Splunk Enterprise

Why am I not receiving Scheduled Dashboard report?

Ash1
Communicator

I have scheduled the dashboard via "Schedule PDF" option , and i use to get mail everyday, but suddenly it got stopped receiving the dashboard PDF report to my mail.

how to trouble shoot the issue???

Labels (2)
Tags (2)
0 Karma
1 Solution

vishwa
Path Finder

yes the issue was with mail, correct it thank you for the guidence.

View solution in original post

richgalloway
SplunkTrust
SplunkTrust

Verify the dashboard is still scheduled and that it is not skipped.  Confirm the PDF is still being sent to you.

Check splunkd.log for "sendemail" errors. 

Verify your email provider is not blocking the messages.  Check your spam folder.

---
If this reply helps you, Karma would be appreciated.
0 Karma

Ash1
Communicator

hi @richgalloway 
1. Verify the dashboard is still scheduled and that it is not skipped.
i used below query to search 

index=_internal sourcetype=scheduler status=* savedsearch_name=xxxx

i am seeing status as status=delegated_remote and status=delegated_remote _completion

2.Check splunkd.log for "sendemail" errors. 
i am getting error: you dont have a role with the capability='run_custom_command' required to run this command "sendemail"

3.Verify your email provider is not blocking the messages.  Check your spam folder.--i dont see any mail in this

0 Karma

richgalloway
SplunkTrust
SplunkTrust

@Ash1 wrote:

hi @richgalloway 
1. Verify the dashboard is still scheduled and that it is not skipped.
i used below query to search 

index=_internal sourcetype=scheduler status=* savedsearch_name=xxxx

Rather than use a search for this, use the UI.  Go to Settings->User interface->View PDF scheduling and find the dashboard in question.  Confirm it is enabled and the TO field is correct.

i am seeing status as status=delegated_remote and status=delegated_remote _completion

2.Check splunkd.log for "sendemail" errors. 

i am getting error: you dont have a role with the capability='run_custom_command' required to run this command "sendemail"

Don't run the sendemail command, look for that word in the log.

 

 

index=_internal source=*splunkd.log "sendemail"

 

 

3.Verify your email provider is not blocking the messages.  Check your spam folder.--i dont see any mail in this


 

---
If this reply helps you, Karma would be appreciated.
0 Karma

Ash1
Communicator

Rather than use a search for this, use the UI.  Go to Settings->User interface->View PDF scheduling and find the dashboard in question.  Confirm it is enabled and the TO field is correct.

Yes it is enabled and To filed is mentioned with correct email id.

Don't run the sendemail command, look for that word in the log.

index=_internal source=*splunkd.log "sendemail"

 i could not find any logs with word sendemail

Tags (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

So there appears to be nothing wrong with Scheduled PDF delivery on Splunk's end.  The problem must be with the email provider.

---
If this reply helps you, Karma would be appreciated.

vishwa
Path Finder

yes the issue was with mail, correct it thank you for the guidence.

Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...