Reporting

Why can I not send raw results as PDF?

bshuford
Path Finder

I have been looking in Splunk documentation for a few hours now and I cannot find a good way to send all the results of a saved search as an emailed PDF. I want all lines to be shown for all results. Right now, I can only get the latest 50 results, and only 10 lines per event. How do I make it so that I see everything? I don't really care how big the PDF or email is.

Tags (3)

Genti
Splunk Employee
Splunk Employee

btw, i take it you do care for the nice indentation, the human readable timestamp and the field extraction (host/source/sourcetype)? If so, then it is not raw results that you would like to send to PDF, it is actually parsed/indexed data.

0 Karma

Genti
Splunk Employee
Splunk Employee

Unfortunately this is the limitation of the PDF server and im not entirely sure but splunk is working on creating some way to make this work.

What can you use in the mean time?
Output to CSV file, use excel or any other type of software to manipulate the data and print to PDF.
Create a view that allows you to show as many events as you want and then print to PDF. Any other ideas?

.gz

Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...