Previously working scheduled reports are not working AND newly created reports are not working.
Creating a new test search works:
index=test1 | timechart count by status
The timechart is created, but putting this search into a report doesn't work:
index=test1 | timechart count by status | collect index=test2
... no scheduled search is run and no data is collected into index=test2
I've check my user/role permissions, and they seem fine .. admin access
I've checked the licensing, no limits reached
No recent search head changes
I've adjusted report/schedule times 5, 15, 1hr (cron & basic)
I've enabled/disabled summary indexing within reports
I've checked the search app for permissions.. admin read/write, global, sharing-config all_apps
I've deleted the original report and recreated it
Splunk 6.4 - enterprise
Another admin here was updating app permissions, refining global sets a few days before, but he assures this shouldn't be the issue.
If this was the problem, the only app I can see that may be the issue would be the Search app .. which i have admin access in.
**Is there a global app permission that needs to be enabled/adjusted?
Any other advice on what to check or do?**
Thank You
↧