Splunk Enterprise Security

Adaptive Response Action Send email not sending results

MaverickT
Communicator

We made a clean installation of on-prem Splunk Enterprise 8.0.9 and Enterprise Security 6.4.0. When correlation search returns results, we would like to append these results to an email via adaptive response action "Send Email".  We had selected the option to include an inline-table, but regardless of this setting, the table with results is still not added to the email.

There are two additional  findings we discovered:

  1. If we try to append results of standard alert search (non-correlation search) to an email it works.
  2. If we set sendresults = 1 in $SPLUNK_HOME/etc/system/local/alert_actions.conf it also works but not for all correlation searches...

Has anybody encountered such problems and how did you solve it?

Labels (2)
0 Karma

thangbui
Engager

I am also facing this problem. Does anyone have a solution to this problem yet?

0 Karma

teunlaan
Contributor

Made a report to Splunk > Fixed in ES  6.6.0

Workaround:  openen your alert in "searches, reports & Alerts" and Save it again. then it should work

0 Karma

thangbui
Engager

Thank you so much, It's worked for me!

0 Karma

teunlaan
Contributor

Did you get a solution for this?

We are seeing the same thing. 

I did some tests and it looks like  the following option in not set in the savedsearches.conf :

action.email.sendresults = 1

 

It always is 0 (and doesnt send anything) whatever you select. 

 

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...

Network to App: Observability Unlocked [May & June Series]

In today’s digital landscape, your environment is no longer confined to the data center. It spans complex ...

SPL2 Deep Dives, AppDynamics Integrations, SAML Made Simple and Much More on Splunk ...

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...