Deleted the schedule report/alert.
They keep sending letters to the post office. They are not in the system. empty reports come from deleted scheduled reports.
Thanks
How did you delete the alert? If you edited savedsearches.conf then did you also restart Splunk?
If you have multiple Splunk instances did you remove the alert from all of them?
@richgalloway Searches, reports, and alerts -> my alert/report -> edit -> delete
checked in savedsearches.conf file, there they are also absent. they are absent at all.
which savedsearches.conf have you checked? There can be multiple savedsearches.conf files depending on the app context and on the permissions set. Have you tried running a btool?
./splunk btool savedsearches list --debug | grep <the info your looking for>
today also received a message from a remote scheduled report.
but deleted already as 2-3 weeks ago
Is it possible someone cloned the alert and that clone is sending the emails? Try searching savedsearches.conf for the email address.
@richgalloway he is nowhere to be found
Have you tried restarting Splunk? It shouldn't be necessary, but perhaps it will help.
@richgalloway tried it, didn't help
@richgalloway But messages with reports come to the mail