestamp being added? Thanks.
between, please share with us your search query..
maybe, you can try to use email notification tokens..
http://docs.splunk.com/Documentation/Splunk/7.1.2/Alert/EmailNotificationTokens