<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk Dashboard - search returns null in Dashboards &amp; Visualizations</title>
    <link>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-Dashboard-search-returns-null/m-p/710355#M58116</link>
    <description>&lt;P&gt;Thanx. Next time when you paste something please use &amp;lt;/&amp;gt; code block to avoid character changes etc.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Based on those I suppose that your data haven't correct values what you are looking for. You should check it by clicking magnifying class on right bottom corner of your dashboard's individual panel. This opens exactly same search you to separate window/tab and you can see what events it found. Then you can debug it by e.g. commenting rows away from bottom to top.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 31 Jan 2025 15:48:58 GMT</pubDate>
    <dc:creator>isoutamo</dc:creator>
    <dc:date>2025-01-31T15:48:58Z</dc:date>
    <item>
      <title>Splunk Dashboard - search returns null</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-Dashboard-search-returns-null/m-p/710333#M58104</link>
      <description>&lt;P&gt;I have created a dashboard that reads a MQ flow that contains messages to different vendors.&amp;nbsp; I have created panels for the different vendors and am trying to group the messages for each of those vendors.&amp;nbsp; Each Vendor will receive 2 message types ASM and SSM.&amp;nbsp; 2 panels work but the other does not, it only returns NULL yet there are messages.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="DarrellR_0-1738333599908.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/34316i381013EAE8D64E1C/image-size/medium?v=v2&amp;amp;px=400" role="button" title="DarrellR_0-1738333599908.png" alt="DarrellR_0-1738333599908.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;The search is exactly the same for all three with the exception of the Vendor address, here is the search&lt;/P&gt;&lt;P&gt;index="emh_prd" ACXForm="TTYIN:MULEOUT:TTYOUT" XXXXXX AND .YYYYYY&lt;BR /&gt;| timechart count by DR1&lt;/P&gt;&lt;P&gt;The XXXXXX is the Vendor address and .YYYYYYY is the sender address.&amp;nbsp; The sender address will stay the same but the each panel will have a different XXXXXX value&lt;/P&gt;&lt;P&gt;I can not figure out why only that 1 does not work and returns NULL when it receives basically the same messages just with a different XXXXXX value&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I hope someone here can help me&lt;/P&gt;</description>
      <pubDate>Fri, 31 Jan 2025 14:38:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-Dashboard-search-returns-null/m-p/710333#M58104</guid>
      <dc:creator>DarrellR</dc:creator>
      <dc:date>2025-01-31T14:38:13Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Dashboard - search returns null</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-Dashboard-search-returns-null/m-p/710335#M58105</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/276030"&gt;@DarrellR&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;are you sure that all the events have the DR1 field?&lt;/P&gt;&lt;P&gt;you could try to add DR1=* to the main search.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Fri, 31 Jan 2025 14:41:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-Dashboard-search-returns-null/m-p/710335#M58105</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2025-01-31T14:41:14Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Dashboard - search returns null</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-Dashboard-search-returns-null/m-p/710336#M58106</link>
      <description>&lt;P&gt;&lt;EM&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;,&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Thanks for the quick reply!&amp;nbsp; I am new to this, where would I add the DR1=* in my search?&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Also not all the panels have the DR1 in there events but they still work.&amp;nbsp; This is part of why I don't understand why some work and not others.&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 31 Jan 2025 14:48:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-Dashboard-search-returns-null/m-p/710336#M58106</guid>
      <dc:creator>DarrellR</dc:creator>
      <dc:date>2025-01-31T14:48:03Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Dashboard - search returns null</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-Dashboard-search-returns-null/m-p/710341#M58107</link>
