<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Dashboard PDF email failing in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Dashboard-PDF-email-failing/m-p/426896#M122297</link>
    <description>&lt;P&gt;A dashboard will export to PDF correctly, but anytime we try to send it via email (be it a test email or scheduled) no email is sent and we see the following internal log entry.  This was working for many months (years?) and suddenly stopped working.  And is true for any/all dashboards we have created.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;2019-04-25 12:00:00,368 -0400 WARNING   sendemail:1398 - search results is empty, no email will be sent
host =       source = /apps/splunk/var/log/splunk/python.log      sourcetype = splunk_python
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Splunk Enterprise&lt;BR /&gt;
Version:&lt;BR /&gt;
7.2.6&lt;BR /&gt;
Build:&lt;BR /&gt;
c0bf0f679ce9&lt;/P&gt;</description>
    <pubDate>Thu, 25 Apr 2019 16:19:14 GMT</pubDate>
    <dc:creator>elumpkin_caisgr</dc:creator>
    <dc:date>2019-04-25T16:19:14Z</dc:date>
    <item>
      <title>Dashboard PDF email failing</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Dashboard-PDF-email-failing/m-p/426896#M122297</link>
      <description>&lt;P&gt;A dashboard will export to PDF correctly, but anytime we try to send it via email (be it a test email or scheduled) no email is sent and we see the following internal log entry.  This was working for many months (years?) and suddenly stopped working.  And is true for any/all dashboards we have created.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;2019-04-25 12:00:00,368 -0400 WARNING   sendemail:1398 - search results is empty, no email will be sent
host =       source = /apps/splunk/var/log/splunk/python.log      sourcetype = splunk_python
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Splunk Enterprise&lt;BR /&gt;
Version:&lt;BR /&gt;
7.2.6&lt;BR /&gt;
Build:&lt;BR /&gt;
c0bf0f679ce9&lt;/P&gt;</description>
      <pubDate>Thu, 25 Apr 2019 16:19:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Dashboard-PDF-email-failing/m-p/426896#M122297</guid>
      <dc:creator>elumpkin_caisgr</dc:creator>
      <dc:date>2019-04-25T16:19:14Z</dc:date>
    </item>
    <item>
      <title>Re: Dashboard PDF email failing</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Dashboard-PDF-email-failing/m-p/426897#M122298</link>
      <description>&lt;P&gt;The same problem occured for me. Workaround for this problem was to exchange the sendemail.py version. I used the sendemail.py version from Splunk 7.2.0 with full path: /etc/apps/search/bin/sendemail.py. Dashboard email sending working as usual afterwards.,&lt;/P&gt;</description>
      <pubDate>Fri, 26 Apr 2019 08:56:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Dashboard-PDF-email-failing/m-p/426897#M122298</guid>
      <dc:creator>gailuh</dc:creator>
      <dc:date>2019-04-26T08:56:02Z</dc:date>
    </item>
    <item>
      <title>Re: Dashboard PDF email failing</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Dashboard-PDF-email-failing/m-p/426898#M122299</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;

&lt;P&gt;I have the same issue, which appears to be introduced in 7.2.6, as email PDF delivery was working prior to upgrade.&lt;/P&gt;

&lt;P&gt;I'd like to try the workaround, however am slightly confused as where to find the sendemail.py version from Splunk 7.2.0 ? Do I need install 7.2.0 and extract sendemail.py or is there an archive somewhere I could pull it from?&lt;/P&gt;

&lt;P&gt;Thanks for your help!&lt;/P&gt;

&lt;P&gt;Jordan&lt;/P&gt;</description>
      <pubDate>Mon, 29 Apr 2019 14:30:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Dashboard-PDF-email-failing/m-p/426898#M122299</guid>
      <dc:creator>JAvnaim</dc:creator>
      <dc:date>2019-04-29T14:30:37Z</dc:date>
    </item>
    <item>
      <title>Re: Dashboard PDF email failing</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Dashboard-PDF-email-failing/m-p/426899#M122300</link>
      <description>&lt;P&gt;I have the same error.&lt;BR /&gt;
Splunk 7.2.6&lt;BR /&gt;
When sending Dashboard as pdf via mail (scheduled or with "send test email" command):&lt;BR /&gt;
2019-04-25 12:00:00,368 -0400 WARNING sendemail:1398 - search results is empty, no email will be sent&lt;/P&gt;

&lt;P&gt;When i open the Dashboard in Splunk i see that it is not empty...&lt;/P&gt;</description>
      <pubDate>Wed, 08 May 2019 07:23:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Dashboard-PDF-email-failing/m-p/426899#M122300</guid>
      <dc:creator>dfgrtKJH</dc:creator>
      <dc:date>2019-05-08T07:23:04Z</dc:date>
    </item>
    <item>
      <title>Re: Dashboard PDF email failing</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Dashboard-PDF-email-failing/m-p/426900#M122301</link>
      <description>&lt;P&gt;Splunk Support:&lt;/P&gt;

