Getting Data In

setting up daily formatted report

aniketb
Path Finder

Hi,

I have a saved search to find out the occurrence of a keyword "Response" in a log.
I am able to create a formatted report of the same.

I would like to receive this report as an email, daily/weekly in my mailbox.
I could find option to create either a one time report or a daily alert. If I set an alert, it sends me a .csv log file. I'm actually more interested in receiving it in a report format.

Please advise me how to proceed with this.

PS: I don't have the PDF Report Server app installed.

0 Karma
1 Solution

lguinn2
Legend

You could save your search on a dashboard, and then schedule the delivery of the dashboard. I personally like this look better, but you can also save your search and have it run on a schedule.

Here is the documentation.

In Splunk 4.3, you can create a scheduled search by selecting Create->Scheduled Search and following the wizard. You can also create an alert with a criteria of "Always" alert.

Here is the documentation for alerts.

View solution in original post

0 Karma

lguinn2
Legend

You could save your search on a dashboard, and then schedule the delivery of the dashboard. I personally like this look better, but you can also save your search and have it run on a schedule.

Here is the documentation.

In Splunk 4.3, you can create a scheduled search by selecting Create->Scheduled Search and following the wizard. You can also create an alert with a criteria of "Always" alert.

Here is the documentation for alerts.

0 Karma

aniketb
Path Finder

I don't have the PDF Report Server app installed.
Any other way?

0 Karma

aniketb
Path Finder

It is 4.3.3

0 Karma

lguinn2
Legend

What is your version of Splunk?

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...