Reporting

Embed reports show older jobs and not most recent

dorilevy
Path Finder

Hello,
UPDATE TO MY QUESTION - i made it more clear:

All the embedded reports i created using splunk "embed" function are showing the earliest artficat result and not the latest one. I tried re-creating the report, edit them but no success.

I also tried to workaround it by setting report ttl so the earilest artifiact will be deleted, but the it's not deleting. instead the expiration time is just pushed by the number of seconds i set for TTL.

When i manually delete the earliest artifact the embed report will show the next earliest one.

This is happening on all my embedded reports.

Thanks
Dori

Tags (3)
0 Karma
1 Solution

Shtark
Explorer
0 Karma

dorilevy
Path Finder

Thanks for the update!
Do you know when is this version due? i couldn't find it.
Also do you have a link to the release notes of this version (i would like to share it in my office)?

0 Karma

Shtark
Explorer

I haven't seen a release date or notes for 6.4.3 yet sorry.

0 Karma

burwell
SplunkTrust
SplunkTrust

So with Splunk 6.4.3, I do see the behaviour of embed has changed. But for me the behaviour is worse.

We have a scheduled job that runs every hour and takes say 45 minutes. If you look at the embed while the job is running (most of the time) then you see a message about waiting for the scheduled job to complete. Is there anyway to see the previous completed job like you can with loadjob? I need this feature.

0 Karma

dorilevy
Path Finder

Update:

I just found out that when i ever access the embedded link, the artifact TTL will increase by the ttl settings (+120 seconds in my case).

So i have 2 issues here:
1. The embedded link is leading to the earlistet artifact and not the latest one.
2. TTL is increased when ever i access the link, so if i access it on an interval less then TTL i will always access the same search results.

0 Karma

woodcock
Esteemed Legend

How are you embedding the jobs? You should be using something like this:

| loadjob savedsearch="admin:search:MySavedSearch" artifact-offset=0

It would be even better to just use the job SID if you can get that somehow.

0 Karma

dorilevy
Path Finder

Hey,

Thanks. Im embedding it using the splunk embed feature.
As you can see from the documentation the loadjob command is not needed, nor the SID.

BR,
Dori

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...