You could change the following line in $SPLUNK_HOME/etc/apps/search/bin/sendemail.py :
datestamp = time.strftime('%Y-%m-%d')
To something like this:
datestamp = time.strftime('%Y%m%d%H%M%S')
This solution might not be supportable going forward if sendemail.py is overwritten by a newer version of Splunk during an update.
Feature request?
See also:
strftime() for a list of directives like %Y-%m-%d
How to work with saved searches (action.email.sendpdf)
alert_actions.conf (action.email.sendpdf)
Answer 1985
Tim.
... View more