Reporting

PDF chart does not display statistics correctly

dshakespeare_sp
Splunk Employee
Splunk Employee

I have set an alert to send me PDF of the results of my search, I want the PDF to show me statistics but The PDF always comes with a chart which is meaningless for my search. I have changed the display parameter in savedsearches.conf "display.general.type = statistics" but it doesn't make any difference.

Tags (1)
1 Solution

jdastmalchi_spl
Splunk Employee
Splunk Employee

When there is a transforming search, splunk always includes chart and table in the generated pdf.
The default value for display.visualizations.show in 'default/savedsearches.conf' is 1 which makes a chart to appear in the generated pdf.

If you just want the statistical table to appear in pdf the solution is to set the display.visualizations.show = 0 in 'savedsearches.conf' for that specific search to get only statistical table in the pdf.

If you wish you to change this for all your generated pdf files you can change this globally in $SPLUNK-HOME/etc/system/local/savedsearches.conf

View solution in original post

jdastmalchi_spl
Splunk Employee
Splunk Employee

When there is a transforming search, splunk always includes chart and table in the generated pdf.
The default value for display.visualizations.show in 'default/savedsearches.conf' is 1 which makes a chart to appear in the generated pdf.

If you just want the statistical table to appear in pdf the solution is to set the display.visualizations.show = 0 in 'savedsearches.conf' for that specific search to get only statistical table in the pdf.

If you wish you to change this for all your generated pdf files you can change this globally in $SPLUNK-HOME/etc/system/local/savedsearches.conf

grittonc
Contributor

This worked for me on v7.0.8.

0 Karma

Jamaal
Engager

I know this is a very old topic but I have the same issue. I added display.visualizations.show = 0 under the saved search I want to disable the chart for but its still showing when a pdf is generated. Will I also need to restart splunk services for the changes to take affect?

0 Karma

aaraneta_splunk
Splunk Employee
Splunk Employee

@Jamaal - As you've said, this question is quite old and it may not generate the type of activity that you're seeking. I would recommend a couple of options:

Option 1: Try asking a new question to the Answers forum so that your question can be seen.

Option 2: If you want to try to get some immediate help for your question, you should join the 1300+ Splunk users in our public Slack chat. People ask each other for immediate help on there daily. You can share your question/link to your post there to see if anyone can take a stab at it.

You first have to request access through http://splk.it/slack. Fill out the form, and once you receive the approval email from our Community Manager (usually the approval process make take a couple days), you can access Slack.com and ask for help in the #general channel.

Thanks!

Get Updates on the Splunk Community!

CX Day is Coming!

Customer Experience (CX) Day is on October 7th!! We're so excited to bring back another day full of wonderful ...

Strengthen Your Future: A Look Back at Splunk 10 Innovations and .conf25 Highlights!

The Big One: Splunk 10 is Here!  The moment many of you have been waiting for has arrived! We are thrilled to ...

Now Offering the AI Assistant Usage Dashboard in Cloud Monitoring Console

Today, we’re excited to announce the release of a brand new AI assistant usage dashboard in Cloud Monitoring ...