Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

action.email.reportFileName not working as expected?

$
0
0
I'm looking for an option to remove the automatic timestamp from the csv output filename attached to emails. According to both the doco (http://docs.splunk.com/Documentation/Splunk/6.4.3/Admin/Alertactionsconf) and this answer: https://answers.splunk.com/answers/439644/removing-time-stamp-from-the-emailed-csv-file.html It sounds like it should be as simple as going into Advanced Edit and adjusting action.email.reportFileName so that the default ($name$-$time:%Y-%m-%d$) is removed and putting in .csv... which I've done. Any ideas why I'm still getting the default : Searchname-yyyy-mm-dd We do have a search cluster that I'm not 100% familiar with but I have verified that the Advanced Edit setting replicated to each node. I've even looked at the savedsearches.conf on in the CLI for each node and verified that it has the action.email.reportFileName =.csv Thanks in advance for your assistance!

Viewing all articles
Browse latest Browse all 47296

Trending Articles