<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Base search not working properly in Dashboards &amp; Visualizations</title>
    <link>https://community.splunk.com/t5/Dashboards-Visualizations/Why-is-my-base-search-not-working-properly/m-p/615547#M50516</link>
    <description>&lt;P&gt;"it's not working" isn't a problem description.&amp;nbsp; Tell us what results you get and how that doesn't meet your expectations.&amp;nbsp; Also, don't just share the queries since base searches and post-processing depend on more than just the &lt;FONT face="courier new,courier"&gt;&amp;lt;query&amp;gt;&lt;/FONT&gt; elements.&amp;nbsp; Please share snippets of the dashboard code.&lt;/P&gt;</description>
    <pubDate>Sun, 02 Oct 2022 21:24:22 GMT</pubDate>
    <dc:creator>richgalloway</dc:creator>
    <dc:date>2022-10-02T21:24:22Z</dc:date>
    <item>
      <title>Why is my base search not working properly?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Why-is-my-base-search-not-working-properly/m-p/615545#M50515</link>
      <description>&lt;P&gt;Hi Team,&lt;/P&gt;
&lt;P&gt;I have below queries in my dashboard&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Panel1:&lt;/STRONG&gt;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;index="abc" sourcetype="abc" $reg$ |lookup local=t Org_Alias.csv OrgFolderName OUTPUT OrgName| search OrgName=$OrgName$ | rename OrgName as "Salesforce Org Name" | chart latest(NumberOfActiveUsersNotLoggedInForMoreThan15Days) as "# Active Users NOT logged in &amp;amp;gt; 15 days" latest(NumberOfActiveUsersNotLoggedInForMoreThan30Days) as "# Active Users NOT logged in &amp;amp;gt; 30 days" latest(NumberOfActiveUsersNotLoggedInForMoreThan60Days) as "# Active Users NOT logged in &amp;amp;gt; 60 days" latest(NumberOfActiveUsersNotLoggedInForMoreThan90Days) as "# Active Users NOT logged in &amp;amp;gt; 90 days" by "Salesforce Org Name"&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Panel2:&lt;/STRONG&gt;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;index="abc" sourcetype="abc" $reg$ |lookup local=t Org_Alias.csv OrgFolderName OUTPUT OrgName| search OrgName=$OrgName$ | chart latest(NumberOfActiveUsers) as "Number Of ActiveUsers" latest(SalesforceOrgId) as "Salesforce Org Id" latest(NumberOfActiveUsersNotLoggedInForMoreThan15Days) as "Number Of ActiveUsers Not Logged In For MoreThan 15Days" latest(NumberOfActiveUsersNotLoggedInForMoreThan30Days) as "Number Of ActiveUsers Not Logged In For MoreThan 30Days" latest(NumberOfActiveUsersNotLoggedInForMoreThan60Days) as "Number Of ActiveUsers Not Logged In For MoreThan 60Days" latest(NumberOfActiveUsersNotLoggedInForMoreThan90Days) as "Number Of ActiveUsers Not Logged In For MoreThan 90Days" by OrgName&lt;/LI-CODE&gt;
&lt;P&gt;&lt;STRONG&gt;panel3:&lt;/STRONG&gt;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;index="abc" sourcetype="abc" InactiveForMoreThan90Days !="No" $reg$ $type$ |lookup local=t Org_Alias.csv OrgFolderName OUTPUT OrgName| search OrgName=$OrgName$ | dedup _raw |stats count(InactiveForMoreThan90Days) as "Total Inactive Users" by OrgName&lt;/LI-CODE&gt;
&lt;P&gt;&lt;STRONG&gt;panel4&lt;/STRONG&gt;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;index="abc" sourcetype="abc" InactiveForMoreThan90Days !="No" $reg$ $type$ |lookup local=t Org_Alias.csv OrgFolderName OUTPUT OrgName|search OrgName=$selected_value4$ | dedup _raw | stats values(OrgName) as "Org" by Name Email UserId UserName LicenseName LastLoginDateTime&lt;/LI-CODE&gt;
&lt;P&gt;&lt;STRONG&gt;I have made my base search as this:&lt;/STRONG&gt;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;index="abc" sourcetype="abc" $reg$ |lookup local=t Org_Alias.csv OrgFolderName OUTPUT OrgName| search OrgName=$OrgName$|rename OrgName as "Salesforce Org Name"&lt;/LI-CODE&gt;
&lt;P&gt;But its not working can someone guide me here.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 03 Oct 2022 08:41:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Why-is-my-base-search-not-working-properly/m-p/615545#M50515</guid>
