Reporting

How do you schedule delivery for app that has the option grayed out?

Builder

I have some Splunk apps like Cisco, Exchange, A.D, Clearpass that have the "Schedule delivery" option grayed out but the Export PDF option available.

I have a requirement from client to schedule delivery of these reports every day at 9am? Please advise how can I achieve this ?

0 Karma
1 Solution

Super Champion

right, you cannot schedule a dashboard that includes an input. The dashboard wouldn't know what was supposed to be inputted (it won't automatically use defaults).

The best workaround would be to clone the dashboard (if you still want one there for user inputs, otherwise just use that dashboard), remove all inputs from the dashboard and replace the tokens to the value you'd like to see on the schedule. This could include wildcards, if you want to see all, or a certain value.

View solution in original post

Super Champion

right, you cannot schedule a dashboard that includes an input. The dashboard wouldn't know what was supposed to be inputted (it won't automatically use defaults).

The best workaround would be to clone the dashboard (if you still want one there for user inputs, otherwise just use that dashboard), remove all inputs from the dashboard and replace the tokens to the value you'd like to see on the schedule. This could include wildcards, if you want to see all, or a certain value.

View solution in original post

Builder

@cmerriman, Thanks! This worked quite well.

0 Karma

Builder

Hi @cmerriman,

Although I have been able to re-create the dashboard with the same data without the user input option, however, The search still seems to be going with the blue progress bar at the top of any panel stuck in the middle.

When I hover mouse over it, it says "0.0% of the time range scanned". how can I solve this ?

I have already checked the html code of default page with customised one, the only difference between them is $earliest$ , $latest$ and $product_selection$ is replaced by -24h@h, now and WLC

0 Karma

Super Champion

How many events are in this 24 hour span that the search is trying to scan? Can you post your search to see if there is a way to possibly make it run more efficiently?

0 Karma

Builder

It has around 1,735,037 events. I forgot to mention that the above condition occurs after it has already ran its first search and populated the dashboard.

This is the link to that image. https://ibb.co/gw6zRR

0 Karma

Builder

Finally found the solution to that problem.

Solution was to "edit search" option of each panel, select"use time picker" from the time range option then select preferred duration e.g "last 24 hours". I noticed that doing this stopped the Search to re-run and get stuck in the middle.

0 Karma

Splunk Employee
Splunk Employee

I assume you are talking about reports. I suspect the reason for the scheduling option being greyed out on some is that the reports require user input for search time range via a time range picker.
You can validate that by picking one of the reports you want to schedule and remove the time range picker, which should allow you to schedule the report and specify the search time frame.

0 Karma

Builder

I have already tried that option too by removing the "time" input from the "edit" dashboard" layout. But still it doesnt work.

So, I just did a test and noticed that "schedule delivery" option becomes available once you remove any kind of input that is there, however, at that point it is not of any use because the dashboard doesnt generate any data as the input itself is not present

0 Karma