Reporting

PDF chart does not display statistics correctly

dshakespeare_sp
Splunk Employee
Splunk Employee

I have set an alert to send me PDF of the results of my search, I want the PDF to show me statistics but The PDF always comes with a chart which is meaningless for my search. I have changed the display parameter in savedsearches.conf "display.general.type = statistics" but it doesn't make any difference.

Tags (1)
1 Solution

jdastmalchi_spl
Splunk Employee
Splunk Employee

When there is a transforming search, splunk always includes chart and table in the generated pdf.
The default value for display.visualizations.show in 'default/savedsearches.conf' is 1 which makes a chart to appear in the generated pdf.

If you just want the statistical table to appear in pdf the solution is to set the display.visualizations.show = 0 in 'savedsearches.conf' for that specific search to get only statistical table in the pdf.

If you wish you to change this for all your generated pdf files you can change this globally in $SPLUNK-HOME/etc/system/local/savedsearches.conf

View solution in original post

jdastmalchi_spl
Splunk Employee
Splunk Employee

When there is a transforming search, splunk always includes chart and table in the generated pdf.
The default value for display.visualizations.show in 'default/savedsearches.conf' is 1 which makes a chart to appear in the generated pdf.

If you just want the statistical table to appear in pdf the solution is to set the display.visualizations.show = 0 in 'savedsearches.conf' for that specific search to get only statistical table in the pdf.

If you wish you to change this for all your generated pdf files you can change this globally in $SPLUNK-HOME/etc/system/local/savedsearches.conf

grittonc
Contributor

This worked for me on v7.0.8.

0 Karma

Jamaal
Engager

I know this is a very old topic but I have the same issue. I added display.visualizations.show = 0 under the saved search I want to disable the chart for but its still showing when a pdf is generated. Will I also need to restart splunk services for the changes to take affect?

0 Karma

aaraneta_splunk
Splunk Employee
Splunk Employee

@Jamaal - As you've said, this question is quite old and it may not generate the type of activity that you're seeking. I would recommend a couple of options:

Option 1: Try asking a new question to the Answers forum so that your question can be seen.

Option 2: If you want to try to get some immediate help for your question, you should join the 1300+ Splunk users in our public Slack chat. People ask each other for immediate help on there daily. You can share your question/link to your post there to see if anyone can take a stab at it.

You first have to request access through http://splk.it/slack. Fill out the form, and once you receive the approval email from our Community Manager (usually the approval process make take a couple days), you can access Slack.com and ask for help in the #general channel.

Thanks!

Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...