<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Server Error in Dashboards &amp; Visualizations</title>
    <link>https://community.splunk.com/t5/Dashboards-Visualizations/Why-am-I-getting-this-Server-Error/m-p/599914#M49232</link>
    <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;I input the code into w3Schools HTML formatter and it shows a fully functioning Splunk dashboard, but when I input into an XML formatter it comes up with the same error in Line 66. "Unenclosed Root Tag" any advice on what may be causing Splunk to not read &amp;lt;/form&amp;gt;&lt;/P&gt;</description>
    <pubDate>Tue, 31 May 2022 14:03:12 GMT</pubDate>
    <dc:creator>Robert11</dc:creator>
    <dc:date>2022-05-31T14:03:12Z</dc:date>
    <item>
      <title>Why am I getting this Server Error?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Why-am-I-getting-this-Server-Error/m-p/599881#M49221</link>
      <description>&lt;P&gt;I tried to create a dashboard within the Search Function. "Splunk dashboard that displays user searches"&lt;/P&gt;
&lt;P&gt;This is on Splunk Enterprise. Currently I am getting ("Server Error") Below is the entered command:&lt;/P&gt;
&lt;P&gt;&amp;lt;form theme="dark"&amp;gt;&lt;BR /&gt;&amp;lt;label&amp;gt;Splunk Search Activity&amp;lt;/label&amp;gt;&lt;BR /&gt;&amp;lt;fieldset submitButton="true" autoRun="false"&amp;gt;&lt;BR /&gt;&amp;lt;input type="time" token="time1"&amp;gt;&lt;BR /&gt;&amp;lt;label&amp;gt;&amp;lt;/label&amp;gt;&lt;BR /&gt;&amp;lt;default&amp;gt;&lt;BR /&gt;&amp;lt;earliest&amp;gt;-24h@h&amp;lt;/earliest&amp;gt;&lt;BR /&gt;&amp;lt;latest&amp;gt;now&amp;lt;/latest&amp;gt;&lt;BR /&gt;&amp;lt;/default&amp;gt;&lt;BR /&gt;&amp;lt;/input&amp;gt;&lt;BR /&gt;&amp;lt;input type="radio" token="exclude1" searchWhenChanged="true"&amp;gt;&lt;BR /&gt;&amp;lt;label&amp;gt;Splunk System User&amp;lt;/label&amp;gt;&lt;BR /&gt;&amp;lt;choice value="user!=splunk-system-user"&amp;gt;exclude&amp;lt;/choice&amp;gt;&lt;BR /&gt;&amp;lt;choice value="*"&amp;gt;include&amp;lt;/choice&amp;gt;&lt;BR /&gt;&amp;lt;default&amp;gt;user!=splunk-system-user&amp;lt;/default&amp;gt;&lt;BR /&gt;&amp;lt;initialValue&amp;gt;user!=splunk-system-user&amp;lt;/initialValue&amp;gt;&lt;BR /&gt;&amp;lt;/input&amp;gt;&lt;BR /&gt;&amp;lt;input type="multiselect" token="user1"&amp;gt;&lt;BR /&gt;&amp;lt;label&amp;gt;User:&amp;lt;/label&amp;gt;&lt;BR /&gt;&amp;lt;fieldForLabel&amp;gt;user1&amp;lt;/fieldForLabel&amp;gt;&lt;BR /&gt;&amp;lt;fieldForValue&amp;gt;user&amp;lt;/fieldForValue&amp;gt;&lt;BR /&gt;&amp;lt;search&amp;gt;&lt;BR /&gt;&amp;lt;query&amp;gt;index=_audit action=search&lt;BR /&gt;search!="'typeahead*" $exclude1$ | stats count by user&amp;lt;/query&amp;gt;&lt;BR /&gt;&amp;lt;earliest&amp;gt;$time1.earliest$&amp;lt;/earliest&amp;gt;&lt;BR /&gt;&amp;lt;latest&amp;gt;$time1.latest$&amp;lt;/latest&amp;gt;&lt;BR /&gt;&amp;lt;/search&amp;gt;&lt;BR /&gt;&amp;lt;choice value="*"&amp;gt;all&amp;lt;/choice&amp;gt;&lt;BR /&gt;&amp;lt;default&amp;gt;*&amp;lt;/default&amp;gt;&lt;BR /&gt;&amp;lt;initialValue&amp;gt;*&amp;lt;/initialValue&amp;gt;&lt;BR /&gt;&amp;lt;delimiter&amp;gt; &amp;lt;/delimiter&amp;gt;&lt;BR /&gt;&amp;lt;/input&amp;gt;&lt;BR /&gt;&amp;lt;input type="text" token="filter1"&amp;gt;&lt;BR /&gt;&amp;lt;label&amp;gt;Search Filter:&amp;lt;/label&amp;gt;&lt;BR /&gt;&amp;lt;default&amp;gt;*&amp;lt;/default&amp;gt;&lt;BR /&gt;&amp;lt;initialValue&amp;gt;*&amp;lt;/initialValue&amp;gt;&lt;BR /&gt;&amp;lt;prefix&amp;gt;"*&amp;lt;/prefix&amp;gt;&lt;BR /&gt;&amp;lt;suffix&amp;gt;*"&amp;lt;/suffix&amp;gt;&lt;BR /&gt;&amp;lt;/input&amp;gt;&lt;BR /&gt;&amp;lt;/fieldset&amp;gt;&lt;BR /&gt;&amp;lt;row&amp;gt;&lt;BR /&gt;&amp;lt;panel&amp;gt;&lt;BR /&gt;&amp;lt;table&amp;gt;&lt;BR /&gt;&amp;lt;search&amp;gt;&lt;BR /&gt;&amp;lt;query&amp;gt;index=_audit action=search search!="'typeahead*" user="$user1$" search=$filter1$ $exclude1$&lt;BR /&gt;| stats count by _time user search total_run_time search_id app event_count&lt;BR /&gt;| sort -_time&amp;lt;/query&amp;gt;&lt;BR /&gt;&amp;lt;earliest&amp;gt;$time1.earliest$&amp;lt;/earliest&amp;gt;&lt;BR /&gt;&amp;lt;latest&amp;gt;$time1.latest$&amp;lt;/latest&amp;gt;&lt;BR /&gt;&amp;lt;sampleRatio&amp;gt;1&amp;lt;/sampleRatio&amp;gt;&lt;BR /&gt;&amp;lt;/search&amp;gt;&lt;BR /&gt;&amp;lt;option name="count"&amp;gt;20&amp;lt;/option&amp;gt;&lt;BR /&gt;&amp;lt;option name="dataOverlayMode"&amp;gt;none&amp;lt;/option&amp;gt;&lt;BR /&gt;&amp;lt;option name="drilldown"&amp;gt;none&amp;lt;/option&amp;gt;&lt;BR /&gt;&amp;lt;option name="percentagesRow"&amp;gt;false&amp;lt;/option&amp;gt;&lt;BR /&gt;&amp;lt;option name="refresh.display"&amp;gt;progressbar&amp;lt;/option&amp;gt;&lt;BR /&gt;&amp;lt;option name="rowNumbers"&amp;gt;false&amp;lt;/option&amp;gt;&lt;BR /&gt;&amp;lt;option name="totalsRow"&amp;gt;false&amp;lt;/option&amp;gt;&lt;BR /&gt;&amp;lt;option name="wrap"&amp;gt;true&amp;lt;/option&amp;gt;&lt;BR /&gt;&amp;lt;/table&amp;gt;&lt;BR /&gt;&amp;lt;/panel&amp;gt;&lt;BR /&gt;&amp;lt;/row&amp;gt;&lt;BR /&gt;&amp;lt;/form&amp;gt;&lt;/P&gt;</description>
      <pubDate>Tue, 31 May 2022 14:13:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Why-am-I-getting-this-Server-Error/m-p/599881#M49221</guid>
      <dc:creator>Robert11</dc:creator>
      <dc:date>2022-05-31T14:13:28Z</dc:date>
    </item>
    <item>
      <title>Re: Server Error</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Why-am-I-getting-this-Server-Error/m-p/599885#M49222</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/246336"&gt;@Robert11&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;at first, in general, never create new dashboards in Search App because then you have to move the dashboard and all knowledge objects in anothe app, it's better to create a new app and develop the new dashboard in this new app.&lt;/P&gt;&lt;P&gt;Then, did you explored the Monitor Console?&lt;/P&gt;&lt;P&gt;Maybe the dashboard you need is already present.&lt;/P&gt;&lt;P&gt;Anyway "Server error" isn't an erro related to the search, do other searches run in your Splunk?&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Tue, 31 May 2022 12:45:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Why-am-I-getting-this-Server-Error/m-p/599885#M49222</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-05-31T12:45:46Z</dc:date>
