All Apps and Add-ons

error in "docgen" command

abhayneilam
Contributor

I am using the following command :

index="cd_data_new" | search was_blocked="False" | dedup was_blocked | table was_blocked | docgen -tfile=322004887_old.odt

In C:\Program Files\Splunk\etc\apps\odts_splunk\templates this directory I have kept my 322004887_old.odt pattern,

Data Transfers Employee Exiting Log Activity Report

Please find below the content of my document in .odt

Dear HR Manager and Direct People Manager,
I am writing you to report the required Employee Exiting Process, for Data Transfer Activity. Employee: Leong, Kok Cheong and SSO: XXXXXXXXXXXX

so in place of XXXXXXXXXXXX I want the output of my quest to be pasted.

Please suggest me to do that..

Basically I want to generate .doc format report through SPLUNK , that is my prior goal.

Thanks in advance !!

0 Karma

splunktechie
Explorer

abhayneilam,
first you should start with looking into templates provided by app itself (could be found in splunk_home/etc/apps/odts_splunk/templates folder). To customize/create template you need openoffice/libreoffice installed. Also, You could find usefull following link on creating templates: http://appyframework.org/podWritingTemplates.html. The only important thing you need to know to create template is that result of splunk search delivered to "events" variable. Constructs like table or cell created using "comments" sections. Values are inserted through "track changes" or openoffice "fields". Was it usefull?

splunktechie
Explorer

Sounds easy, just take dump_table_custom.odt template from app's templates folder, change it(in libre office/openoffice) accordingly. You just don't need to change comment line that inserts command . And use this template in docgen command like docgen -tfile=mytable.odt

0 Karma

abhayneilam
Contributor

Could you please get me clear picture about how to create the custom report..lets say I am getting a ssoid and the name from a splunk query and that I want to put in a particular place in my custom document , how do I do that ?

Please let me know the solution as I am working on this since long

0 Karma

splunktechie
Explorer

abhayneilam,
thanks for your feedback, i will try to extend app's page to give more details about creating own templates in near future.

0 Karma

abhayneilam
Contributor

Can you get me some examples for this? I have gone through the examples but not able to understand ...it would be helpful If I get some real example for this....Kindly help me with this...

Thanks in Advance Splunktechie

0 Karma

splunktechie
Explorer

Anyway it seems I need to provide deeper docs about creating custome templates.

0 Karma

abhayneilam
Contributor

Following is the format of my file :

Data Transfers Employee Exiting Log Activity ReportPlease find below the content of my document in .odtDear HR Manager and Direct People Manager,
I am writing you to report the required Employee Exiting Process, for Data Transfer Activity. Employee: Leong, Kok Cheong and SSO: XXXXXXXXXXXX

Now, Instead of XXXXXXX I want to run one query and want to fetch the result and want to put there ..

0 Karma

splunktechie
Explorer

Hello abhayneilam,
it's only a matter of proper template - what it's inside your template? could you post it somewhere?

Ayn
Legend

Can't help you I'm afraid, I don't have any experience with this app. It seems it has excellent documentation though so my bet would be to start there...

0 Karma

abhayneilam
Contributor

I am getting the error that "format is not correct", I just want to know whether I can create a report in .doc format with docgen command, I have some report format, in the middle of some places I need to put some data from the query

Pleae help me out with this

0 Karma

Ayn
Legend

I don't get it. What is the error you're referring to?

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...