Deployment Architecture

Why are embedded reports from a search head cluster sometimes blank?

Olivier44
Explorer

Hello,

I made a web page with 4 embedded reports from Splunk. The reports are scheduled every 5 minutes and the web page reload itself every 1 minute. The embedded reports are pointing to one search head which is in a search head cluster.

My problem is that sometimes, some reports are blank, but the others are good!

Anyone has an idea of where is the problem ?

Thanks

0 Karma
1 Solution

renjith_nair
SplunkTrust
SplunkTrust

The scheduled report runs randomly on one of the search heads on the cluster. So it might not be on the search head where you have set the embedding. On top of that there was a bug in splunk which affects the behavior but this is fixed in 6.3

Also remember to set the embedSecret = in server.conf .

Details are

When using report embedding, normally the generated URLs can only
  be used on the search head they were generated on
* If "embedSecret" is set, then the token in the URL will be encrypted
  with this key.  Then other search heads with the exact same setting
  can also use the same URL.
* This is needed if you want to use report embedding across multiple
  nodes on a search head pool.

I'm running a search head cluster with url loadbalancing and embedded report works fine there.

Happy Splunking!

View solution in original post

renjith_nair
SplunkTrust
SplunkTrust

The scheduled report runs randomly on one of the search heads on the cluster. So it might not be on the search head where you have set the embedding. On top of that there was a bug in splunk which affects the behavior but this is fixed in 6.3

Also remember to set the embedSecret = in server.conf .

Details are

When using report embedding, normally the generated URLs can only
  be used on the search head they were generated on
* If "embedSecret" is set, then the token in the URL will be encrypted
  with this key.  Then other search heads with the exact same setting
  can also use the same URL.
* This is needed if you want to use report embedding across multiple
  nodes on a search head pool.

I'm running a search head cluster with url loadbalancing and embedded report works fine there.

Happy Splunking!
Get Updates on the Splunk Community!

What's new in Splunk Cloud Platform 9.1.2312?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.1.2312! Analysts can ...

What’s New in Splunk Security Essentials 3.8.0?

Splunk Security Essentials (SSE) is an app that can amplify the power of your existing Splunk Cloud Platform, ...

Let’s Get You Certified – Vegas-Style at .conf24

Are you ready to level up your Splunk game? Then, let’s get you certified live at .conf24 – our annual user ...