Splunk Enterprise

Why am I not receiving Scheduled Dashboard report?

Ash1
Communicator

I have scheduled the dashboard via "Schedule PDF" option , and i use to get mail everyday, but suddenly it got stopped receiving the dashboard PDF report to my mail.

how to trouble shoot the issue???

Labels (2)
Tags (2)
0 Karma
1 Solution

vishwa
Path Finder

yes the issue was with mail, correct it thank you for the guidence.

View solution in original post

richgalloway
SplunkTrust
SplunkTrust

Verify the dashboard is still scheduled and that it is not skipped.  Confirm the PDF is still being sent to you.

Check splunkd.log for "sendemail" errors. 

Verify your email provider is not blocking the messages.  Check your spam folder.

---
If this reply helps you, Karma would be appreciated.
0 Karma

Ash1
Communicator

hi @richgalloway 
1. Verify the dashboard is still scheduled and that it is not skipped.
i used below query to search 

index=_internal sourcetype=scheduler status=* savedsearch_name=xxxx

i am seeing status as status=delegated_remote and status=delegated_remote _completion

2.Check splunkd.log for "sendemail" errors. 
i am getting error: you dont have a role with the capability='run_custom_command' required to run this command "sendemail"

3.Verify your email provider is not blocking the messages.  Check your spam folder.--i dont see any mail in this

0 Karma

richgalloway
SplunkTrust
SplunkTrust

@Ash1 wrote:

hi @richgalloway 
1. Verify the dashboard is still scheduled and that it is not skipped.
i used below query to search 

index=_internal sourcetype=scheduler status=* savedsearch_name=xxxx

Rather than use a search for this, use the UI.  Go to Settings->User interface->View PDF scheduling and find the dashboard in question.  Confirm it is enabled and the TO field is correct.

i am seeing status as status=delegated_remote and status=delegated_remote _completion

2.Check splunkd.log for "sendemail" errors. 

i am getting error: you dont have a role with the capability='run_custom_command' required to run this command "sendemail"

Don't run the sendemail command, look for that word in the log.

 

 

index=_internal source=*splunkd.log "sendemail"

 

 

3.Verify your email provider is not blocking the messages.  Check your spam folder.--i dont see any mail in this


 

---
If this reply helps you, Karma would be appreciated.
0 Karma

Ash1
Communicator

Rather than use a search for this, use the UI.  Go to Settings->User interface->View PDF scheduling and find the dashboard in question.  Confirm it is enabled and the TO field is correct.

Yes it is enabled and To filed is mentioned with correct email id.

Don't run the sendemail command, look for that word in the log.

index=_internal source=*splunkd.log "sendemail"

 i could not find any logs with word sendemail

Tags (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

So there appears to be nothing wrong with Scheduled PDF delivery on Splunk's end.  The problem must be with the email provider.

---
If this reply helps you, Karma would be appreciated.

vishwa
Path Finder

yes the issue was with mail, correct it thank you for the guidence.

Get Updates on the Splunk Community!

What's New in Splunk Enterprise 9.4: Features to Power Your Digital Resilience

Hey Splunky People! We are excited to share the latest updates in Splunk Enterprise 9.4. In this release we ...

Take Your Breath Away with Splunk Risk-Based Alerting (RBA)

WATCH NOW!The Splunk Guide to Risk-Based Alerting is here to empower your SOC like never before. Join Haylee ...

SignalFlow: What? Why? How?

What is SignalFlow? Splunk Observability Cloud’s analytics engine, SignalFlow, opens up a world of in-depth ...