<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Clustermaps not loading properly using a base search in Dashboards &amp; Visualizations</title>
    <link>https://community.splunk.com/t5/Dashboards-Visualizations/Clustermaps-not-loading-properly-using-a-base-search/m-p/546091#M37511</link>
    <description>&lt;P&gt;This will be no help to you unfortunately, but I have seen similar behaviour I believe on a Splunk 7.X environment, but never found the cause. What version are you on?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 30 Mar 2021 21:41:14 GMT</pubDate>
    <dc:creator>bowesmana</dc:creator>
    <dc:date>2021-03-30T21:41:14Z</dc:date>
    <item>
      <title>Clustermaps not loading properly using a base search</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Clustermaps-not-loading-properly-using-a-base-search/m-p/546010#M37504</link>
      <description>&lt;P&gt;In a dashboard, a single panel using a lookup and geostats works fine.&amp;nbsp; When I take that search and split it up to use a base search with multiple panels it semi-breaks.&amp;nbsp; The Cluster map will start loading but the pie charts appear then disappear.&amp;nbsp; The other panels on the dashboard are pie charts and they all load appropriately. Once the search completes however, if you click refresh the cluster map results will display properly.&amp;nbsp; Is this a problem with my source, the SPL, or something else (bug)? Source below is just the Panel for the Cluster map I am having problems with.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;lt;form&amp;gt;&lt;BR /&gt;&amp;lt;label&amp;gt;Firewall Clustermap&amp;lt;/label&amp;gt;&lt;BR /&gt;&amp;lt;description&amp;gt;Inbound Traffic&amp;lt;/description&amp;gt;&lt;BR /&gt;&amp;lt;search id="Global_Traffic"&amp;gt;&lt;BR /&gt;&amp;lt;query&amp;gt;index=xyz_firewall sourcetype=xyz_log policy_name="XYZ" direction=inbound |fields Country,src_ip,vendor_action,dest_ip,dest_port, src_port&lt;BR /&gt;|iplocation src_ip |search Country=* [|inputlookup XYZ_Country_Block_List]&lt;BR /&gt;&amp;lt;/query&amp;gt;&lt;BR /&gt;&amp;lt;earliest&amp;gt;$field1.earliest$&amp;lt;/earliest&amp;gt;&lt;BR /&gt;&amp;lt;latest&amp;gt;$field1.latest$&amp;lt;/latest&amp;gt;&lt;BR /&gt;&amp;lt;/search&amp;gt;&lt;BR /&gt;&amp;lt;fieldset submitButton="true"&amp;gt;&lt;BR /&gt;&amp;lt;input type="time" token="field1"&amp;gt;&lt;BR /&gt;&amp;lt;label&amp;gt;Choose Time then Click Submit&amp;lt;/label&amp;gt;&lt;BR /&gt;&amp;lt;default&amp;gt;&lt;BR /&gt;&amp;lt;earliest&amp;gt;-1m&amp;lt;/earliest&amp;gt;&lt;BR /&gt;&amp;lt;latest&amp;gt;now&amp;lt;/latest&amp;gt;&lt;BR /&gt;&amp;lt;/default&amp;gt;&lt;BR /&gt;&amp;lt;/input&amp;gt;&lt;BR /&gt;&amp;lt;/fieldset&amp;gt;&lt;BR /&gt;&amp;lt;row&amp;gt;&lt;BR /&gt;&amp;lt;panel&amp;gt;&lt;BR /&gt;&amp;lt;title&amp;gt;GLOBAL DROPS&amp;lt;/title&amp;gt;&lt;BR /&gt;&amp;lt;map&amp;gt;&lt;BR /&gt;&amp;lt;title&amp;gt;ACTION: Drop&amp;lt;/title&amp;gt;&lt;BR /&gt;&amp;lt;search base="Global_Traffic"&amp;gt;&lt;BR /&gt;&amp;lt;query&amp;gt;|Search vendor_action IN (Drop, Deny, Block, Reject) |geostats count by Country globallimit=0&amp;lt;/query&amp;gt;&lt;BR /&gt;&amp;lt;/search&amp;gt;&lt;BR /&gt;&amp;lt;option name="mapping.type"&amp;gt;marker&amp;lt;/option&amp;gt;&lt;BR /&gt;&amp;lt;option name="refresh.display"&amp;gt;progressbar&amp;lt;/option&amp;gt;&lt;BR /&gt;&amp;lt;/map&amp;gt;&lt;BR /&gt;&amp;lt;/panel&amp;gt;&lt;/P&gt;</description>
      <pubDate>Tue, 30 Mar 2021 13:45:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Clustermaps-not-loading-properly-using-a-base-search/m-p/546010#M37504</guid>
      <dc:creator>HaxUez</dc:creator>
      <dc:date>2021-03-30T13:45:02Z</dc:date>
    </item>
    <item>
      <title>Re: Clustermaps not loading properly using a base search</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Clustermaps-not-loading-properly-using-a-base-search/m-p/546018#M37505</link>
