<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to get rid of warning sign &amp;quot;search is waiting for input ...&amp;quot; and display the data in dashboard panel? in Dashboards &amp; Visualizations</title>
    <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-get-rid-of-warning-sign-quot-search-is-waiting-for-input/m-p/172996#M10709</link>
    <description>&lt;P&gt;This happens when you have a token in your view which is not set, like having an input form with a token "host" (called $host$ in the xml code) and never set in your view&lt;BR /&gt;
Double check your code and token you are using in your input forms (pulldown, multiselect...)&lt;/P&gt;</description>
    <pubDate>Wed, 06 Aug 2014 11:43:51 GMT</pubDate>
    <dc:creator>guilmxm</dc:creator>
    <dc:date>2014-08-06T11:43:51Z</dc:date>
    <item>
      <title>How to get rid of warning sign "search is waiting for input ..." and display the data in dashboard panel?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-get-rid-of-warning-sign-quot-search-is-waiting-for-input/m-p/172995#M10708</link>
      <description>&lt;P&gt;I have created a dashboard panel of Active Directory that shows the successful logins of Non EU accounts for last 24 hours. It shows me the output when I create it but when I save it as a dash board panel it does not show any output. It shows the warning sign saying "search is waiting for input...". &lt;/P&gt;

&lt;P&gt;Any help regarding this would be much appreciated.&lt;/P&gt;

&lt;P&gt;thanks&lt;/P&gt;</description>
      <pubDate>Wed, 06 Aug 2014 11:05:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-get-rid-of-warning-sign-quot-search-is-waiting-for-input/m-p/172995#M10708</guid>
      <dc:creator>asharjaved</dc:creator>
      <dc:date>2014-08-06T11:05:14Z</dc:date>
    </item>
    <item>
      <title>Re: How to get rid of warning sign "search is waiting for input ..." and display the data in dashboard panel?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-get-rid-of-warning-sign-quot-search-is-waiting-for-input/m-p/172996#M10709</link>
      <description>&lt;P&gt;This happens when you have a token in your view which is not set, like having an input form with a token "host" (called $host$ in the xml code) and never set in your view&lt;BR /&gt;
Double check your code and token you are using in your input forms (pulldown, multiselect...)&lt;/P&gt;</description>
      <pubDate>Wed, 06 Aug 2014 11:43:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-get-rid-of-warning-sign-quot-search-is-waiting-for-input/m-p/172996#M10709</guid>
      <dc:creator>guilmxm</dc:creator>
      <dc:date>2014-08-06T11:43:51Z</dc:date>
    </item>
    <item>
      <title>Re: How to get rid of warning sign "search is waiting for input ..." and display the data in dashboard panel?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-get-rid-of-warning-sign-quot-search-is-waiting-for-input/m-p/172997#M10710</link>
      <description>&lt;P&gt;See:&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/6.1.3/Viz/PanelreferenceforSimplifiedXML"&gt;http://docs.splunk.com/Documentation/Splunk/6.1.3/Viz/PanelreferenceforSimplifiedXML&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 06 Aug 2014 12:16:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-get-rid-of-warning-sign-quot-search-is-waiting-for-input/m-p/172997#M10710</guid>
      <dc:creator>guilmxm</dc:creator>
      <dc:date>2014-08-06T12:16:26Z</dc:date>
    </item>
    <item>
      <title>Re: How to get rid of warning sign "search is waiting for input ..." and display the data in dashboard panel?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-get-rid-of-warning-sign-quot-search-is-waiting-for-input/m-p/172998#M10711</link>
      <description>&lt;P&gt;@guilmxm&lt;/P&gt;

&lt;P&gt;Just suspended and removed all posts by the user leetistur that you downvoted for their google answer &lt;span class="lia-unicode-emoji" title=":face_with_tongue:"&gt;😛&lt;/span&gt; They were a spammer&lt;/P&gt;</description>
      <pubDate>Wed, 06 Aug 2014 18:55:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-get-rid-of-warning-sign-quot-search-is-waiting-for-input/m-p/172998#M10711</guid>
      <dc:creator>ppablo</dc:creator>
      <dc:date>2014-08-06T18:55:42Z</dc:date>
    </item>
    <item>
      <title>Re: How to get rid of warning sign "search is waiting for input ..." and display the data in dashboard panel?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-get-rid-of-warning-sign-quot-search-is-waiting-for-input/m-p/172999#M10712</link>
      <description>&lt;P&gt;@ppapblo&lt;/P&gt;

