Scheduled Search (Report) with attached CSV show 0 results, but executing the same search show correct results


Hi everyone Splunker.

I'm actually dealing with a quite serious problem which let me send to our customer empty csv results.

A saved search for report has been scheduled to run once a day at 5 AM. The email has an empty csv file.

However, when i look for the report name within Splunk GUI and click on execute, it prompt me the correct results.

I thought was an authorizative problem related to the owner of the Report, but the owner is me, and i can see the right result both within the App in which the report exist, both everywhere.

The curious thing is that sometimes the csv attached to the email show the currect result, other time not (I've set the chron to run every ten minutes).

Please, may you help me?

Thanks in advance

Tags (1)
0 Karma


This might be related to authorization problem or some knowledge objects permission problem.
Can you run the schedule search with nobody or admin user to verify this issue. Please make sure the schedule search is created in correct app context and has access to all knowledge objects. When the schedule search is configured, please make sure it runs as owner context .

Refer below documentation for more details.

0 Karma

Ultra Champion

spl please

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In the last month, the Splunk Threat Research Team (STRT) has had 2 releases of new security content via the ...

Announcing the 1st Round Champion’s Tribute Winners of the Great Resilience Quest

We are happy to announce the 20 lucky questers who are selected to be the first round of Champion's Tribute ...

We’ve Got Education Validation!

Are you feeling it? All the career-boosting benefits of up-skilling with Splunk? It’s not just a feeling, it's ...