<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How do I prevent Splunk from automatically removing spaces from my search query? in Splunk Dev</title>
    <link>https://community.splunk.com/t5/Splunk-Dev/How-do-I-prevent-Splunk-from-automatically-removing-spaces-from/m-p/256274#M3202</link>
    <description>&lt;P&gt;We are having the same issue.  We primarily use IE as well.  I will test in Firefox and Microsoft Edge.&lt;/P&gt;</description>
    <pubDate>Thu, 03 Nov 2016 19:07:19 GMT</pubDate>
    <dc:creator>james_hopton</dc:creator>
    <dc:date>2016-11-03T19:07:19Z</dc:date>
    <item>
      <title>How do I prevent Splunk from automatically removing spaces from my search query?</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/How-do-I-prevent-Splunk-from-automatically-removing-spaces-from/m-p/256265#M3193</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I've been using Splunk 6.4 to create a set dashboard panels. I've come a across an issue where I have the following query:&lt;/P&gt;

&lt;P&gt;index=index Category="$Category_1$" | eval  eval_1=substr(field_1,1,7) | top limit=$TopNo_1$ eval_1 | fields - percent &lt;/P&gt;

&lt;P&gt;This query works perfectly when I first write and save it to a panel. However, once I leave the dashboard and come back into it, the panel no longer returns anything because the query has been changed to this:&lt;/P&gt;

&lt;P&gt;index=index Category="$Category_1$" | eval  eval_1=substr(field_1,1,7) | top limit=$TopNo_1$ eval_1 | fields-percent &lt;/P&gt;

&lt;P&gt;The spaces in the fields section get removed. Instead of removing the percent field, it tries to show only the -percent field, which does not exist. Now it doesn't seem to matter what I try with that fields, if I try "percent", or try moving that segment to the middle of the query. Both of these tweaks work at first, but ultimately the spaces get removed.&lt;/P&gt;

&lt;P&gt;Sometimes this query does stay the way I need it to. However, on the same dashboard, I have a second panel which faces the same problem. What then becomes the case is that one panel will be fine, but the other is broken, and when I fix the second panel, the first panel breaks, and then vice versa if I fix the first panel.&lt;/P&gt;

&lt;P&gt;I have tried going directly into the source and making changes there, but the same issue occurs.&lt;/P&gt;

&lt;P&gt;So my question is, has anyone ever encountered this problem before? Can anyone suggest a work around?&lt;/P&gt;

&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 11:26:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/How-do-I-prevent-Splunk-from-automatically-removing-spaces-from/m-p/256265#M3193</guid>
      <dc:creator>poneill1703</dc:creator>
      <dc:date>2020-09-29T11:26:25Z</dc:date>
    </item>
    <item>
      <title>Re: How do I prevent Splunk from automatically removing spaces from my search query?</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/How-do-I-prevent-Splunk-from-automatically-removing-spaces-from/m-p/256266#M3194</link>
      <description>&lt;P&gt;I've not seen this. What browser are you using? Does it happen if you use a different browser?&lt;/P&gt;</description>
      <pubDate>Mon, 17 Oct 2016 19:44:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/How-do-I-prevent-Splunk-from-automatically-removing-spaces-from/m-p/256266#M3194</guid>
      <dc:creator>lguinn2</dc:creator>
      <dc:date>2016-10-17T19:44:56Z</dc:date>
    </item>
    <item>
      <title>Re: How do I prevent Splunk from automatically removing spaces from my search query?</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/How-do-I-prevent-Splunk-from-automatically-removing-spaces-from/m-p/256267#M3195</link>
      <description>&lt;P&gt;I'm using Internet Explorer 11. I'm only permitted to use this browser on my work laptop, so I don't know if this happens on different browsers.&lt;/P&gt;</description>
      <pubDate>Tue, 18 Oct 2016 08:12:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/How-do-I-prevent-Splunk-from-automatically-removing-spaces-from/m-p/256267#M3195</guid>
      <dc:creator>poneill1703</dc:creator>
      <dc:date>2016-10-18T08:12:21Z</dc:date>
    </item>
    <item>
      <title>Re: How do I prevent Splunk from automatically removing spaces from my search query?</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/How-do-I-prevent-Splunk-from-automatically-removing-spaces-from/m-p/256268#M3196</link>
      <description>&lt;P&gt;Hi Poneill1703, &lt;/P&gt;

