Even I have the same issues. I made the below changes on alert_actions.conf file. Please anyone help me on this...
[default]
maxresults=100000
[email]
command = $action.email.preprocess_results{default=""}$ | sendemail "results_link=$results.url$" "ssname=$name$" "graceful=$graceful{default=True}$" "trigger_time=$trigger_time$" maxinputs="$action.email.maxresults{default=100000}$" maxtime="$action.email.maxtime{default=5m}$" results_file="$results.file$"
lisplunk@ifm0187:/opt/li/splunk/etc/apps/LI_miscSettings/default>
... View more