Reporting

How do you schedule delivery for app that has the option grayed out?

damode
Motivator

I have some Splunk apps like Cisco, Exchange, A.D, Clearpass that have the "Schedule delivery" option grayed out but the Export PDF option available.

I have a requirement from client to schedule delivery of these reports every day at 9am? Please advise how can I achieve this ?

0 Karma
1 Solution

cmerriman
Super Champion

right, you cannot schedule a dashboard that includes an input. The dashboard wouldn't know what was supposed to be inputted (it won't automatically use defaults).

The best workaround would be to clone the dashboard (if you still want one there for user inputs, otherwise just use that dashboard), remove all inputs from the dashboard and replace the tokens to the value you'd like to see on the schedule. This could include wildcards, if you want to see all, or a certain value.

View solution in original post

cmerriman
Super Champion

right, you cannot schedule a dashboard that includes an input. The dashboard wouldn't know what was supposed to be inputted (it won't automatically use defaults).

The best workaround would be to clone the dashboard (if you still want one there for user inputs, otherwise just use that dashboard), remove all inputs from the dashboard and replace the tokens to the value you'd like to see on the schedule. This could include wildcards, if you want to see all, or a certain value.

damode
Motivator

@cmerriman, Thanks! This worked quite well.

0 Karma

damode
Motivator

Hi @cmerriman,

Although I have been able to re-create the dashboard with the same data without the user input option, however, The search still seems to be going with the blue progress bar at the top of any panel stuck in the middle.

When I hover mouse over it, it says "0.0% of the time range scanned". how can I solve this ?

I have already checked the html code of default page with customised one, the only difference between them is $earliest$ , $latest$ and $product_selection$ is replaced by -24h@h, now and WLC

0 Karma

cmerriman
Super Champion

How many events are in this 24 hour span that the search is trying to scan? Can you post your search to see if there is a way to possibly make it run more efficiently?

0 Karma

damode
Motivator

It has around 1,735,037 events. I forgot to mention that the above condition occurs after it has already ran its first search and populated the dashboard.

This is the link to that image. https://ibb.co/gw6zRR

0 Karma

damode
Motivator

Finally found the solution to that problem.

Solution was to "edit search" option of each panel, select"use time picker" from the time range option then select preferred duration e.g "last 24 hours". I noticed that doing this stopped the Search to re-run and get stuck in the middle.

0 Karma

s2_splunk
Splunk Employee
Splunk Employee

I assume you are talking about reports. I suspect the reason for the scheduling option being greyed out on some is that the reports require user input for search time range via a time range picker.
You can validate that by picking one of the reports you want to schedule and remove the time range picker, which should allow you to schedule the report and specify the search time frame.

0 Karma

damode
Motivator

I have already tried that option too by removing the "time" input from the "edit" dashboard" layout. But still it doesnt work.

So, I just did a test and noticed that "schedule delivery" option becomes available once you remove any kind of input that is there, however, at that point it is not of any use because the dashboard doesnt generate any data as the input itself is not present

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Unlock What’s Next: The Splunk Cloud Platform at .conf25

In just a few days, Boston will be buzzing as the Splunk team and thousands of community members come together ...