&lt;P&gt;I see, i didn't realized &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; tks!&lt;/P&gt;</description>
      <pubDate>Wed, 06 Aug 2014 19:44:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-get-rid-of-warning-sign-quot-search-is-waiting-for-input/m-p/172999#M10712</guid>
      <dc:creator>guilmxm</dc:creator>
      <dc:date>2014-08-06T19:44:27Z</dc:date>
    </item>
    <item>
      <title>Re: How to get rid of warning sign "search is waiting for input ..." and display the data in dashboard panel?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-get-rid-of-warning-sign-quot-search-is-waiting-for-input/m-p/173000#M10713</link>
      <description>&lt;P&gt;Hi, It is still not working. Actually I have 4 dashboard panels of Active Directory but only two are showing information. And two are waiting for input. The source code of form view is given below:&lt;/P&gt;

&lt;P&gt;AD Auth Report&lt;BR /&gt;
  Passed Logins&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;&amp;lt;input type="multiselect" searchWhenChanged="true" token="mv5"&amp;gt;
  &amp;lt;default&amp;gt;[object Object]&amp;lt;/default&amp;gt;
&amp;lt;/input&amp;gt;


&amp;lt;panel&amp;gt;
  &amp;lt;table&amp;gt;
    &amp;lt;title&amp;gt;Passed Logins&amp;lt;/title&amp;gt;
    &amp;lt;searchString&amp;gt;index = windows  NOT Account_Name="*$" Account_Domain != - AND Account_Domain != EU  EventCode=4634 | stats count by Account_Domain , Account_Name&amp;lt;/searchString&amp;gt;
  &amp;lt;/table&amp;gt;
&amp;lt;/panel&amp;gt;


&amp;lt;panel&amp;gt;
  &amp;lt;event&amp;gt;
    &amp;lt;title&amp;gt;Passed Non EU Account&amp;lt;/title&amp;gt;
    &amp;lt;searchString&amp;gt;index=windows EventCode=4624   | mvexpand Account_Name   | mvexpand Account_Domain   | search Account_Name!="*$" NOT Account_Name = "#*" Account_Domain != EU Account_Domain != NT* NOT Account_Name = "*$" Account_Name !="-"  Account_Domain !="-" | stats count by Account_Name , Account_Domain&amp;lt;/searchString&amp;gt;
    &amp;lt;earliestTime&amp;gt;-24h@h&amp;lt;/earliestTime&amp;gt;
    &amp;lt;latestTime&amp;gt;now&amp;lt;/latestTime&amp;gt;
    &amp;lt;option name="wrap"&amp;gt;true&amp;lt;/option&amp;gt;
    &amp;lt;option name="rowNumbers"&amp;gt;0&amp;lt;/option&amp;gt;
    &amp;lt;option name="dataOverlayMode"&amp;gt;none&amp;lt;/option&amp;gt;
    &amp;lt;option name="list.drilldown"&amp;gt;full&amp;lt;/option&amp;gt;
    &amp;lt;option name="list.wrap"&amp;gt;1&amp;lt;/option&amp;gt;
    &amp;lt;option name="maxLines"&amp;gt;5&amp;lt;/option&amp;gt;
    &amp;lt;option name="raw.drilldown"&amp;gt;full&amp;lt;/option&amp;gt;
    &amp;lt;option name="table.drilldown"&amp;gt;all&amp;lt;/option&amp;gt;
    &amp;lt;option name="table.wrap"&amp;gt;1&amp;lt;/option&amp;gt;
    &amp;lt;option name="type"&amp;gt;list&amp;lt;/option&amp;gt;
    &amp;lt;option name="count"&amp;gt;10&amp;lt;/option&amp;gt;
    &amp;lt;fields&amp;gt;["host","source","sourcetype"]&amp;lt;/fields&amp;gt;        
  &amp;lt;/event&amp;gt;
&amp;lt;/panel&amp;gt;


&amp;lt;panel&amp;gt;
  &amp;lt;table&amp;gt;
    &amp;lt;title&amp;gt;Failed User Logon in last 24 Hrs&amp;lt;/title&amp;gt;
    &amp;lt;searchString&amp;gt;index=windows  EventCode=4625    | rex "(?ms)Failure Information.+?Failure Reason:\s+(?&amp;amp;lt;failure_information&amp;amp;gt;\V+)" | stats count by ComputerName , Workstation_Name, user , Source_Network_Address, failure_information, signature | sort -count&amp;lt;/searchString&amp;gt;
    &amp;lt;earliestTime&amp;gt;-24h@h&amp;lt;/earliestTime&amp;gt;
    &amp;lt;latestTime&amp;gt;now&amp;lt;/latestTime&amp;gt;
  &amp;lt;/table&amp;gt;
&amp;lt;/panel&amp;gt;


