Alerting

Unable to send scheduled search results by email

anthonycopus
Path Finder

Hi,

I'm currently trying to schedule a search which sends the results by pdf to a few emails.
However, in the splunk ui the settings appear correct but won't send.

I have alert condition set to 'always'
Send email is ticket to 'enabled'
Include results in email as pdf is selected
Valid email addresses and email subject are entered.

But this appears to all be ignored. The savedsearch is valid and I'm sure email settings are correct as I can add instruction to inline queries to send results to email. It's simply these alert settings that inexplicably (to me) won't work.

Any ideas?

Also, I would like the graph to have stacked results rather than side by side (as it's a timechart span=1d count by variable). Is this possible easily?

Thanks
Anthony

0 Karma
1 Solution

anthonycopus
Path Finder

After speaking with Splunk support, it turns out the issue was the alert_actions.conf file in the local folder.

This was not needed after upgrading to splunk 6.0.1 (previously splunk 4.0). Removing this file from the directory permitted alerts to go ahead as per normal.

View solution in original post

0 Karma

anthonycopus
Path Finder

After speaking with Splunk support, it turns out the issue was the alert_actions.conf file in the local folder.

This was not needed after upgrading to splunk 6.0.1 (previously splunk 4.0). Removing this file from the directory permitted alerts to go ahead as per normal.

0 Karma
Get Updates on the Splunk Community!

Introducing Splunk Enterprise 9.2

WATCH HERE! Watch this Tech Talk to learn about the latest features and enhancements shipped in the new Splunk ...

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...