Alerting

How to fix the formatting of a scheduled report received via email?

a548506
Path Finder

Hello,

I am receiving a schedule report via email from my dev environment and prod environment. Same report, but the email format is not the same coming from my prod env. The email from dev env has a nice format with the name of my Report ... whereas the one coming from my prod env shows the link.

It doesn't look nice and clean like the one coming from my dev. We are running 6.4.1 on both env.

Any thoughts on how to fix this?

0 Karma
1 Solution

somesoni2
Revered Legend

Check if the "Include" section is different for the alert in both environmennt (most probably it is). Go you SPlunk-> You app which contains your alert -> Alerts, open the alert and under Send email action, see what all checkboxes are selected for Include.
http://docs.splunk.com/Documentation/Splunk/6.5.0/Alert/Emailnotification#Configure_email_notificati...
(see step3- Include)

View solution in original post

somesoni2
Revered Legend

Check if the "Include" section is different for the alert in both environmennt (most probably it is). Go you SPlunk-> You app which contains your alert -> Alerts, open the alert and under Send email action, see what all checkboxes are selected for Include.
http://docs.splunk.com/Documentation/Splunk/6.5.0/Alert/Emailnotification#Configure_email_notificati...
(see step3- Include)

a548506
Path Finder

Hi,

Thanks for the input. I'm sorry that i wasn't more clear, but my issue is with a scheduled search report. Would that still apply to that as well?

Thanks!

0 Karma

somesoni2
Revered Legend

Yup... just go to Reports, instead of Alerts... The email Action is same for both.

0 Karma

a548506
Path Finder

Awesome, thanks for the help. We solved the issue.

0 Karma

sloshburch
Splunk Employee
Splunk Employee

Nice! Glad @somesoni2 was able to help! @a548506, since it sounds like this solved the problem, would you mark the answer as "accepted"?

Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...