      <dc:creator>aditsss</dc:creator>
      <dc:date>2022-10-03T08:41:09Z</dc:date>
    </item>
    <item>
      <title>Re: Base search not working properly</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Why-is-my-base-search-not-working-properly/m-p/615547#M50516</link>
      <description>&lt;P&gt;"it's not working" isn't a problem description.&amp;nbsp; Tell us what results you get and how that doesn't meet your expectations.&amp;nbsp; Also, don't just share the queries since base searches and post-processing depend on more than just the &lt;FONT face="courier new,courier"&gt;&amp;lt;query&amp;gt;&lt;/FONT&gt; elements.&amp;nbsp; Please share snippets of the dashboard code.&lt;/P&gt;</description>
      <pubDate>Sun, 02 Oct 2022 21:24:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Why-is-my-base-search-not-working-properly/m-p/615547#M50516</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2022-10-02T21:24:22Z</dc:date>
    </item>
    <item>
      <title>Re: Base search not working properly</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Why-is-my-base-search-not-working-properly/m-p/615558#M50517</link>
      <description>&lt;P&gt;See the documentation on base searches&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/9.0.1/Viz/Savedsearches#Post-process_searches_2" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/9.0.1/Viz/Savedsearches#Post-process_searches_2&lt;/A&gt;&lt;/P&gt;&lt;P&gt;You have not used a transforming base search, therefore the documentation explicitly states that you need to use the fields command to specify the fields you need for any post process searches.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 03 Oct 2022 01:47:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Why-is-my-base-search-not-working-properly/m-p/615558#M50517</guid>
      <dc:creator>bowesmana</dc:creator>
      <dc:date>2022-10-03T01:47:55Z</dc:date>
    </item>
    <item>
      <title>Re: Base search not working properly</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Why-is-my-base-search-not-working-properly/m-p/615586#M50525</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225066"&gt;@aditsss&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;as&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/6367"&gt;@bowesmana&lt;/a&gt;&amp;nbsp;and&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/213957"&gt;@richgalloway&lt;/a&gt;&amp;nbsp;said, see the documentation and the Splunk Dashboard Examples App (&lt;A href="https://splunkbase.splunk.com/app/1603)" target="_blank"&gt;https://splunkbase.splunk.com/app/1603)&lt;/A&gt;&amp;nbsp;where there are some useful examples also about Post process Search.&lt;/P&gt;&lt;P&gt;anyway, your problem probably is related to the fact that, when you don't use a streaming command (as stats or timechart, etc...) you have to define in the basesearch the field that you want to use in the panels, in other words, add at the end of the base search a row with:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| fields ename OrgName NumberOfActiveUsersNotLoggedInForMoreThan15Days NumberOfActiveUsersNotLoggedInForMoreThan30Days NumberOfActiveUsersNotLoggedInForMoreThan60Days NumberOfActiveUsersNotLoggedInForMoreThan90Days NumberOfActiveUsers SalesforceOrgId InactiveForMoreThan90Days Name Email UserId UserName LicenseName LastLoginDateTime&lt;/LI-CODE&gt;&lt;P&gt;then is some of your panels, in which you are using _raw for dedupping, maybe it could be betetr to use two basesearches. one for the panels with dedup_raw (panels 3 and 4) and one for the without ones (Panels 1 and 2).&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Mon, 03 Oct 2022 06:59:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Why-is-my-base-search-not-working-properly/m-p/615586#M50525</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-10-03T06:59:21Z</dc:date>
    </item>
    <item>
