Dashboards & Visualizations

Why is the scheduled dashboard PDF attaching "_clone" to the file name and how to prevent this?

jldebell
Path Finder

Hi,

We have a dashboard that we are attempting to schedule on a weekly basis as a PDF. On the dashboard page, we select the Edit drop-down, select Edit PDF Schedule and select the Schedule PDF button. We add the details including the scheduled time, the email addresses, and the format. Click on Save. I went into All Configurations and confirmed the PDF is available. The name of the file is _ScheduledView_appname_weekly_report_clone. The system doesn't provide an option to name the file. We cannot locate other files on the system with the same name. How do we prevent the _clone portion from populating or remove it from the name?

Thanks, Jenn

1 Solution

somesoni2
Revered Legend

Check the sharing permissions of the _ScheduledView_appname_weekly_report_clone.
If it's private, check the folder $Splunk_Home/etc/users///local/savedsearches.conf.
If it's App or Global, check the folder $Splunk_Home/etc/apps//local/savedsearches.conf.

Once found update the name to remove the _clone. Once done, go to $Splunk_Home/etc/apps//metadata/local.meta and find _ScheduledView_appname_weekly_report_clone entry and rename it too. Restart/refresh SPlunk Instance once all these are done.

View solution in original post

somesoni2
Revered Legend

Check the sharing permissions of the _ScheduledView_appname_weekly_report_clone.
If it's private, check the folder $Splunk_Home/etc/users///local/savedsearches.conf.
If it's App or Global, check the folder $Splunk_Home/etc/apps//local/savedsearches.conf.

Once found update the name to remove the _clone. Once done, go to $Splunk_Home/etc/apps//metadata/local.meta and find _ScheduledView_appname_weekly_report_clone entry and rename it too. Restart/refresh SPlunk Instance once all these are done.

jldebell
Path Finder

Thanks for the recommendation! I was able to update it. i did a debug/refresh and it updated. Thanks again!

0 Karma
Get Updates on the Splunk Community!

Archived Metrics Now Available for APAC and EMEA realms

We’re excited to announce the launch of Archived Metrics in Splunk Infrastructure Monitoring for our customers ...

Detecting Remote Code Executions With the Splunk Threat Research Team

WATCH NOWRemote code execution (RCE) vulnerabilities pose a significant risk to organizations. If exploited, ...

Enter the Dashboard Challenge and Watch the .conf24 Global Broadcast!

The Splunk Community Dashboard Challenge is still happening, and it's not too late to enter for the week of ...