I have an issue where the link in the email alert does not function properly. I see the following message instead:
I am on version 7.2.0 Enterprise edition. I have power user access and the alert permissions are set to "Shared in App". I have seen other discussions for known issues that appear related, but those issues do not show up under my version of Splunk in the known issues list
I ask about the expires, because it seems like the search has expired for these cases as I believe the link only works for 30-45 minutes.
When you are creating alert, you also define expiration for its results. After that time the result will be deleted and you cannot found it anymore with that link.
Hi
have You (/Your splunk admin) configured your Splunk server's email settings to use correct URL on emails?
r. Ismo
Other "view results" links in alert emails seem to work. It isn't every alert email that doesn't work.
Is mail configuration done on separate app / some particular (e.g. under search) or under …./etc/system/local? If first one have this app/configuration exported as system?
I saw in another thread that there is an expires parameter in a later version(8.0.1). Is this located somewhere else in the settings in 7.2.0?