      <description>&lt;P&gt;Before refresh and After refresh screenshots of Cluster maps&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="After Refresh" style="width: 892px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/13544iD3B89171F724DE50/image-size/large?v=v2&amp;amp;px=999" role="button" title="Clustermap_after_refresh.PNG" alt="After Refresh" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;After Refresh&lt;/span&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Before Refresh" style="width: 896px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/13545iF209754A6CBD47DF/image-size/large?v=v2&amp;amp;px=999" role="button" title="Clustermap_Before_refresh.PNG" alt="Before Refresh" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;Before Refresh&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 30 Mar 2021 14:12:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Clustermaps-not-loading-properly-using-a-base-search/m-p/546018#M37505</guid>
      <dc:creator>HaxUez</dc:creator>
      <dc:date>2021-03-30T14:12:56Z</dc:date>
    </item>
    <item>
      <title>Re: Clustermaps not loading properly using a base search</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Clustermaps-not-loading-properly-using-a-base-search/m-p/546091#M37511</link>
      <description>&lt;P&gt;This will be no help to you unfortunately, but I have seen similar behaviour I believe on a Splunk 7.X environment, but never found the cause. What version are you on?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 30 Mar 2021 21:41:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Clustermaps-not-loading-properly-using-a-base-search/m-p/546091#M37511</guid>
      <dc:creator>bowesmana</dc:creator>
      <dc:date>2021-03-30T21:41:14Z</dc:date>
    </item>
    <item>
      <title>Re: Clustermaps not loading properly using a base search</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Clustermaps-not-loading-properly-using-a-base-search/m-p/546232#M37528</link>
      <description>&lt;P&gt;Version 8.1.2&lt;/P&gt;</description>
      <pubDate>Wed, 31 Mar 2021 14:42:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Clustermaps-not-loading-properly-using-a-base-search/m-p/546232#M37528</guid>
      <dc:creator>HaxUez</dc:creator>
      <dc:date>2021-03-31T14:42:23Z</dc:date>
    </item>
    <item>
      <title>Re: Clustermaps not loading properly using a base search</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Clustermaps-not-loading-properly-using-a-base-search/m-p/667614#M54610</link>
      <description>&lt;P&gt;Hello All&amp;nbsp;&lt;/P&gt;&lt;P&gt;I had exactly the same Issue and this only happens when u use the base search directly to get the cluster map populated. I solved the issue and maybe is a silly way to do it but it was the only way to make it workg for me.&lt;BR /&gt;&lt;BR /&gt;In your cluster map&amp;nbsp; edit search --&amp;gt; search string text box do something like this&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;mainQuery&lt;/STRONG&gt;: it is your base search, in my case is a Macro used in differnt dashboads&lt;BR /&gt;###################&amp;nbsp; Code ###############################&lt;/P&gt;&lt;P&gt;| &lt;STRONG&gt;fields &lt;FONT color="#008000"&gt;1&amp;nbsp;&lt;/FONT&gt;&lt;/STRONG&gt; &amp;nbsp;``` there is no fields called 1 - the idea is to get an empty result from the base search ```&lt;BR /&gt;```&amp;nbsp; The idea about the code below is to use the query mainQuery and get the fields to pass them to geostats ```&lt;/P&gt;&lt;P&gt;| &lt;STRONG&gt;append&lt;/STRONG&gt;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;[&amp;nbsp; &lt;STRONG&gt;search&lt;/STRONG&gt; `&lt;STRONG&gt;&lt;FONT color="#008000"&gt;mainQuery&lt;/FONT&gt;&lt;/STRONG&gt;`&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; | &lt;STRONG&gt;fields &lt;FONT color="#008000"&gt;lat lon country sales&lt;/FONT&gt;&lt;/STRONG&gt;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;]&lt;BR /&gt;| &lt;STRONG&gt;geostats&lt;/STRONG&gt;&lt;FONT color="#008000"&gt; latfield=lat longfield=lon count(sales) by country globallimit=0 locallimit=0&lt;/FONT&gt;&lt;BR /&gt;&lt;BR /&gt;###################&amp;nbsp; end of Code ###############################&lt;/P&gt;</description>
      <pubDate>Mon, 06 Nov 2023 20:10:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Clustermaps-not-loading-properly-using-a-base-search/m-p/667614#M54610</guid>
      <dc:creator>victorsalazar</dc:creator>
      <dc:date>2023-11-06T20:10:28Z</dc:date>
    </item>
  </channel>
</rss>

