Reporting

PDF scheduled view will not display inline. What is the issue? (Splunk v4.3.4)

the_wolverine
Champion

PDF Server is installed and working. I can schedule a PDF report or view. The report (scheduled search) will display properly inline. However the view will not display inline.

When manually opened, the PDF is correct and as expected.

The contents of email:

"Scheduled view delivery.
A PDF snapshot has been generated for the view: My_TEST_Report.
Name: 'ScheduledView_My_TEST_Report'
"

I know that Splunk is able to display PDF inline since when I schedule a report as PDF, it will provide the PDF snapshot of the results inline in the email message. However, the scheduled view is not displayed inline as expected.

I have tried setting inline = 1 under [email] stanza in alert_actions.conf in addition to ensuring that the scheduled search was explicitly set to deliver the PDF inline.

0 Karma
1 Solution

the_wolverine
Champion

The issue is that the setting to display inline is overridden by the mail client setting which determines (based on file size) whether it will be displayed in-line or as attachment.

View solution in original post

the_wolverine
Champion

The issue is that the setting to display inline is overridden by the mail client setting which determines (based on file size) whether it will be displayed in-line or as attachment.

splunkIT
Splunk Employee
Splunk Employee
0 Karma

bmignosa_splunk
Splunk Employee
Splunk Employee

Is there a configuration file or setting within mail that will include more pdf pages inline?

0 Karma

Chubbybunny
Splunk Employee
Splunk Employee

I've taken a closer look, and found the OS X "Mail" client will include the PDF inline. However, the PDF attachment will need to be 1 page, anything more will be shown as an email attachment.

*tested on MS Outlook:mac2011 - and is always delivered as an attachment.

0 Karma

the_wolverine
Champion

I have further narrowed down the issue to the number of queries (or panels.) If I only have a single query, it displays inline properly. If I have 2 or more queries/panels, it comes as an attachment.

0 Karma
Get Updates on the Splunk Community!

Detecting Remote Code Executions With the Splunk Threat Research Team

WATCH NOWRemote code execution (RCE) vulnerabilities pose a significant risk to organizations. If exploited, ...

Enter the Splunk Community Dashboard Challenge for Your Chance to Win!

The Splunk Community Dashboard Challenge is underway! This is your chance to showcase your skills in creating ...

.conf24 | Session Scheduler is Live!!

.conf24 is happening June 11 - 14 in Las Vegas, and we are thrilled to announce that the conference catalog ...