Reporting

Empty scheduled PDF reports

marksnelling
Communicator

I have a report that runs once a day that generates a PDF chart based on a view. When I load the view in my browser and click "Generate PDF" it takes approximately 3 seconds and the PDF is successfully rendered in my browser (Chrome). However the chart in the emailed report has no data, just the axis.

I'm using Splunk 5.0.1 and I don't have the PDF server app installed.

Tags (1)
1 Solution

marksnelling
Communicator

This problem has gone away for me in Splunk 6.0.2

View solution in original post

marksnelling
Communicator

This problem has gone away for me in Splunk 6.0.2

grundsch
Communicator

here I still have the problem, version 6.1.3

0 Karma

machiel
Path Finder

I also have the issue that some results do not come through in a daily PDF report (version 6.3).

0 Karma

kevinking
Explorer

I had a similar issue, 2 panes out of 6 on a dashboard would have no data if a chart or 'no results' if a table.
Creating a saved search and using a searchName element instead of a searchString for the table/chart panes resolved it.
The saved searches are also scheduled, but it also worked on the first run before a scheduled search ran. I don't know if that mattered or not.

grundsch
Communicator

Same here (version 6.1.3).
I had two online searches, not overly complicated, but they didn't show up in the sheduled reports (sent via the sendemail command).
Moving them to saved searches (not sheduled, jobs/artifacts deleted), the pdf now includes the data.

cwagnello
Engager

I have the same problem. It seems like a race condition as the PDF gets generated before the data is fully downloaded, so it's a matter of which finished first the data arriving from Splunk and how long the PDF takes to render.

The issue I am seeing is that I have multiple saved searches that run once a day at the same time. I have a dashboard that has a panel for each of the searches. I created a scheduled PDF to be run well after the saved searches are run. The PDF that gets delivered only has data in the panels that have less than 100 or so rows (this is just a guess). Empirically what I've seen is 10 rows of results show up fine but anything over 180 rows of data does not show up at all.

I have not found a solution for this.

the_wolverine
Champion

I agree it feels like a race condition. All my searches are scheduled so there should be no delay waiting for results.

0 Karma

marksnelling
Communicator

Here's a link to the XML generating the report http://pastebin.com/aEjgCS73

0 Karma

mkelderm
Path Finder

I have the same issue. My PDF is shown correctly in my broser (firefox) x and y axis and leganda are shown, but no graphic. Generate PDF is based on a dashboard:

index=prd_access sourcetype=access:web:msl querystring=/MSL/3/DeclaratieService operation=IndienenDeclaratie earliest=-1h | eval duur=floor(duration) | rangemap field=duur snelst=0-1 snel=2-5 traag=6-10 traagst=11-600 default=stroop | timechart span=5m count by range
{"stroop":0x000000,"traagst":0xFF0000,"traag":0xffa500,"snel":0xffff00,"snelst":0x00ff00}

0 Karma

Drainy
Champion

Could you paste your XML/Search so we could have a test? 🙂

0 Karma

marksnelling
Communicator

Has nobody encountered this?

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...