&lt;P&gt;I have tried creating a panel in a dashboard using a similar query don't see this happening. I'm using Chrome. Not sure if is caused by the IE browser you use. Could you please try in a different browser? &lt;/P&gt;

&lt;P&gt;Thanks! &lt;BR /&gt;
Hunter&lt;/P&gt;</description>
      <pubDate>Tue, 18 Oct 2016 09:11:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/How-do-I-prevent-Splunk-from-automatically-removing-spaces-from/m-p/256268#M3196</guid>
      <dc:creator>hunters_splunk</dc:creator>
      <dc:date>2016-10-18T09:11:49Z</dc:date>
    </item>
    <item>
      <title>Re: How do I prevent Splunk from automatically removing spaces from my search query?</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/How-do-I-prevent-Splunk-from-automatically-removing-spaces-from/m-p/256269#M3197</link>
      <description>&lt;P&gt;Hi Hunter,&lt;/P&gt;

&lt;P&gt;I'm only permitted to use IE on my work laptop.&lt;/P&gt;

&lt;P&gt;This problem is hit and miss for me. I've seen this occur before, but fortunately the issue didn't persist.&lt;/P&gt;

&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 18 Oct 2016 09:18:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/How-do-I-prevent-Splunk-from-automatically-removing-spaces-from/m-p/256269#M3197</guid>
      <dc:creator>poneill1703</dc:creator>
      <dc:date>2016-10-18T09:18:04Z</dc:date>
    </item>
    <item>
      <title>Re: How do I prevent Splunk from automatically removing spaces from my search query?</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/How-do-I-prevent-Splunk-from-automatically-removing-spaces-from/m-p/256270#M3198</link>
      <description>&lt;P&gt;What happens if you &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.5.0/Search/Addcommentstosearches"&gt;add a comment&lt;/A&gt; at the end of the search, or use a &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.5.0/SearchReference/Noop"&gt;noop command&lt;/A&gt;, so your search becomes&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=index Category="$Category_1$" | eval eval_1=substr(field_1,1,7) | top limit=$TopNo_1$ eval_1 | fields - percent `comment("comment text")`
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;or&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=index Category="$Category_1$" | eval eval_1=substr(field_1,1,7) | top limit=$TopNo_1$ eval_1 | fields - percent | noop
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Tue, 18 Oct 2016 09:54:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/How-do-I-prevent-Splunk-from-automatically-removing-spaces-from/m-p/256270#M3198</guid>
      <dc:creator>davebrooking</dc:creator>
      <dc:date>2016-10-18T09:54:38Z</dc:date>
    </item>
    <item>
      <title>Re: How do I prevent Splunk from automatically removing spaces from my search query?</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/How-do-I-prevent-Splunk-from-automatically-removing-spaces-from/m-p/256271#M3199</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I tried adding the noop command. Same thing, the spaces get removed. I apply the change to one of my panels, and it sticks. However, the other panel then breaks. And then vice versa if I apply the change to the second panel, the first panel breaks again because the spaces get removed.&lt;/P&gt;

&lt;P&gt;I tried adding the comment as suggested above, but the syntax does not work for me.&lt;/P&gt;

&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Tue, 18 Oct 2016 10:56:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/How-do-I-prevent-Splunk-from-automatically-removing-spaces-from/m-p/256271#M3199</guid>
      <dc:creator>poneill1703</dc:creator>
      <dc:date>2016-10-18T10:56:00Z</dc:date>
    </item>
    <item>
      <title>Re: How do I prevent Splunk from automatically removing spaces from my search query?</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/How-do-I-prevent-Splunk-from-automatically-removing-spaces-from/m-p/256272#M3200</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;

&lt;P&gt;It appears that the comment macro was shipped in Splunk 6.5. &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.4.0/Search/Addcommentstosearches"&gt;The documentation for 6.4 shows how to create the macro&lt;/A&gt;.&lt;/P&gt;