&lt;P&gt;I understand that your PDF scheduled from dashboards are no longer working on 7.2.6. I confirmed this is a known issue and we are actively working on finding a solution for it.&lt;/P&gt;

&lt;P&gt;We have found two possible workarounds:&lt;BR /&gt;
- Replace sendemail.py from 7.2.6 with the same file in your older version.&lt;BR /&gt;
- Edit your saved search, in the "Search" field replace "| noop" with "| makeresults".&lt;/P&gt;

&lt;P&gt;For the moment, the issue is still unresolved.&lt;/P&gt;</description>
      <pubDate>Wed, 08 May 2019 08:33:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Dashboard-PDF-email-failing/m-p/426900#M122301</guid>
      <dc:creator>dfgrtKJH</dc:creator>
      <dc:date>2019-05-08T08:33:30Z</dc:date>
    </item>
    <item>
      <title>Re: Dashboard PDF email failing</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Dashboard-PDF-email-failing/m-p/426901#M122302</link>
      <description>&lt;P&gt;solution if you do not have the old version:&lt;/P&gt;

&lt;OL&gt;
&lt;LI&gt;create backup of /opt/splunk/etc/apps/search/bin/sendemail.py&lt;/LI&gt;
&lt;LI&gt;open /opt/splunk/etc/apps/search/bin/sendemail.py (Splunk 7.2.6) with a editor as a user with write permissions.&lt;/LI&gt;
&lt;LI&gt;remove line 1398 "logger.warn("search results is empty, no email will be sent")"&lt;/LI&gt;
&lt;LI&gt;remove line 1397 "else:"&lt;/LI&gt;
&lt;LI&gt;remove 4 spaces at the start of lines 1393-1396 (if, results=,else,results=)&lt;/LI&gt;
&lt;LI&gt;remove line 1392 "if results:"&lt;/LI&gt;
&lt;LI&gt;save file&lt;/LI&gt;
&lt;LI&gt;test&lt;/LI&gt;
&lt;/OL&gt;</description>
      <pubDate>Wed, 08 May 2019 09:23:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Dashboard-PDF-email-failing/m-p/426901#M122302</guid>
      <dc:creator>dfgrtKJH</dc:creator>
      <dc:date>2019-05-08T09:23:28Z</dc:date>
    </item>
    <item>
      <title>Re: Dashboard PDF email failing</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Dashboard-PDF-email-failing/m-p/426902#M122303</link>
      <description>&lt;P&gt;We were having this problem with 7.2.6, and the issue was resolved with the 7.3 update -- though I could not find any reference to it in the release notes.&lt;/P&gt;

&lt;P&gt;The contents of the sendemail.py program look markedly different, so obviously a lot of code therein was touched by this update.&lt;/P&gt;

&lt;P&gt;Just glad it's working again,&lt;BR /&gt;
Aaron&lt;/P&gt;</description>
      <pubDate>Wed, 12 Jun 2019 21:15:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Dashboard-PDF-email-failing/m-p/426902#M122303</guid>
      <dc:creator>aaron_sakovich</dc:creator>
      <dc:date>2019-06-12T21:15:51Z</dc:date>
    </item>
    <item>
      <title>Re: Dashboard PDF email failing</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Dashboard-PDF-email-failing/m-p/426903#M122304</link>
      <description>&lt;P&gt;I can confirm this was fixed in 7.3.0.&lt;BR /&gt;
Yes the changelog does not contains this bugfix, which is rather unprofessional in my optinion.&lt;BR /&gt;
This thread can be closed.&lt;/P&gt;</description>
      <pubDate>Thu, 13 Jun 2019 07:28:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Dashboard-PDF-email-failing/m-p/426903#M122304</guid>
      <dc:creator>dfgrtKJH</dc:creator>
      <dc:date>2019-06-13T07:28:15Z</dc:date>
    </item>
    <item>
      <title>Re: Dashboard PDF email failing</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Dashboard-PDF-email-failing/m-p/426904#M122305</link>
      <description>&lt;P&gt;Does this workaround apply for 7.2.9 as well?&lt;/P&gt;</description>
      <pubDate>Mon, 25 Nov 2019 09:08:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Dashboard-PDF-email-failing/m-p/426904#M122305</guid>
      <dc:creator>saramamurthy_sp</dc:creator>
      <dc:date>2019-11-25T09:08:34Z</dc:date>
    </item>
  </channel>
</rss>

