We made a clean installation of on-prem Splunk Enterprise 8.0.9 and Enterprise Security 6.4.0. When correlation search returns results, we would like to append these results to an email via adaptive response action "Send Email". We had selected the option to include an inline-table, but regardless of this setting, the table with results is still not added to the email.
There are two additional findings we discovered:
Has anybody encountered such problems and how did you solve it?
I am also facing this problem. Does anyone have a solution to this problem yet?
Made a report to Splunk > Fixed in ES 6.6.0
Workaround: openen your alert in "searches, reports & Alerts" and Save it again. then it should work
Thank you so much, It's worked for me!
Did you get a solution for this?
We are seeing the same thing.
I did some tests and it looks like the following option in not set in the savedsearches.conf :
action.email.sendresults = 1
It always is 0 (and doesnt send anything) whatever you select.