Ok, I have an answer, @vrmandadi. Sparklines in alert emails are not currently supported. It's something we are looking into currently, though, so please stay tuned! Thank you for your question!
All best,
@frobinson_splunk
Ok, I have an answer, @vrmandadi. Sparklines in alert emails are not currently supported. It's something we are looking into currently, though, so please stay tuned! Thank you for your question!
All best,
@frobinson_splunk
Thank You.
Hi @vrmandadi,
I'm a tech writer here at Splunk and I'd like to help with your question. On first checking to see what you can do with an alert email, It looks like you can configure savedsearches.conf to include a visualization:
See the savedsearches.conf conf file's "# Visualization options" section for some more details.
Also, the spec file example for an email alert action seems to align with what you're trying to do:
"display.events.fields = ["host","source","sourcetype","latitude"]
display.page.search.mode = verbose
display.visualizations.charting.chart = area
display.visualizations.type = mapping"
Please let me know if this helps!
Best,
@frobinson_splunk
Thanks for the quick response frobinson.I just want to know that a stats command with sparkline in it can be saved as an alert.Beacause what I heard is that we cannot save a stats command with sparkline as an alert
Ah, ok @vrmandadi thank you for the clarification. I'll look into this and report back!