&amp;lt;panel&amp;gt;
  &amp;lt;event&amp;gt;
    &amp;lt;title&amp;gt;Passed Non EU Accounts&amp;lt;/title&amp;gt;
    &amp;lt;searchName&amp;gt;Passed Non EU Accounts&amp;lt;/searchName&amp;gt;
     &amp;lt;searchString&amp;gt;index=windows EventCode=4624   | mvexpand Account_Name   | mvexpand Account_Domain   | search Account_Name!="*$" NOT Account_Name = "#*" Account_Domain != EU Account_Domain != NT* NOT Account_Name = "*$" Account_Name !="-"  Account_Domain !="-" | stats count by Account_Name , Account_Domain&amp;lt;/searchString&amp;gt;
     &amp;lt;option name="list.drilldown"&amp;gt;full&amp;lt;/option&amp;gt;
    &amp;lt;option name="list.wrap"&amp;gt;1&amp;lt;/option&amp;gt;
    &amp;lt;option name="maxLines"&amp;gt;5&amp;lt;/option&amp;gt;
    &amp;lt;option name="raw.drilldown"&amp;gt;full&amp;lt;/option&amp;gt;
    &amp;lt;option name="rowNumbers"&amp;gt;0&amp;lt;/option&amp;gt;
    &amp;lt;option name="table.drilldown"&amp;gt;all&amp;lt;/option&amp;gt;
    &amp;lt;option name="table.wrap"&amp;gt;1&amp;lt;/option&amp;gt;
    &amp;lt;option name="type"&amp;gt;list&amp;lt;/option&amp;gt;
    &amp;lt;option name="count"&amp;gt;10&amp;lt;/option&amp;gt;
    &amp;lt;fields&amp;gt;["host","source","sourcetype"]&amp;lt;/fields&amp;gt;
  &amp;lt;/event&amp;gt;
&amp;lt;/panel&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Wed, 17 Sep 2014 11:02:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-get-rid-of-warning-sign-quot-search-is-waiting-for-input/m-p/173000#M10713</guid>
      <dc:creator>ashari</dc:creator>
      <dc:date>2014-09-17T11:02:17Z</dc:date>
    </item>
    <item>
      <title>Re: How to get rid of warning sign "search is waiting for input ..." and display the data in dashboard panel?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-get-rid-of-warning-sign-quot-search-is-waiting-for-input/m-p/173001#M10714</link>
      <description>&lt;P&gt;Was there a solution to this question?&lt;BR /&gt;&lt;BR /&gt;
I too am having this issue.  I can run the search in a search window, however if I add the same search as a panel in a dashboard (new or existing) I get the "search is waiting for input" message.&lt;/P&gt;

&lt;P&gt;My search is:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;    index="genband-cdr" AM00SBC07 OR AM00SBC08 | fillnull value="sucessful" S3_call_error2 | top S3_call_error2 useother=f | where percent &amp;gt;3| map search="search S3_call_error2=$S3_call_error2$ | top S3_call_error2 by S3_call_dest_custid |sort 3 -count |rename S3_call_dest_custid AS PTSID S3_call_error2 AS Error| table PTSID, Error"
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Tue, 30 Dec 2014 14:55:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-get-rid-of-warning-sign-quot-search-is-waiting-for-input/m-p/173001#M10714</guid>
      <dc:creator>lennys26</dc:creator>
      <dc:date>2014-12-30T14:55:25Z</dc:date>
    </item>
    <item>
      <title>Re: How to get rid of warning sign "search is waiting for input ..." and display the data in dashboard panel?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-get-rid-of-warning-sign-quot-search-is-waiting-for-input/m-p/173002#M10715</link>
      <description>&lt;P&gt;Like the first answer suggests, it might be an issue with the XML seeing an unset token; looks like the source is your search string. I'm not sure if that is an expected result of including $ in your searches, or if it's a bug, so hopefully someone else can clarify. You &lt;EM&gt;should&lt;/EM&gt; be able to work around it by changing your search string to have double $'s. It won't work in the search, but it will work in the dashboard. IE:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;&amp;lt;searchString&amp;gt;index = windows  NOT Account_Name="*$$" Account_Domain != - AND Account_Domain != EU  EventCode=4634 | stats count by Account_Domain , Account_Name&amp;lt;/searchString&amp;gt;

&amp;lt;searchString&amp;gt;index=windows EventCode=4624   | mvexpand Account_Name   | mvexpand Account_Domain   | search Account_Name!="*$$" NOT Account_Name = "#*" Account_Domain != EU Account_Domain != NT* NOT Account_Name = "*$$" Account_Name !="-"  Account_Domain !="-" | stats count by Account_Name , Account_Domain&amp;lt;/searchString&amp;gt;

