Getting Data In

No Data reports- any way to not send email?

zindain24
Path Finder

Looking for a way to prevent Splunk from sending an email with a blank report. In our case certain reports run every hour and are often empty. My customers are asking for a way to stop these "No Data" emails. Anyone have a suggestion? Thanks!

Tags (1)
0 Karma
1 Solution

Takajian
Builder

I think you can configure alert condition to prevent Splunk from sending when search result is no data. The setting will be "Trigger if Number of results is more than 0 ". You can refer to following manual. Hope this help.

http://docs.splunk.com/Documentation/Splunk/latest/user/SchedulingSavedSearches

View solution in original post

0 Karma

Takajian
Builder

I think you can configure alert condition to prevent Splunk from sending when search result is no data. The setting will be "Trigger if Number of results is more than 0 ". You can refer to following manual. Hope this help.

http://docs.splunk.com/Documentation/Splunk/latest/user/SchedulingSavedSearches

0 Karma

rafaelschwed
New Member

Setting the trigger does not work, still sends the blank report.

0 Karma
Get Updates on the Splunk Community!

.conf25 Community Recap

Hello Splunkers, And just like that, .conf25 is in the books! What an incredible few days — full of learning, ...

Splunk App Developers | .conf25 Recap & What’s Next

If you stopped by the Builder Bar at .conf25 this year, thank you! The retro tech beer garden vibes were ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...