Reporting

How do I configure my Splunk report to only send an email when there is new data?

chustar
Path Finder

When we don't have data for a day, our splunk report still sends out its email with old and stale data. How can I prevent it from doing this?

Tags (3)
0 Karma

somesoni2
Revered Legend

We would need more information, in order to give you proper help here. Could you post your alert search (mask anything sensitive, its schedule information, the time range it works on (Start time and End time) etc?

0 Karma

woodcock
Esteemed Legend

You can split it up into 2 searches that run one right after. The second one writes the results to a file with | outputcsv. The first one reads this file with inputcsv and compares the results in this file (the previous day's run) with the results from your existing search. If it is the same, make sure that your combined search generates 0 rows and have your alert email only when Number of events is greater than 0. Done.

0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...