Reporting

Why is there a bad link in email alerts?

bowers
New Member

I have an issue where the link in the email alert does not function properly. I see the following message instead:

"The search you requested could not be found."

I am on version 7.2.0 Enterprise edition.  I have power user access and the alert permissions are set to "Shared in App".  I have seen other discussions for known issues that appear related, but those issues do not show up under my version of Splunk in the known issues list

Labels (1)
0 Karma

bowers
New Member

I ask about the expires, because it seems like the search has expired for these cases as I believe the link only works for 30-45 minutes.

0 Karma

isoutamo
SplunkTrust
SplunkTrust

When you are creating alert, you also define expiration for its results. After that time the result will be deleted and you cannot found it anymore with that link.

0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

have You (/Your splunk admin) configured your Splunk server's email settings to use correct URL on emails?

r. Ismo

0 Karma

bowers
New Member

Other "view results" links in alert emails seem to work.  It isn't every alert email that doesn't work.

0 Karma

isoutamo
SplunkTrust
SplunkTrust

Is mail configuration done on separate app / some particular (e.g. under search) or under …./etc/system/local? If first one have this app/configuration exported as system?

0 Karma

bowers
New Member

I saw in another thread that there is an expires parameter in a later version(8.0.1).  Is this located somewhere else in the settings in 7.2.0?

 

https://community.splunk.com/t5/Alerting/What-is-the-Expires-parameter-of-an-alert/m-p/539326?adlt=s...

0 Karma
Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...