      <title>Re: Base search not working properly</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Why-is-my-base-search-not-working-properly/m-p/615682#M50543</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For my 1st panel the query is below:&lt;/P&gt;&lt;P&gt;index="abc" sourcetype="xyz" $reg$ |lookup local=t Org_Alias.csv OrgFolderName OUTPUT OrgName| search OrgName=$OrgName$ | rename OrgName as "Salesforce Org Name" | chart latest(NumberOfActiveUsersNotLoggedInForMoreThan15Days) as "# Active Users NOT logged in &amp;amp;gt; 15 days" latest(NumberOfActiveUsersNotLoggedInForMoreThan30Days) as "# Active Users NOT logged in &amp;amp;gt; 30 days" latest(NumberOfActiveUsersNotLoggedInForMoreThan60Days) as "# Active Users NOT logged in &amp;amp;gt; 60 days" latest(NumberOfActiveUsersNotLoggedInForMoreThan90Days) as "# Active Users NOT logged in &amp;amp;gt; 90 days" by "Salesforce Org Name"&lt;/P&gt;&lt;P&gt;And I made my base search as below:&lt;/P&gt;&lt;P&gt;index="abc" sourcetype="xyy" $reg$ |lookup local=t Org_Alias.csv OrgFolderName OUTPUT OrgName| search OrgName=$OrgName$| fields ename OrgName NumberOfActiveUsersNotLoggedInForMoreThan15Days NumberOfActiveUsersNotLoggedInForMoreThan30Days NumberOfActiveUsersNotLoggedInForMoreThan60Days NumberOfActiveUsersNotLoggedInForMoreThan90Days NumberOfActiveUsers SalesforceOrgId InactiveForMoreThan90Days Name Email UserId UserName LicenseName LastLoginDateTime&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And I am using my base search like this in my 1st panel but not working:&lt;/P&gt;&lt;P&gt;&amp;lt;query&amp;gt; | chart latest(NumberOfActiveUsersNotLoggedInForMoreThan15Days) as "# Active Users NOT logged in &amp;amp;gt; 15 days" latest(NumberOfActiveUsersNotLoggedInForMoreThan30Days) as "# Active Users NOT logged in &amp;amp;gt; 30 days" latest(NumberOfActiveUsersNotLoggedInForMoreThan60Days) as "# Active Users NOT logged in &amp;amp;gt; 60 days" latest(NumberOfActiveUsersNotLoggedInForMoreThan90Days) as "# Active Users NOT logged in &amp;amp;gt; 90 days" by "Salesforce Org Name"&amp;lt;/query&amp;gt;&lt;/P&gt;&lt;P&gt;Can you guide me why its not working&lt;/P&gt;</description>
      <pubDate>Mon, 03 Oct 2022 17:43:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Why-is-my-base-search-not-working-properly/m-p/615682#M50543</guid>
      <dc:creator>aditsss</dc:creator>
      <dc:date>2022-10-03T17:43:04Z</dc:date>
    </item>
    <item>
      <title>Re: Base search not working properly</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Why-is-my-base-search-not-working-properly/m-p/615737#M50558</link>
      <description>&lt;P&gt;As&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/213957"&gt;@richgalloway&lt;/a&gt;&amp;nbsp;says, if you say "it is not working", it is very hard to provide a solution without knowing your data, what the results look like and what 'not working' means to you. For example, "not working" could mean&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;splunk reports an error&lt;/LI&gt;&lt;LI&gt;there are no results shown&lt;/LI&gt;&lt;LI&gt;the result you see are not what you expect&lt;/LI&gt;&lt;LI&gt;splunk reports that it is waiting for input&lt;/LI&gt;&lt;LI&gt;something else&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Please describe or screenshot your sanitized output, along with what you see as 'wrong' and if it is related to data, then please describe your data as well.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 03 Oct 2022 23:24:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Why-is-my-base-search-not-working-properly/m-p/615737#M50558</guid>
      <dc:creator>bowesmana</dc:creator>
      <dc:date>2022-10-03T23:24:27Z</dc:date>
    </item>
    <item>
      <title>Re: Base search not working properly</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Why-is-my-base-search-not-working-properly/m-p/615761#M50561</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/6367"&gt;@bowesmana&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Its showing No result found.&lt;/P&gt;&lt;P&gt;Attached is the screenshot.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 04 Oct 2022 04:53:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Why-is-my-base-search-not-working-properly/m-p/615761#M50561</guid>
