Scheduled Search (Report) with attached CSV show 0 results, but executing the same search show correct results


Hi everyone Splunker.

I'm actually dealing with a quite serious problem which let me send to our customer empty csv results.

A saved search for report has been scheduled to run once a day at 5 AM. The email has an empty csv file.

However, when i look for the report name within Splunk GUI and click on execute, it prompt me the correct results.

I thought was an authorizative problem related to the owner of the Report, but the owner is me, and i can see the right result both within the App in which the report exist, both everywhere.

The curious thing is that sometimes the csv attached to the email show the currect result, other time not (I've set the chron to run every ten minutes).

Please, may you help me?

Thanks in advance

Tags (1)
0 Karma


This might be related to authorization problem or some knowledge objects permission problem.
Can you run the schedule search with nobody or admin user to verify this issue. Please make sure the schedule search is created in correct app context and has access to all knowledge objects. When the schedule search is configured, please make sure it runs as owner context .

Refer below documentation for more details.

0 Karma

Ultra Champion

spl please

0 Karma
Get Updates on the Splunk Community!

Security Highlights: September 2022 Newsletter

 September 2022 The Splunk App for Fraud Analytics (SFA) is now Splunk SupportedUse your existing Splunk ...

Platform Highlights | September 2022 Newsletter

 September 2022 What’s New in 9.0 and How to UpgradeGet a walk through of what is new Splunk Enterprise 9.0 ...

Observability Highlights | September 2022 Newsletter

 September 2022 Splunk Observability SuiteAccess to "Classic" SignalFx Interface Will be Removed on Sept 30, ...