Alerting

Alert emailing PDF with "no results found", please help.

Log_wrangler
Builder

Hi,
I have read thru some other posts but I am still not sure if this is a bug or misconfig on my alert.

I have a rather simple search running to check when a certain event count > 10, for the Last 1 hour.

The alert is scheduled to "Run every hour At 15 minutes past the hour"

The alert sends an email with results inline, which I can verify are correct, but the PDF is showing "No Results Found".
The Search Head is 6.3.1 and not sure if this is a bug.
Or do I need to adjust the alert schedule to be more or less frequent than the search?
Please advise.
Thank you

0 Karma

prakash007
Builder

@Log_wrangler : did you setup your alert to have PDF as an attachment..??
I would check index=_internal source=*pdfgen.log and index=_internal source=*python.log to get more details about your scheduled report.

0 Karma

Log_wrangler
Builder

Thank you for the reply. Yes I have PDF, CSV, and inline table. The inline table and CSV show the results but just not the PDF...

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...