      <dc:creator>aditsss</dc:creator>
      <dc:date>2022-10-04T04:53:10Z</dc:date>
    </item>
    <item>
      <title>Re: Base search not working properly</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Why-is-my-base-search-not-working-properly/m-p/615766#M50562</link>
      <description>&lt;P&gt;Click the 'Open in search' magnifying glass icon to open the search in a new tab and then you can diagnose why - the way to diagnose the search is to build up your components of the search piece by piece and you will then discover why it breaks, e.g. if your search is&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;piece_of_search_1
piece_of_search_2
piece_of_search_3&lt;/LI-CODE&gt;&lt;P&gt;and you get no results, then in that new window you have, remove your equivalent to piece_of_search_3 and see if that gives you correct data.&lt;/P&gt;&lt;P&gt;At some point you will be able to understand which SPL command is not giving you what you expect - when you have worked that out, you can post here your results and we can advise.&lt;/P&gt;</description>
      <pubDate>Tue, 04 Oct 2022 05:55:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Why-is-my-base-search-not-working-properly/m-p/615766#M50562</guid>
      <dc:creator>bowesmana</dc:creator>
      <dc:date>2022-10-04T05:55:34Z</dc:date>
    </item>
    <item>
      <title>Re: Base search not working properly</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Why-is-my-base-search-not-working-properly/m-p/615780#M50563</link>
      <description>&lt;P&gt;Easy way to exclude part of you search is just comment it out with three ` like ```spl1 | spl2```&amp;nbsp;&lt;/P&gt;&lt;P&gt;Then just move start comment e.g. line by line towards end to find where it fails.&lt;/P&gt;&lt;P&gt;And as you are using this as a base search then you also need to check how many results it get in base search part (as there are upper limit 500k lines. Also check how long it takes as there is also 60s limit.&lt;/P&gt;&lt;P&gt;You should also remember that this search is not working 1:1 with dashboard search when you are running it in separate session. But as &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/6367"&gt;@bowesmana&lt;/a&gt;&amp;nbsp;said, this is the best way to find where the issue is.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 04 Oct 2022 09:02:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Why-is-my-base-search-not-working-properly/m-p/615780#M50563</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2022-10-04T09:02:41Z</dc:date>
    </item>
    <item>
      <title>Re: Base search not working properly</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Why-is-my-base-search-not-working-properly/m-p/615851#M50571</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225066"&gt;@aditsss&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;the&amp;nbsp;&lt;SPAN&gt;"Salesforce Org Name" field isn't in the fields list of the basesearch&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;ciao.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Giuseppe&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 04 Oct 2022 16:14:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Why-is-my-base-search-not-working-properly/m-p/615851#M50571</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-10-04T16:14:11Z</dc:date>
    </item>
    <item>
