Reporting

Report failed schedule report

rsathish47
Contributor

HI All,

how do we report failed scheduled report/search in splunk.. Please let me know your thoughts .

Thanks
Sathish R

Tags (1)
0 Karma

jonaclough
Path Finder

Scheduled report:

index=_internal source="*scheduler.log" log_level=ERROR 
| eval user=mvindex(split(savedsearch_id, ";"), 0)
| eval app=mvindex(split(savedsearch_id, ";"), 1)
| eval search=mvindex(split(savedsearch_id, ";"), 2)
| stats count by user, app , search, message

Failed search:

index=_audit action=search has_error_warn=true fully_completed_search=false

 

0 Karma

MuS
SplunkTrust
SplunkTrust

Hi rsathish47,

check your Splunk logs like this:

index=_internal source="*scheduler.log"

this will bring up all information about the scheduled searches. You can find more information on other Splunk internal messages if you leave the source from the search.
You can find some pdf related messages in python.log for example and you can increase logging channels to get more detailed messages back http://docs.splunk.com/Documentation/Splunk/latest/Troubleshooting/Enabledebuglogging

hope that helps ...

cheers, MuS

MuS
SplunkTrust
SplunkTrust

please provide more details, like do you want to search for searches that literally failed (the search itself?) or do you want to run a search that searches for events that contain the value failed ?

0 Karma

rsathish47
Contributor

Errors Like this
An error occurred while generating a PDF of this report
Some times we are not reciveing mail from scheduled search/report

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

SOK it to Me: Top 3 Benefits of Using Splunk Operator on Kubernetes that’ll Make ...

    Thursday, July 9, 2026  |  11:00AM–12:00PM PDT Duration: 1 hour (includes Q&A) Managing can feel like a ...

Upgrade Prep for 10.4, Network Observability Deep Dives, and More from Splunk Lantern

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...

Splunk Developer Day announcements: AI agents, MCP tools, Forecasting, and Custom ...

Splunk Developer Day was packed with product and platform updates for developers building in the AI ...