Reporting

Embed reports show older jobs and not most recent

dorilevy
Path Finder

Hello,
UPDATE TO MY QUESTION - i made it more clear:

All the embedded reports i created using splunk "embed" function are showing the earliest artficat result and not the latest one. I tried re-creating the report, edit them but no success.

I also tried to workaround it by setting report ttl so the earilest artifiact will be deleted, but the it's not deleting. instead the expiration time is just pushed by the number of seconds i set for TTL.

When i manually delete the earliest artifact the embed report will show the next earliest one.

This is happening on all my embedded reports.

Thanks
Dori

Tags (3)
0 Karma
1 Solution

Shtark
Explorer
0 Karma

dorilevy
Path Finder

Thanks for the update!
Do you know when is this version due? i couldn't find it.
Also do you have a link to the release notes of this version (i would like to share it in my office)?

0 Karma

Shtark
Explorer

I haven't seen a release date or notes for 6.4.3 yet sorry.

0 Karma

burwell
SplunkTrust
SplunkTrust

So with Splunk 6.4.3, I do see the behaviour of embed has changed. But for me the behaviour is worse.

We have a scheduled job that runs every hour and takes say 45 minutes. If you look at the embed while the job is running (most of the time) then you see a message about waiting for the scheduled job to complete. Is there anyway to see the previous completed job like you can with loadjob? I need this feature.

0 Karma

dorilevy
Path Finder

Update:

I just found out that when i ever access the embedded link, the artifact TTL will increase by the ttl settings (+120 seconds in my case).

So i have 2 issues here:
1. The embedded link is leading to the earlistet artifact and not the latest one.
2. TTL is increased when ever i access the link, so if i access it on an interval less then TTL i will always access the same search results.

0 Karma

woodcock
Esteemed Legend

How are you embedding the jobs? You should be using something like this:

| loadjob savedsearch="admin:search:MySavedSearch" artifact-offset=0

It would be even better to just use the job SID if you can get that somehow.

0 Karma

dorilevy
Path Finder

Hey,

Thanks. Im embedding it using the splunk embed feature.
As you can see from the documentation the loadjob command is not needed, nor the SID.

BR,
Dori

0 Karma
Get Updates on the Splunk Community!

Join Us for Splunk University and Get Your Bootcamp Game On!

If you know, you know! Splunk University is the vibe this summer so register today for bootcamps galore ...

.conf24 | Learning Tracks for Security, Observability, Platform, and Developers!

.conf24 is taking place at The Venetian in Las Vegas from June 11 - 14. Continue reading to learn about the ...

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...