      <title>Re: Base search not working properly</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Why-is-my-base-search-not-working-properly/m-p/615868#M50573</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is my base search:&lt;/P&gt;&lt;P&gt;index="abc" sourcetype="xyz" $reg$ |lookup local=t Org_Alias.csv OrgFolderName OUTPUT OrgName| search OrgName=$OrgName$| rename OrgName as "Salesforce Org Name"|fields Salesforce Org Name NumberOfActiveUsersNotLoggedInForMoreThan15Days NumberOfActiveUsersNotLoggedInForMoreThan30Days NumberOfActiveUsersNotLoggedInForMoreThan60Days NumberOfActiveUsersNotLoggedInForMoreThan90Days NumberOfActiveUsers SalesforceOrgId InactiveForMoreThan90Days Name Email UserId UserName LicenseName LastLoginDateTime&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is my query after base search for 1st panel:&lt;/P&gt;&lt;P&gt;&amp;lt;search base = "basesearch"&amp;gt;&lt;BR /&gt;&amp;lt;query&amp;gt; | chart latest(NumberOfActiveUsersNotLoggedInForMoreThan15Days) as "# Active Users NOT logged in &amp;amp;gt; 15 days" latest(NumberOfActiveUsersNotLoggedInForMoreThan30Days) as "# Active Users NOT logged in &amp;amp;gt; 30 days" latest(NumberOfActiveUsersNotLoggedInForMoreThan60Days) as "# Active Users NOT logged in &amp;amp;gt; 60 days" latest(NumberOfActiveUsersNotLoggedInForMoreThan90Days) as "# Active Users NOT logged in &amp;amp;gt; 90 days" by "Salesforce Org Name"&amp;lt;/query&amp;gt;&lt;BR /&gt;&amp;lt;/search&amp;gt;&lt;/P&gt;&lt;P&gt;This is the original query for 1st panel:&lt;/P&gt;&lt;P&gt;index="abc" sourcetype="xyz" $reg$ |lookup local=t Org_Alias.csv OrgFolderName OUTPUT OrgName| search OrgName=$OrgName$ | rename OrgName as "Salesforce Org Name" | chart latest(NumberOfActiveUsersNotLoggedInForMoreThan15Days) as "# Active Users NOT logged in &amp;amp;gt; 15 days" latest(NumberOfActiveUsersNotLoggedInForMoreThan30Days) as "# Active Users NOT logged in &amp;amp;gt; 30 days" latest(NumberOfActiveUsersNotLoggedInForMoreThan60Days) as "# Active Users NOT logged in &amp;amp;gt; 60 days" latest(NumberOfActiveUsersNotLoggedInForMoreThan90Days) as "# Active Users NOT logged in &amp;amp;gt; 90 days" by "Salesforce Org Name"&lt;/P&gt;&lt;P&gt;Can you guide me where I am wrong as still its showing "NO RESULT FOUND".&lt;/P&gt;&lt;P&gt;I try to debug but its not showing anything&lt;/P&gt;&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;please guide&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 04 Oct 2022 17:50:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Why-is-my-base-search-not-working-properly/m-p/615868#M50573</guid>
      <dc:creator>aditsss</dc:creator>
      <dc:date>2022-10-04T17:50:06Z</dc:date>
    </item>
    <item>
      <title>Re: Base search not working properly</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Why-is-my-base-search-not-working-properly/m-p/615926#M50576</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;as I said, the&amp;nbsp;&lt;SPAN&gt;"Salesforce Org Name" field isn't in the fields list, so please try this as basesearch:&lt;/SPAN&gt;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index="abc" sourcetype="xyz" $reg$ 
| lookup local=t Org_Alias.csv OrgFolderName OUTPUT OrgName
| search OrgName=$OrgName$
| rename OrgName as "Salesforce Org Name"
| fields 
   Salesforce 
   Org 
   Name
   NumberOfActiveUsersNotLoggedInForMoreThan15Days 
   NumberOfActiveUsersNotLoggedInForMoreThan30Days 
   NumberOfActiveUsersNotLoggedInForMoreThan60Days 
   NumberOfActiveUsersNotLoggedInForMoreThan90Days 
   NumberOfActiveUsers SalesforceOrgId InactiveForMoreThan90Days 
   Email 
   UserId 
   UserName 
   LicenseName 
   LastLoginDateTime 
   "Salesforce Org Name"&lt;/LI-CODE&gt;&lt;P&gt;Then name field is duplicated, but it isn't relevant.&lt;/P&gt;&lt;P&gt;&amp;nbsp;Then try to avoid field names with spaces, eventually you can rename them as last row, but avoid them during the search building.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Wed, 05 Oct 2022 07:00:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Why-is-my-base-search-not-working-properly/m-p/615926#M50576</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-10-05T07:00:53Z</dc:date>
    </item>
    <item>
      <title>Re: Base search not working properly</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Why-is-my-base-search-not-working-properly/m-p/615928#M50577</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;I think what he did was&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| rename...