&amp;lt;searchString&amp;gt;index=windows EventCode=4624   | mvexpand Account_Name   | mvexpand Account_Domain   | search Account_Name!="*$$" NOT Account_Name = "#*" Account_Domain != EU Account_Domain != NT* NOT Account_Name = "*$$" Account_Name !="-"  Account_Domain !="-" | stats count by Account_Name , Account_Domain&amp;lt;/searchString&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Tue, 13 Jan 2015 20:58:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-get-rid-of-warning-sign-quot-search-is-waiting-for-input/m-p/173002#M10715</guid>
      <dc:creator>bwheelock</dc:creator>
      <dc:date>2015-01-13T20:58:29Z</dc:date>
    </item>
    <item>
      <title>Re: How to get rid of warning sign "search is waiting for input ..." and display the data in dashboard panel?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-get-rid-of-warning-sign-quot-search-is-waiting-for-input/m-p/173003#M10716</link>
      <description>&lt;P&gt;In both cases ,it looks like there are dollar signs ($) in the search string.  You need to escape them with a second one ($$) in order to avoid the message.  otherwise Splunk thinks everything after the $ is a variable (that hasn't been populated)&lt;/P&gt;</description>
      <pubDate>Fri, 01 May 2015 22:36:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-get-rid-of-warning-sign-quot-search-is-waiting-for-input/m-p/173003#M10716</guid>
      <dc:creator>alaorath</dc:creator>
      <dc:date>2015-05-01T22:36:18Z</dc:date>
    </item>
    <item>
      <title>Re: How to get rid of warning sign "search is waiting for input ..." and display the data in dashboard panel?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-get-rid-of-warning-sign-quot-search-is-waiting-for-input/m-p/173004#M10717</link>
      <description>&lt;P&gt;Don't use '&amp;amp;' in the search but use instead the escaped characters: &lt;/P&gt;

&lt;P&gt;&lt;A href="http://stackoverflow.com/questions/1091945/what-characters-do-i-need-to-escape-in-xml-documents"&gt;http://stackoverflow.com/questions/1091945/what-characters-do-i-need-to-escape-in-xml-documents&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 15 Jun 2016 22:03:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-get-rid-of-warning-sign-quot-search-is-waiting-for-input/m-p/173004#M10717</guid>
      <dc:creator>daniel_augustyn</dc:creator>
      <dc:date>2016-06-15T22:03:47Z</dc:date>
    </item>
    <item>
      <title>Re: How to get rid of warning sign "search is waiting for input ..." and display the data in dashboard panel?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-get-rid-of-warning-sign-quot-search-is-waiting-for-input/m-p/173005#M10718</link>
      <description>&lt;P&gt;No need to point to other sites &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt; you can use this answer&lt;/P&gt;

&lt;P&gt;&lt;A href="https://answers.splunk.com/answers/3435/escape-and-in-the-xml-of-dashboards.html"&gt;https://answers.splunk.com/answers/3435/escape-and-in-the-xml-of-dashboards.html&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;or the docs &lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/6.4.1/Viz/OverviewofSimplifiedXML#Special_characters_in_XML_files"&gt;http://docs.splunk.com/Documentation/Splunk/6.4.1/Viz/OverviewofSimplifiedXML#Special_characters_in_XML_files&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 15 Jun 2016 22:22:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-get-rid-of-warning-sign-quot-search-is-waiting-for-input/m-p/173005#M10718</guid>
      <dc:creator>MuS</dc:creator>
      <dc:date>2016-06-15T22:22:48Z</dc:date>
    </item>
    <item>
      <title>Re: How to get rid of warning sign "search is waiting for input ..." and display the data in dashboard panel?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-get-rid-of-warning-sign-quot-search-is-waiting-for-input/m-p/173006#M10719</link>
      <description>&lt;P&gt;I just ran into this issue with a new dashboard and eventually pinned it down to the fact that the token i had set in  my dropdown was not being populated into the request query string, so the search couldn't find it.&lt;/P&gt;

&lt;P&gt;The solution was to refresh the dashboard.&lt;/P&gt;</description>
      <pubDate>Thu, 10 Jan 2019 19:36:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-get-rid-of-warning-sign-quot-search-is-waiting-for-input/m-p/173006#M10719</guid>
      <dc:creator>declanshanaghy</dc:creator>
      <dc:date>2019-01-10T19:36:20Z</dc:date>
    </item>
    <item>
      <title>Re: How to get rid of warning sign "search is waiting for input ..." and display the data in dashboard panel?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-get-rid-of-warning-sign-quot-search-is-waiting-for-input/m-p/173007#M10720</link>
      <description>&lt;P&gt;"I'm not sure if that is an expected result of including $ in your searches" the case is to pass variable in a new search&lt;BR /&gt;
    | map search="search  $uid$" | ...&lt;/P&gt;</description>
      <pubDate>Thu, 15 Aug 2019 13:57:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-get-rid-of-warning-sign-quot-search-is-waiting-for-input/m-p/173007#M10720</guid>
      <dc:creator>yuraminsk</dc:creator>
      <dc:date>2019-08-15T13:57:44Z</dc:date>
    </item>
  </channel>
</rss>

