Splunk Enterprise

Why am I not receiving Scheduled Dashboard report?

Ash1
Communicator

I have scheduled the dashboard via "Schedule PDF" option , and i use to get mail everyday, but suddenly it got stopped receiving the dashboard PDF report to my mail.

how to trouble shoot the issue???

Labels (2)
Tags (2)
0 Karma
1 Solution

vishwa
Path Finder

yes the issue was with mail, correct it thank you for the guidence.

View solution in original post

richgalloway
SplunkTrust
SplunkTrust

Verify the dashboard is still scheduled and that it is not skipped.  Confirm the PDF is still being sent to you.

Check splunkd.log for "sendemail" errors. 

Verify your email provider is not blocking the messages.  Check your spam folder.

---
If this reply helps you, Karma would be appreciated.
0 Karma

Ash1
Communicator

hi @richgalloway 
1. Verify the dashboard is still scheduled and that it is not skipped.
i used below query to search 

index=_internal sourcetype=scheduler status=* savedsearch_name=xxxx

i am seeing status as status=delegated_remote and status=delegated_remote _completion

2.Check splunkd.log for "sendemail" errors. 
i am getting error: you dont have a role with the capability='run_custom_command' required to run this command "sendemail"

3.Verify your email provider is not blocking the messages.  Check your spam folder.--i dont see any mail in this

0 Karma

richgalloway
SplunkTrust
SplunkTrust

@Ash1 wrote:

hi @richgalloway 
1. Verify the dashboard is still scheduled and that it is not skipped.
i used below query to search 

index=_internal sourcetype=scheduler status=* savedsearch_name=xxxx

Rather than use a search for this, use the UI.  Go to Settings->User interface->View PDF scheduling and find the dashboard in question.  Confirm it is enabled and the TO field is correct.

i am seeing status as status=delegated_remote and status=delegated_remote _completion

2.Check splunkd.log for "sendemail" errors. 

i am getting error: you dont have a role with the capability='run_custom_command' required to run this command "sendemail"

Don't run the sendemail command, look for that word in the log.

 

 

index=_internal source=*splunkd.log "sendemail"

 

 

3.Verify your email provider is not blocking the messages.  Check your spam folder.--i dont see any mail in this


 

---
If this reply helps you, Karma would be appreciated.
0 Karma

Ash1
Communicator

Rather than use a search for this, use the UI.  Go to Settings->User interface->View PDF scheduling and find the dashboard in question.  Confirm it is enabled and the TO field is correct.

Yes it is enabled and To filed is mentioned with correct email id.

Don't run the sendemail command, look for that word in the log.

index=_internal source=*splunkd.log "sendemail"

 i could not find any logs with word sendemail

Tags (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

So there appears to be nothing wrong with Scheduled PDF delivery on Splunk's end.  The problem must be with the email provider.

---
If this reply helps you, Karma would be appreciated.

vishwa
Path Finder

yes the issue was with mail, correct it thank you for the guidence.

Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...