| fields Salesforce Org Name ...&lt;/LI-CODE&gt;&lt;P&gt;without the quotes as the first field name listed&lt;/P&gt;</description>
      <pubDate>Wed, 05 Oct 2022 07:03:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Why-is-my-base-search-not-working-properly/m-p/615928#M50577</guid>
      <dc:creator>bowesmana</dc:creator>
      <dc:date>2022-10-05T07:03:19Z</dc:date>
    </item>
    <item>
      <title>Re: Base search not working properly</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Why-is-my-base-search-not-working-properly/m-p/615933#M50578</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225066"&gt;@aditsss&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;yes as correctly&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/6367"&gt;@bowesmana&lt;/a&gt;&amp;nbsp;said, you should move the rename (| rename OrgName as "Salesforce Org Name" in the panel after the stats command and use the Orgname field in the stats command and in the basesearch.&lt;/P&gt;&lt;P&gt;So the basesearch should be:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index="abc" sourcetype="xyz" $reg$ 
| lookup local=t Org_Alias.csv OrgFolderName OUTPUT OrgName
| search OrgName=$OrgName$
| fields 
   Salesforce 
   Org 
   Name
   NumberOfActiveUsersNotLoggedInForMoreThan15Days 
   NumberOfActiveUsersNotLoggedInForMoreThan30Days 
   NumberOfActiveUsersNotLoggedInForMoreThan60Days 
   NumberOfActiveUsersNotLoggedInForMoreThan90Days 
   NumberOfActiveUsers SalesforceOrgId InactiveForMoreThan90Days 
   Email 
   UserId 
   UserName 
   LicenseName 
   LastLoginDateTime 
   OrgName&lt;/LI-CODE&gt;&lt;P&gt;and the panel's search should be:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| chart latest(NumberOfActiveUsersNotLoggedInForMoreThan15Days) as "# Active Users NOT logged in &amp;amp;gt; 15 days" latest(NumberOfActiveUsersNotLoggedInForMoreThan30Days) as "# Active Users NOT logged in &amp;amp;gt; 30 days" latest(NumberOfActiveUsersNotLoggedInForMoreThan60Days) as "# Active Users NOT logged in &amp;amp;gt; 60 days" latest(NumberOfActiveUsersNotLoggedInForMoreThan90Days) as "# Active Users NOT logged in &amp;amp;gt; 90 days" by Orgname
| rename OrgName AS "Salesforce Org Name"&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Wed, 05 Oct 2022 08:19:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Why-is-my-base-search-not-working-properly/m-p/615933#M50578</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-10-05T08:19:53Z</dc:date>
    </item>
    <item>
      <title>Re: Base search not working properly</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Why-is-my-base-search-not-working-properly/m-p/616575#M50628</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;Thank you for this fantastic solution.&lt;/P&gt;&lt;P&gt;But the panels which have dedup is not working&lt;/P&gt;&lt;P&gt;My base serach:&lt;/P&gt;&lt;P&gt;index="abc" sourcetype="xyz" $reg$ $type$ |lookup local=t Org_Alias.csv OrgFolderName OUTPUT OrgName| search OrgName=$OrgName$ | fields Salesforce Org Name&lt;BR /&gt;NumberOfActiveUsersNotLoggedInForMoreThan15Days&lt;BR /&gt;NumberOfActiveUsersNotLoggedInForMoreThan30Days&lt;BR /&gt;NumberOfActiveUsersNotLoggedInForMoreThan60Days&lt;BR /&gt;NumberOfActiveUsersNotLoggedInForMoreThan90Days&lt;BR /&gt;NumberOfActiveUsers SalesforceOrgId InactiveForMoreThan90Days&lt;BR /&gt;SalesforceOrgId&lt;BR /&gt;Email&lt;BR /&gt;UserId&lt;BR /&gt;UserName&lt;BR /&gt;LicenseName&lt;BR /&gt;LastLoginDateTime&lt;BR /&gt;OrgName&lt;/P&gt;&lt;P&gt;My panel search:&lt;/P&gt;&lt;P&gt;| dedup _raw |stats count(InactiveForMoreThan90Days) as "Total Inactive Users" by OrgName&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Actual panel query without base search:&lt;/P&gt;&lt;P&gt;index="abc" sourcetype="xyz" InactiveForMoreThan90Days !="No" $reg$ $type$ |lookup local=t Org_Alias.csv OrgFolderName OUTPUT OrgName| search OrgName=$OrgName$ | dedup _raw |stats count(InactiveForMoreThan90Days) as "Total Inactive Users" by OrgName&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 10 Oct 2022 20:58:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Why-is-my-base-search-not-working-properly/m-p/616575#M50628</guid>
      <dc:creator>aditsss</dc:creator>
      <dc:date>2022-10-10T20:58:10Z</dc:date>
    </item>
    <item>
