Reporting

How come my scheduled report is sending emails with no results when manual search shows data?

Earenhart
Path Finder

Hello,

I have a report that is run daily going back 24 hours. That report was reporting results just fine up until a few days ago, and nothing about the report has changed, yet now the results in the email are blank even though running the search manually returns results. What could possibly cause this type of behavior? I have checked the schedule settings, permissions, the search itself, none of it is any different than what I originally saved. Other saved reports and alerts are running just fine.

Are there any sort of backend changes to splunk that have been known to cause this type of behavior? Perhaps changes in the environment?

There was a post about this same issue in 2015 titled "Scheduled report shows "No results found" but manual report sees data", which was never answered.

0 Karma

somesoni2
Revered Legend

Check if the data that the scheduled report is looking for, was searchable at the time the report was run. By running something like this

your base search | eval _time=_indextime

Here we're changing the event timestamp to the time when it got indexed, to confirm that the search had all the data available to it when it ran.

0 Karma

Earenhart
Path Finder

I was able to simply delete and resave the report, and it appears to be working properly now. I still would like to understand why this happens if anyone knows. Having a report/alert randomly break for reasons unknown is definitely unacceptable.

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...