&lt;P&gt;However, I don't think this will solve your issue if the noop didn't work. It was a long shot and I thought the removal of the spaces may have been related to whether the fields command was the last portion of the search, and maybe adding 'extras' may have fooled the system into not removing the spaces.&lt;/P&gt;

&lt;P&gt;Dave&lt;/P&gt;</description>
      <pubDate>Tue, 18 Oct 2016 11:18:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/How-do-I-prevent-Splunk-from-automatically-removing-spaces-from/m-p/256272#M3200</guid>
      <dc:creator>davebrooking</dc:creator>
      <dc:date>2016-10-18T11:18:51Z</dc:date>
    </item>
    <item>
      <title>Re: How do I prevent Splunk from automatically removing spaces from my search query?</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/How-do-I-prevent-Splunk-from-automatically-removing-spaces-from/m-p/256273#M3201</link>
      <description>&lt;P&gt;Yeah, I had the same thinking and tried moving the fields parts to the middle of the query, but no dice.&lt;/P&gt;</description>
      <pubDate>Tue, 18 Oct 2016 12:48:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/How-do-I-prevent-Splunk-from-automatically-removing-spaces-from/m-p/256273#M3201</guid>
      <dc:creator>poneill1703</dc:creator>
      <dc:date>2016-10-18T12:48:54Z</dc:date>
    </item>
    <item>
      <title>Re: How do I prevent Splunk from automatically removing spaces from my search query?</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/How-do-I-prevent-Splunk-from-automatically-removing-spaces-from/m-p/256274#M3202</link>
      <description>&lt;P&gt;We are having the same issue.  We primarily use IE as well.  I will test in Firefox and Microsoft Edge.&lt;/P&gt;</description>
      <pubDate>Thu, 03 Nov 2016 19:07:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/How-do-I-prevent-Splunk-from-automatically-removing-spaces-from/m-p/256274#M3202</guid>
      <dc:creator>james_hopton</dc:creator>
      <dc:date>2016-11-03T19:07:19Z</dc:date>
    </item>
    <item>
      <title>Re: How do I prevent Splunk from automatically removing spaces from my search query?</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/How-do-I-prevent-Splunk-from-automatically-removing-spaces-from/m-p/256275#M3203</link>
      <description>&lt;P&gt;I've narrowed it down to IE.  With the following example it will do it every time.  Edit the dashboard and just change the last underscore in the title to a space or back.  Or change the drilldown from cell to row or back.  Save and refresh the page.  I tested with MS Edge and Firefox and neither had the problem.&lt;/P&gt;

&lt;P&gt;James_Test_dash_strip_test&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;&amp;lt;panel&amp;gt;
  &amp;lt;table&amp;gt;
    &amp;lt;title&amp;gt;Top Host,Index and Sourcetype Today&amp;lt;/title&amp;gt;
    &amp;lt;search&amp;gt;
      &amp;lt;query&amp;gt;index=_internal source="/opt/splunk/var/log/splunk/license_usage.log" type=Usage | stats sparkline(sum(b),1h) as Today, sum(b) as Bytes,latest(poolsz) as poolsz by h,idx,st | eval Gbytes=round(Bytes/1024/1024/1024,2) | eval lic=round(poolsz/1024/1024/1024,0) | eval Lic_Pct=round(Gbytes/lic*100,2) | sort -Gbytes | head 10 | fields - lic,poolsz,Bytes | rename idx AS index | rename h AS host | rename st AS sourcetype&amp;lt;/query&amp;gt;
      &amp;lt;earliest&amp;gt;@d&amp;lt;/earliest&amp;gt;
      &amp;lt;latest&amp;gt;now&amp;lt;/latest&amp;gt;
    &amp;lt;/search&amp;gt;
    &amp;lt;option name="drilldown"&amp;gt;row&amp;lt;/option&amp;gt;
    &amp;lt;option name="wrap"&amp;gt;false&amp;lt;/option&amp;gt;
  &amp;lt;/table&amp;gt;
&amp;lt;/panel&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Tue, 29 Sep 2020 11:40:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/How-do-I-prevent-Splunk-from-automatically-removing-spaces-from/m-p/256275#M3203</guid>
      <dc:creator>james_hopton</dc:creator>
      <dc:date>2020-09-29T11:40:46Z</dc:date>
    </item>
  </channel>
</rss>

