This sendmail command worked for me.😀 | rest timeout=600 splunk_server=local /servicesNS/-/-/saved/searches add_orphan_field=yes count=0 | search orphan=1 disabled=0 is_scheduled=1 title IN ("Missed_workfusion","Failed Intake Document") | eval status = if(disabled = 0, "enabled", "disabled") | fields title eai:acl.owner eai:acl.app eai:acl.sharing orphan status is_scheduled cron_schedule next_scheduled_time next_scheduled_time actions "action.email.to" | rename title AS "search_name" eai:acl.owner AS owner eai:acl.app AS app eai:acl.sharing AS sharing "action.email.to" as Email_Address | map search="| makeresults search_name owner | sendemail to=\"$Email_Address$\" cc="abc@xyz.com;123@yahoo.com" subject=\"Orphaned Searches/Reports/Alerts to be reviewed and reowned\" message=\"Below Searches/Reports/Alerts in Splunk were orphaned. \n Please take necessary action in changing the ownership from retired owners to new owners in getting the reports functional otherwise these reports would be disabled by SPLUNK Team after 15 days since the first trigger\n. SEARCH NAME : \\\"$search_name$\\\" \n OWNER OF THE SEARCH : \\\"$owner$\\\" \n APPLICATION : \\\"$app$\\\" \n STATUS : \\\"$status$\\\" \n CRON SCHEDULE OF SEARCH: \\\$cron_schedule$\\\ \n EMAIL ADDRESS OF SEARCH: \\\"$Email_Address$\\\" \n Thanks & Regards \n SPLUNK Team \""
... View more