    </item>
    <item>
      <title>Re: Server Error</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Why-am-I-getting-this-Server-Error/m-p/599905#M49229</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;I went to create dashboard app and when I input the above code it now kicks back "Error on Line 66:Unclosed root tag" The error is coming from &amp;lt;/form&amp;gt; at the very bottom.&lt;/P&gt;&lt;P&gt;Below Code:&lt;/P&gt;&lt;P&gt;&amp;lt;dashboard&amp;gt;&lt;BR /&gt;&amp;lt;label&amp;gt;User Searches&amp;lt;/label&amp;gt;&lt;BR /&gt;&amp;lt;description&amp;gt;Displays Splunk User Searches&amp;lt;/description&amp;gt;&lt;BR /&gt;&amp;lt;form theme="dark"&amp;gt;&lt;BR /&gt;&amp;lt;label&amp;gt;Splunk Search Activity&amp;lt;/label&amp;gt;&lt;BR /&gt;&amp;lt;fieldset submitButton="true" autoRun="false"&amp;gt;&lt;BR /&gt;&amp;lt;input type="time" token="time1"&amp;gt;&lt;BR /&gt;&amp;lt;label&amp;gt;&amp;lt;/label&amp;gt;&lt;BR /&gt;&amp;lt;default&amp;gt;&lt;BR /&gt;&amp;lt;earliest&amp;gt;-24h@h&amp;lt;/earliest&amp;gt;&lt;BR /&gt;&amp;lt;latest&amp;gt;now&amp;lt;/latest&amp;gt;&lt;BR /&gt;&amp;lt;/default&amp;gt;&lt;BR /&gt;&amp;lt;/input&amp;gt;&lt;BR /&gt;&amp;lt;input type="radio" token="exclude1" searchWhenChanged="true"&amp;gt;&lt;BR /&gt;&amp;lt;label&amp;gt;Splunk System User&amp;lt;/label&amp;gt;&lt;BR /&gt;&amp;lt;choice value="user!=splunk-system-user"&amp;gt;exclude&amp;lt;/choice&amp;gt;&lt;BR /&gt;&amp;lt;choice value="*"&amp;gt;include&amp;lt;/choice&amp;gt;&lt;BR /&gt;&amp;lt;default&amp;gt;user!=splunk-system-user&amp;lt;/default&amp;gt;&lt;BR /&gt;&amp;lt;initialValue&amp;gt;user!=splunk-system-user&amp;lt;/initialValue&amp;gt;&lt;BR /&gt;&amp;lt;/input&amp;gt;&lt;BR /&gt;&amp;lt;input type="multiselect" token="user1"&amp;gt;&lt;BR /&gt;&amp;lt;label&amp;gt;User:&amp;lt;/label&amp;gt;&lt;BR /&gt;&amp;lt;fieldForLabel&amp;gt;user1&amp;lt;/fieldForLabel&amp;gt;&lt;BR /&gt;&amp;lt;fieldForValue&amp;gt;user&amp;lt;/fieldForValue&amp;gt;&lt;BR /&gt;&amp;lt;search&amp;gt;&lt;BR /&gt;&amp;lt;query&amp;gt;index=_audit action=search&lt;BR /&gt;search!="'typeahead*" $exclude1$ | stats count by user&amp;lt;/query&amp;gt;&lt;BR /&gt;&amp;lt;earliest&amp;gt;$time1.earliest$&amp;lt;/earliest&amp;gt;&lt;BR /&gt;&amp;lt;latest&amp;gt;$time1.latest$&amp;lt;/latest&amp;gt;&lt;BR /&gt;&amp;lt;/search&amp;gt;&lt;BR /&gt;&amp;lt;choice value="*"&amp;gt;all&amp;lt;/choice&amp;gt;&lt;BR /&gt;&amp;lt;default&amp;gt;*&amp;lt;/default&amp;gt;&lt;BR /&gt;&amp;lt;initialValue&amp;gt;*&amp;lt;/initialValue&amp;gt;&lt;BR /&gt;&amp;lt;delimiter&amp;gt; &amp;lt;/delimiter&amp;gt;&lt;BR /&gt;&amp;lt;/input&amp;gt;&lt;BR /&gt;&amp;lt;input type="text" token="filter1"&amp;gt;&lt;BR /&gt;&amp;lt;label&amp;gt;Search Filter:&amp;lt;/label&amp;gt;&lt;BR /&gt;&amp;lt;default&amp;gt;*&amp;lt;/default&amp;gt;&lt;BR /&gt;&amp;lt;initialValue&amp;gt;*&amp;lt;/initialValue&amp;gt;&lt;BR /&gt;&amp;lt;prefix&amp;gt;"*&amp;lt;/prefix&amp;gt;&lt;BR /&gt;&amp;lt;suffix&amp;gt;*"&amp;lt;/suffix&amp;gt;&lt;BR /&gt;&amp;lt;/input&amp;gt;&lt;BR /&gt;&amp;lt;/fieldset&amp;gt;&lt;BR /&gt;&amp;lt;row&amp;gt;&lt;BR /&gt;&amp;lt;panel&amp;gt;&lt;BR /&gt;&amp;lt;table&amp;gt;&lt;BR /&gt;&amp;lt;search&amp;gt;&lt;BR /&gt;&amp;lt;query&amp;gt;index=_audit action=search search!