Looking for a way to prevent Splunk from sending an email with a blank report. In our case certain reports run every hour and are often empty. My customers are asking for a way to stop these "No Data" emails. Anyone have a suggestion? Thanks!
I think you can configure alert condition to prevent Splunk from sending when search result is no data. The setting will be "Trigger if Number of results is more than 0 ". You can refer to following manual. Hope this help.
http://docs.splunk.com/Documentation/Splunk/latest/user/SchedulingSavedSearches
I think you can configure alert condition to prevent Splunk from sending when search result is no data. The setting will be "Trigger if Number of results is more than 0 ". You can refer to following manual. Hope this help.
http://docs.splunk.com/Documentation/Splunk/latest/user/SchedulingSavedSearches
Setting the trigger does not work, still sends the blank report.