Reporting

I can't see any fields when I access the url link in alert mail of my savesearch?

rsimmons
Splunk Employee
Splunk Employee

I can't see any fields when I access the url link in alert mail of my savesearch? I would like to drill down on a savesearch and not only see the results but also the fields. I no that this was disabled by design for version 4.0.9 and later and also understand that the performance can be degraded but would like to have the process to enabled.

Tags (1)

rsimmons
Splunk Employee
Splunk Employee

In your savedsearches.conf, add

dispatch.status_buckets=1

to the searches that you want to retain the field summaries for, it can greatly impact the performance by enabling this stanza.

Get Updates on the Splunk Community!

What the End of Support for Splunk Add-on Builder Means for You

Hello Splunk Community! We want to share an important update regarding the future of the Splunk Add-on Builder ...

Solve, Learn, Repeat: New Puzzle Channel Now Live

Welcome to the Splunk Puzzle PlaygroundIf you are anything like me, you love to solve problems, and what ...

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...