Reporting

Scheduled report is done, but report page says "There are no results because the first scheduled run of the report has not completed.".

yutaka1005
Builder

I have just same issue as below question!

https://answers.splunk.com/answers/498825/why-does-my-scheduled-report-deliver-results-in-pd.html

My environment
OS:Linux7
Splunk:Stand-Alone Splunk 7.1.2

In my environment, there is the report scheduled every 15 minutes.
And if I check status in job activity, it is "done", and job inspector says "completed" too.

But if I check the page of report itself, it says "There are no results because the first scheduled run of the report has not completed.".

Does anyone have same issue?
Also, does anyone know how to solve it?

Please someone give me some information about it.

0 Karma

splunk_pn
Explorer

Hi, I think you maybe have another issue, because I didn't have this problem in 6.x version or in 7.0, the bug I was struck by was only in version 7.1.1.

I believe this was the bug corrected in 7.1.2:

2018-06-03 SPL-154567, SPL-154139 embedded report uses oldest search artifact from the history endpoint

My case id was 001116998.

/Patrik

0 Karma

splunk_pn
Explorer

Hi,

It turned out to be a bug in 7.1.1, fixed in 7.1.2 (and newer).
,

0 Karma

yutaka1005
Builder

Thank you for answer!

Would you tell me issue number of it?

0 Karma

skydancer
New Member

Any reference for that? Unfortunately, I am running Splunk 6.5.1.

0 Karma

splunk_pn
Explorer

Hi, did you find any solution to this?

I am seeing the same thing on my installation. Have a scheduled report that says in the job monitor that it is "done", and when opening that job id link - it is run and shows the correct result.
But going in to the report and clicking the report it says "There are no results because the first scheduled...".

OS:Windows 2012 R2
Splunk stand-alone 7.1.1.

0 Karma

skydancer
New Member

I have a very similar problem. I have number of users who can search on specific indices and theoretically can schedule reports, as their current role includes schedule_search capability. However, when a report is created and scheduled (even to run every minute) it always says:

"There are no results because the first scheduled run of the report has not completed."

Opening the report in search produces valid results though, and the search takes 1-2 seconds only.

0 Karma
Get Updates on the Splunk Community!

.conf24 | Day 0

Hello Splunk Community! My name is Chris, and I'm based in Canberra, Australia's capital, and I travelled for ...

Enhance Security Visibility with Splunk Enterprise Security 7.1 through Threat ...

 (view in My Videos)Struggling with alert fatigue, lack of context, and prioritization around security ...

Troubleshooting the OpenTelemetry Collector

  In this tech talk, you’ll learn how to troubleshoot the OpenTelemetry collector - from checking the ...