This is the solution from Splunk as well: https://splunkcommunities.force.com/customers/apex/ArticleDetailPage?URLName=Scheduled-Search-Alert-not-Triggering-Emails
... View more
To get around putting the app on the indexers (indexer load).
Just before the base64 command run the "| localop" command
Index=indexname sourcetype=sourcetypename
| localop
| base64 field=warnDataType action=decode mode=replace suppress_error=True
... View more