Reporting

Why is CSV generated from report via trigger action inserting alternating blank rows?

lshoreSPLUNK
Engager

Hi All, 

I'm experiencing a funny issue with a Report I've setup within the "Search" module of Splunk.  The report is  generating a straight-forward table, example below:

lshoreSPLUNK_0-1606755081153.png

I've it configured for the search runs once per day, with a trigger action to send an email with the search results in a .csv file.  I've had this alert up and running for months without issue, however in recent days when I open the attached .CSV file for this daily email, there are alternative blank rows being included in the CSV file:

lshoreSPLUNK_0-1606755436084.png

If I run this search and download the .csv manually, the report doesn't have any alternating blank rows included in the report.  Similarly, if I update this daily report to instead attach a PDF of the search results, the PDF does not include any alternating blank rows.  So, I think the issue lies with something to do with the Trigger Action 'send email' however I can't seem to figure out what's causing this. 

Is anyone aware of this being a known issue, or is there somewhere obvious that I'm overlooking here? 

Thanks

Labels (1)

Saeryn
Engager

I am also experiencing this issue -- it was working at one point w/o the additional line.  I've looked over the fields we're using and the extra LF doesn't appear to be coming from a field.

Tags (2)
0 Karma
Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...