Splunk Enterprise

Why am I not receiving Scheduled Dashboard report?

Ash1
Communicator

I have scheduled the dashboard via "Schedule PDF" option , and i use to get mail everyday, but suddenly it got stopped receiving the dashboard PDF report to my mail.

how to trouble shoot the issue???

Labels (2)
Tags (2)
0 Karma
1 Solution

vishwa
Path Finder

yes the issue was with mail, correct it thank you for the guidence.

View solution in original post

richgalloway
SplunkTrust
SplunkTrust

Verify the dashboard is still scheduled and that it is not skipped.  Confirm the PDF is still being sent to you.

Check splunkd.log for "sendemail" errors. 

Verify your email provider is not blocking the messages.  Check your spam folder.

---
If this reply helps you, Karma would be appreciated.
0 Karma

Ash1
Communicator

hi @richgalloway 
1. Verify the dashboard is still scheduled and that it is not skipped.
i used below query to search 

index=_internal sourcetype=scheduler status=* savedsearch_name=xxxx

i am seeing status as status=delegated_remote and status=delegated_remote _completion

2.Check splunkd.log for "sendemail" errors. 
i am getting error: you dont have a role with the capability='run_custom_command' required to run this command "sendemail"

3.Verify your email provider is not blocking the messages.  Check your spam folder.--i dont see any mail in this

0 Karma

richgalloway
SplunkTrust
SplunkTrust

@Ash1 wrote:

hi @richgalloway 
1. Verify the dashboard is still scheduled and that it is not skipped.
i used below query to search 

index=_internal sourcetype=scheduler status=* savedsearch_name=xxxx

Rather than use a search for this, use the UI.  Go to Settings->User interface->View PDF scheduling and find the dashboard in question.  Confirm it is enabled and the TO field is correct.

i am seeing status as status=delegated_remote and status=delegated_remote _completion

2.Check splunkd.log for "sendemail" errors. 

i am getting error: you dont have a role with the capability='run_custom_command' required to run this command "sendemail"

Don't run the sendemail command, look for that word in the log.

 

 

index=_internal source=*splunkd.log "sendemail"

 

 

3.Verify your email provider is not blocking the messages.  Check your spam folder.--i dont see any mail in this


 

---
If this reply helps you, Karma would be appreciated.
0 Karma

Ash1
Communicator

Rather than use a search for this, use the UI.  Go to Settings->User interface->View PDF scheduling and find the dashboard in question.  Confirm it is enabled and the TO field is correct.

Yes it is enabled and To filed is mentioned with correct email id.

Don't run the sendemail command, look for that word in the log.

index=_internal source=*splunkd.log "sendemail"

 i could not find any logs with word sendemail

Tags (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

So there appears to be nothing wrong with Scheduled PDF delivery on Splunk's end.  The problem must be with the email provider.

---
If this reply helps you, Karma would be appreciated.

vishwa
Path Finder

yes the issue was with mail, correct it thank you for the guidence.

Get Updates on the Splunk Community!

Introducing Splunk Enterprise 9.2

WATCH HERE! Watch this Tech Talk to learn about the latest features and enhancements shipped in the new Splunk ...

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...