Dashboards & Visualizations

PDF scheduling is giving errors while using loadjob command in a Dashboard

swastikm123
Engager

I have a dashboard in which there are multiple panels and it has 3 base searches defined in it. I'm getting the below errors while scheduling PDF delivery for the dashboard but while manually exporting the PDF I'm not getting any errors.I'm getting the below errors for only 2 panels of the Dashboard:-

Server reported HTTP status=400 while getting mode=results<?xml version="1.0"
encoding="UTF-8"?><response> <messages> <msg type="FATAL">Error in 'SearchOperator:loadjob':
Cannot find artifacts for savedsearch_ident '$subsearch_sid3$'.</msg> </messages></response>

Both the Panel Searches are using loadjob commands.Loadjob command is using the SID of previous searches to get the results.

Kindly, help me out on this one?

Labels (1)
0 Karma

niketn
Legend

@swastikm123 Since, loadjob and post-process searches use Dispatch directly artifacts on SH to pull search results directly, for your Scheduled Dashboard PDF delivery it might be possible that Dispatch directory is getting cleaned up when search result are getting pulled up in the dashboard. Since this is scheduled dashboard can you use regular search query instead of loadjob?

If the issue persists reach out to Splunk Support with relevant details to get assistance.

____________________________________________
| makeresults | eval message= "Happy Splunking!!!"

swastikm123
Engager

@niketn  Thank you for your Response.I tried to use the actual search in place of loadjob but it gives me a different read connection timeout error as below and it is not working out.

Splunkd daemon is not responding: ("Error connecting to
https://[::1]:8089/services/search/jobs/<SID>/results:
('The read operation timed out',)",)

And I have tried to schedule the dashboard by increasing the Job expiration of the search job but still receiving the error:-

Server reported HTTP status=400 while getting mode=results<?xml version="1.0"
encoding="UTF-8"?><response> <messages> <msg type="FATAL">Error in 'SearchOperator:loadjob':
error accessing https://[::1]:8089/services/search/jobs/$subsearch_sid4$/?output_mode=json,
statusCode=401, description=Unauthorized</msg> </messages></response.

Kindly, let me know If I'm missing anything else here?

0 Karma

niketn
Legend

@swastikm123 best would be to open a support ticket and work with the Support team by providing them with required details. Seems like your SPL is very expensive or pulls a lot of data. Have you checked dispatch directory size and usage, search logs, failure details?

____________________________________________
| makeresults | eval message= "Happy Splunking!!!"
0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...