The certificate has hostname.domain.local
and the scheduled reports are coming out with hostname:port/PathToReport
minus the domain.local
. I have checked the etc/system/local/server.conf
and it has the fully qualified domain name in there, but it is not being input to the report links.
Look at the answer here: https://community.splunk.com/t5/Reporting/How-to-modify-the-quot-View-Results-in-Splunk-quot-link-fr...
depending on how many search heads you want to put this into you may be better off setting up an app to distribute the settings to your search heads... or if you are doing a single then put it in $SPLUNK_HOME$/etc/system/local/alert_actions.conf