<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PDF reports are incomplete in Reporting</title>
    <link>https://community.splunk.com/t5/Reporting/PDF-reports-are-incomplete/m-p/197907#M4292</link>
    <description>&lt;P&gt;What was the time difference you checked the PDF and compared it with running the search manually on dashboard.&lt;/P&gt;

&lt;P&gt;The issue can be summary index not getting filled (summary search can be delayed if there are a lot of saved searches running) and the summary index search is getting queued up and getting executed later than 6 AM.&lt;/P&gt;

&lt;P&gt;Have you ever seen messages like: Maximum Concurrent Searches that can run on Splunk has reached?&lt;/P&gt;

&lt;P&gt;This can be one cause of the problem.&lt;/P&gt;</description>
    <pubDate>Wed, 07 Jun 2017 17:51:30 GMT</pubDate>
    <dc:creator>behlkush</dc:creator>
    <dc:date>2017-06-07T17:51:30Z</dc:date>
    <item>
      <title>PDF reports are incomplete</title>
      <link>https://community.splunk.com/t5/Reporting/PDF-reports-are-incomplete/m-p/197901#M4286</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;We have a dashboard containing 8 charts. These charts are rendered using saved searches. The searches make use of a summary index to get the data.&lt;/P&gt;

&lt;P&gt;Summary index creation time: &lt;STRONG&gt;Once a day at 00:45 AM&lt;/STRONG&gt;.&lt;BR /&gt;&lt;BR /&gt;
Schedule for generating PDF and emailing is: &lt;STRONG&gt;Daily at 6:00 AM&lt;/STRONG&gt;.&lt;BR /&gt;&lt;BR /&gt;
Page size for PDF report is set as: &lt;STRONG&gt;A3&lt;/STRONG&gt;&lt;BR /&gt;&lt;BR /&gt;
Number of charts per page of PDF is: &lt;STRONG&gt;2&lt;/STRONG&gt;&lt;/P&gt;

&lt;P&gt;One chart on this dashboard has some issues. The chart is used to show last 7 days session count.&lt;BR /&gt;&lt;BR /&gt;
The search is:  &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=my_summary report=my_report earliest=-7d@d latest=-1d | timechart partial=false span=1d  sum(sessions) as TotalSessions sum(downloads) as TotalDownloads
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;On few days the the chart on PDF doesn't contain complete information. The previous day's data will be missing. Whereas if i open the application and view the dashboard on my browser, i see the chart completely.&lt;BR /&gt;&lt;BR /&gt;
Note: Some days the same chart on PDF contains complete information.&lt;/P&gt;

&lt;P&gt;What could be the problem? How to debug this issue?&lt;/P&gt;

&lt;P&gt;Thanks&lt;/P&gt;

&lt;P&gt;Strive&lt;/P&gt;</description>
      <pubDate>Sat, 22 Mar 2014 07:58:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/PDF-reports-are-incomplete/m-p/197901#M4286</guid>
      <dc:creator>strive</dc:creator>
      <dc:date>2014-03-22T07:58:46Z</dc:date>
    </item>
    <item>
      <title>Re: PDF reports are incomplete</title>
      <link>https://community.splunk.com/t5/Reporting/PDF-reports-are-incomplete/m-p/197902#M4287</link>
      <description>&lt;P&gt;I have exactly the same problem with a daily scheduled PDF report. Sending a test email results in complete results (today at least).&lt;/P&gt;</description>
      <pubDate>Fri, 08 Jan 2016 10:16:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/PDF-reports-are-incomplete/m-p/197902#M4287</guid>
      <dc:creator>machiel</dc:creator>
      <dc:date>2016-01-08T10:16:01Z</dc:date>
    </item>
    <item>
      <title>Re: PDF reports are incomplete</title>
      <link>https://community.splunk.com/t5/Reporting/PDF-reports-are-incomplete/m-p/197903#M4288</link>
      <description>&lt;P&gt;Looking internally to similar issues, there have been a few bug fixes in the past that resolved issues similar to what you are experiencing with PDF exports and charts therein. &lt;/P&gt;