="'typeahead*" user="$user1$" search=$filter1$ $exclude1$&lt;BR /&gt;| stats count by _time user search total_run_time search_id app event_count&lt;BR /&gt;| sort -_time&amp;lt;/query&amp;gt;&lt;BR /&gt;&amp;lt;earliest&amp;gt;$time1.earliest$&amp;lt;/earliest&amp;gt;&lt;BR /&gt;&amp;lt;latest&amp;gt;$time1.latest$&amp;lt;/latest&amp;gt;&lt;BR /&gt;&amp;lt;sampleRatio&amp;gt;1&amp;lt;/sampleRatio&amp;gt;&lt;BR /&gt;&amp;lt;/search&amp;gt;&lt;BR /&gt;&amp;lt;option name="count"&amp;gt;20&amp;lt;/option&amp;gt;&lt;BR /&gt;&amp;lt;option name="dataOverlayMode"&amp;gt;none&amp;lt;/option&amp;gt;&lt;BR /&gt;&amp;lt;option name="drilldown"&amp;gt;none&amp;lt;/option&amp;gt;&lt;BR /&gt;&amp;lt;option name="percentagesRow"&amp;gt;false&amp;lt;/option&amp;gt;&lt;BR /&gt;&amp;lt;option name="refresh.display"&amp;gt;progressbar&amp;lt;/option&amp;gt;&lt;BR /&gt;&amp;lt;option name="rowNumbers"&amp;gt;false&amp;lt;/option&amp;gt;&lt;BR /&gt;&amp;lt;option name="totalsRow"&amp;gt;false&amp;lt;/option&amp;gt;&lt;BR /&gt;&amp;lt;option name="wrap"&amp;gt;true&amp;lt;/option&amp;gt;&lt;BR /&gt;&amp;lt;/table&amp;gt;&lt;BR /&gt;&amp;lt;/panel&amp;gt;&lt;BR /&gt;&amp;lt;/row&amp;gt;&lt;BR /&gt;&amp;lt;/form&amp;gt;&lt;/P&gt;</description>
      <pubDate>Tue, 31 May 2022 13:52:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Why-am-I-getting-this-Server-Error/m-p/599905#M49229</guid>
      <dc:creator>Robert11</dc:creator>
      <dc:date>2022-05-31T13:52:11Z</dc:date>
    </item>
    <item>
      <title>Re: Server Error</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Why-am-I-getting-this-Server-Error/m-p/599914#M49232</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;I input the code into w3Schools HTML formatter and it shows a fully functioning Splunk dashboard, but when I input into an XML formatter it comes up with the same error in Line 66. "Unenclosed Root Tag" any advice on what may be causing Splunk to not read &amp;lt;/form&amp;gt;&lt;/P&gt;</description>
      <pubDate>Tue, 31 May 2022 14:03:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Why-am-I-getting-this-Server-Error/m-p/599914#M49232</guid>
      <dc:creator>Robert11</dc:creator>
      <dc:date>2022-05-31T14:03:12Z</dc:date>
    </item>
    <item>
      <title>Re: Server Error</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Why-am-I-getting-this-Server-Error/m-p/599915#M49233</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/246336"&gt;@Robert11&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;I don't see anything strange, as I said, try to use the UI -- Edit Search button so you don't have any problem of chars.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Tue, 31 May 2022 14:06:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Why-am-I-getting-this-Server-Error/m-p/599915#M49233</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-05-31T14:06:19Z</dc:date>
    </item>
  </channel>
</rss>