      <title>Re: Base search not working properly</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Why-is-my-base-search-not-working-properly/m-p/616605#M50630</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225066"&gt;@aditsss&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;as I said, you have to put in the fields list at the end of the base search all the fields to use in the panel's search.&lt;/P&gt;&lt;P&gt;In your case, you dedup for _raw that isn't a field in the base search, so you don't have any result.&lt;/P&gt;&lt;P&gt;You could try to add _raw to the fields list or (BETTER) put the "| dedup _raw" in the base search.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Tue, 11 Oct 2022 07:16:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Why-is-my-base-search-not-working-properly/m-p/616605#M50630</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-10-11T07:16:06Z</dc:date>
    </item>
    <item>
      <title>Re: Base search not working properly</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Why-is-my-base-search-not-working-properly/m-p/616740#M50636</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I used like this but isn't working&lt;/P&gt;&lt;P&gt;Base search:&lt;/P&gt;&lt;P&gt;index="abc" sourcetype="xyz" $reg$ $type$ |lookup local=t Org_Alias.csv OrgFolderName OUTPUT OrgName| search OrgName=$OrgName$ |fields Salesforce Org Name&lt;BR /&gt;NumberOfActiveUsersNotLoggedInForMoreThan15Days&lt;BR /&gt;NumberOfActiveUsersNotLoggedInForMoreThan30Days&lt;BR /&gt;NumberOfActiveUsersNotLoggedInForMoreThan60Days&lt;BR /&gt;NumberOfActiveUsersNotLoggedInForMoreThan90Days&lt;BR /&gt;NumberOfActiveUsers SalesforceOrgId InactiveForMoreThan90Days&lt;BR /&gt;SalesforceOrgId&lt;BR /&gt;Email&lt;BR /&gt;UserId&lt;BR /&gt;UserName&lt;BR /&gt;LicenseName&lt;BR /&gt;LastLoginDateTime&lt;BR /&gt;OrgName| dedup _raw&lt;/P&gt;&lt;P&gt;panel search:&lt;/P&gt;&lt;P&gt;|stats count(InactiveForMoreThan90Days) as "Total Inactive Users" by OrgName&lt;/P&gt;</description>
      <pubDate>Tue, 11 Oct 2022 20:33:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Why-is-my-base-search-not-working-properly/m-p/616740#M50636</guid>
      <dc:creator>aditsss</dc:creator>
      <dc:date>2022-10-11T20:33:32Z</dc:date>
    </item>
    <item>
      <title>Re: Base search not working properly</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Why-is-my-base-search-not-working-properly/m-p/616811#M50651</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225066"&gt;@aditsss&lt;/a&gt;&amp;nbsp;ì,&lt;/P&gt;&lt;P&gt;use fields as last command&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index="abc" sourcetype="xyz" $reg$ $type$ 
| lookup local=t Org_Alias.csv OrgFolderName OUTPUT OrgName
| search OrgName=$OrgName$ 
| dedup _raw
| fields Salesforce Org Name
NumberOfActiveUsersNotLoggedInForMoreThan15Days
NumberOfActiveUsersNotLoggedInForMoreThan30Days
NumberOfActiveUsersNotLoggedInForMoreThan60Days
NumberOfActiveUsersNotLoggedInForMoreThan90Days
NumberOfActiveUsers SalesforceOrgId InactiveForMoreThan90Days
SalesforceOrgId Email UserId UserName LicenseName LastLoginDateTime OrgName&lt;/LI-CODE&gt;&lt;P&gt;Then check if, running the base search, you still have the fields:&amp;nbsp;&lt;SPAN&gt;InactiveForMoreThan90Days and OrgName.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Ciao.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Giuseppe&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 12 Oct 2022 12:09:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Why-is-my-base-search-not-working-properly/m-p/616811#M50651</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-10-12T12:09:06Z</dc:date>
    </item>
    <item>
      <title>Re: Base search not working properly</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Why-is-my-base-search-not-working-properly/m-p/616888#M50656</link>
      <description>&lt;P&gt;One thing that has been pointed out before - the statement in the base search&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| fields Salesforce Org Name&lt;/LI-CODE&gt;&lt;P&gt;should I believe be&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| fields "Salesforce Org Name"&lt;/LI-CODE&gt;&lt;P&gt;as you later refer to this as a field with quotes - if you do not use quotes in the first statement, then you are asking for 3 fields Salesforce, Org and Name.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 12 Oct 2022 21:27:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Why-is-my-base-search-not-working-properly/m-p/616888#M50656</guid>
      <dc:creator>bowesmana</dc:creator>
      <dc:date>2022-10-12T21:27:42Z</dc:date>
    </item>
  </channel>
</rss>