&lt;P&gt;What version of Splunk are you all experiencing this issue on?&lt;/P&gt;</description>
      <pubDate>Thu, 11 Feb 2016 01:18:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/PDF-reports-are-incomplete/m-p/197903#M4288</guid>
      <dc:creator>pgreer_splunk</dc:creator>
      <dc:date>2016-02-11T01:18:47Z</dc:date>
    </item>
    <item>
      <title>Re: PDF reports are incomplete</title>
      <link>https://community.splunk.com/t5/Reporting/PDF-reports-are-incomplete/m-p/197904#M4289</link>
      <description>&lt;P&gt;Splunk 6.3.2 &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 11 Feb 2016 10:33:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/PDF-reports-are-incomplete/m-p/197904#M4289</guid>
      <dc:creator>machiel</dc:creator>
      <dc:date>2016-02-11T10:33:32Z</dc:date>
    </item>
    <item>
      <title>Re: PDF reports are incomplete</title>
      <link>https://community.splunk.com/t5/Reporting/PDF-reports-are-incomplete/m-p/197905#M4290</link>
      <description>&lt;P&gt;Looking at what is out there (as fixes or open issues) I'm not seeing anything specific that matches the behavior you're seeing since 6.3.2 (current version is 6.3.3).&lt;/P&gt;

&lt;P&gt;So - I'll suggest that you open up a case with as much documentation/example as possible and support will determine if this is a duplicate to an existing open case, whether it might be resolved in the 6.3.3 release (or when a fix might be released), whether there is a work around or patch, or if this is a new 'feature' you've uncovered that has not been reported as of yet.&lt;/P&gt;</description>
      <pubDate>Thu, 11 Feb 2016 20:26:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/PDF-reports-are-incomplete/m-p/197905#M4290</guid>
      <dc:creator>pgreer_splunk</dc:creator>
      <dc:date>2016-02-11T20:26:24Z</dc:date>
    </item>
    <item>
      <title>Re: PDF reports are incomplete</title>
      <link>https://community.splunk.com/t5/Reporting/PDF-reports-are-incomplete/m-p/197906#M4291</link>
      <description>&lt;P&gt;Any chance this happens on very specific days?  Like every Monday and Tuesday?  Or Like every day that has a three in the date (3rd,13th,23rd,30th31st). If so perhaps we can narrow it down a bit.&lt;/P&gt;</description>
      <pubDate>Thu, 11 Aug 2016 22:12:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/PDF-reports-are-incomplete/m-p/197906#M4291</guid>
      <dc:creator>jkat54</dc:creator>
      <dc:date>2016-08-11T22:12:28Z</dc:date>
    </item>
    <item>
      <title>Re: PDF reports are incomplete</title>
      <link>https://community.splunk.com/t5/Reporting/PDF-reports-are-incomplete/m-p/197907#M4292</link>
      <description>&lt;P&gt;What was the time difference you checked the PDF and compared it with running the search manually on dashboard.&lt;/P&gt;

&lt;P&gt;The issue can be summary index not getting filled (summary search can be delayed if there are a lot of saved searches running) and the summary index search is getting queued up and getting executed later than 6 AM.&lt;/P&gt;

&lt;P&gt;Have you ever seen messages like: Maximum Concurrent Searches that can run on Splunk has reached?&lt;/P&gt;

&lt;P&gt;This can be one cause of the problem.&lt;/P&gt;</description>
      <pubDate>Wed, 07 Jun 2017 17:51:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/PDF-reports-are-incomplete/m-p/197907#M4292</guid>
      <dc:creator>behlkush</dc:creator>
      <dc:date>2017-06-07T17:51:30Z</dc:date>
    </item>
  </channel>
</rss>

