Reporting

remote report/alert sends email

gitingua
Communicator

Deleted the schedule report/alert. 
They keep sending letters to the post office. They are not in the system. empty reports come from deleted scheduled reports. 

Thanks

Labels (2)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

How did you delete the alert?  If you edited savedsearches.conf then did you also restart Splunk?

If you have multiple Splunk instances did you remove the alert from all of them?

---
If this reply helps you, Karma would be appreciated.
0 Karma

gitingua
Communicator

@richgalloway Searches, reports, and alerts -> my alert/report -> edit -> delete

checked in savedsearches.conf file, there they are also absent. they are absent at all. 

 

0 Karma

diogofgm
SplunkTrust
SplunkTrust

which savedsearches.conf have you checked? There can be multiple savedsearches.conf files depending on the app context and on the permissions set. Have you tried running a btool?

./splunk btool savedsearches list --debug | grep <the info your looking for>

 

------------
Hope I was able to help you. If so, some karma would be appreciated.
0 Karma

gitingua
Communicator

today also received a message from a remote scheduled report.

but deleted already as 2-3 weeks ago

0 Karma

gitingua
Communicator

Nothing found

 

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Is it possible someone cloned the alert and that clone is sending the emails? Try searching savedsearches.conf for the email address.

---
If this reply helps you, Karma would be appreciated.
0 Karma

gitingua
Communicator

@richgalloway he is nowhere to be found

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Have you tried restarting Splunk?  It shouldn't be necessary, but perhaps it will help.

---
If this reply helps you, Karma would be appreciated.
0 Karma

gitingua
Communicator

@richgalloway tried it, didn't help

0 Karma

gitingua
Communicator

@richgalloway But messages with reports come to the mail

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

A Four-Part Event Series: Full Stack Observability For the AI Era

As AI reshapes applications, infrastructure, and the way teams operate, the traditional boundaries of ...

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Event Series: Level up your SOC: Advancing with Splunk Enterprise Security

AI has fundamentally raised the stakes for security operations, and this three-part series is your guide to ...