      <description>&lt;P&gt;Here is the events from left to right for the 3 panels.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="DarrellR_1-1738335090326.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/34319i4D7C3E8D1510A884/image-size/medium?v=v2&amp;amp;px=400" role="button" title="DarrellR_1-1738335090326.png" alt="DarrellR_1-1738335090326.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="DarrellR_2-1738335179531.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/34320i4BAB48641D291F80/image-size/medium?v=v2&amp;amp;px=400" role="button" title="DarrellR_2-1738335179531.png" alt="DarrellR_2-1738335179531.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="DarrellR_3-1738335266949.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/34321i6E7E1D0C61CE9ED5/image-size/medium?v=v2&amp;amp;px=400" role="button" title="DarrellR_3-1738335266949.png" alt="DarrellR_3-1738335266949.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;So here the DR1 is not showing but the 1st and 3rd panels work but the middle one does not.&amp;nbsp; The characters in the RED box is what the DR1 is looking for either SSM or ASM&lt;/P&gt;</description>
      <pubDate>Fri, 31 Jan 2025 14:56:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-Dashboard-search-returns-null/m-p/710341#M58107</guid>
      <dc:creator>DarrellR</dc:creator>
      <dc:date>2025-01-31T14:56:30Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Dashboard - search returns null</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-Dashboard-search-returns-null/m-p/710342#M58108</link>
      <description>&lt;P&gt;Here is your original search&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index="emh_prd" ACXForm="TTYIN:MULEOUT:TTYOUT" XXXXXX AND .YYYYYY
| timechart count by DR1&lt;/LI-CODE&gt;&lt;P&gt;You should do it like&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index="emh_prd" ACXForm="TTYIN:MULEOUT:TTYOUT" XXXXXX AND .YYYYYY DR1=*
| timechart count by DR1&lt;/LI-CODE&gt;&lt;P&gt;or&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index="emh_prd" ACXForm="TTYIN:MULEOUT:TTYOUT" XXXXXX AND .YYYYYY
| eval DR1 = coalesce(DR1, "DR1 N/A")
| timechart count by DR1&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/Splunk/9.4.0/SearchReference/ConditionalFunctions#coalesce.28.26lt.3Bvalues.29" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/9.4.0/SearchReference/ConditionalFunctions#coalesce.28.26lt.3Bvalues.29&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 31 Jan 2025 15:01:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-Dashboard-search-returns-null/m-p/710342#M58108</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2025-01-31T15:01:13Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Dashboard - search returns null</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-Dashboard-search-returns-null/m-p/710345#M58109</link>
      <description>&lt;P&gt;Thanks but neither of those seem to work, I still get NULL even though there are messages.&amp;nbsp; This is very frustrating&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 31 Jan 2025 15:16:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-Dashboard-search-returns-null/m-p/710345#M58109</guid>
      <dc:creator>DarrellR</dc:creator>
      <dc:date>2025-01-31T15:16:43Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Dashboard - search returns null</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-Dashboard-search-returns-null/m-p/710347#M58110</link>
      <description>&lt;P&gt;Are you sure that those queries are used on those panels? Or are there some other filtering after those queries which remove all results?&lt;/P&gt;&lt;P&gt;Can you share those panels source and also your sample data (with anonymous values when needed)?&lt;/P&gt;</description>
      <pubDate>Fri, 31 Jan 2025 15:20:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-Dashboard-search-returns-null/m-p/710347#M58110</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2025-01-31T15:20:42Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Dashboard - search returns null</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-Dashboard-search-returns-null/m-p/710349#M58111</link>
      <description>&lt;P&gt;This is panel 1&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="DarrellR_0-1738337063427.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/34322iB4BE9302A3F65FDD/image-size/medium?v=v2&amp;amp;px=400" role="button" title="DarrellR_0-1738337063427.png" alt="DarrellR_0-1738337063427.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 31 Jan 2025 15:24:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-Dashboard-search-returns-null/m-p/710349#M58111</guid>
      <dc:creator>DarrellR</dc:creator>
      <dc:date>2025-01-31T15:24:55Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Dashboard - search returns null</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-Dashboard-search-returns-null/m-p/710351#M58112</link>
      <description>&lt;P&gt;This is panel 2 [the one showing NULL]&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="DarrellR_0-1738337165388.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/34323i1C1ACE546641F965/image-size/medium?v=v2&amp;amp;px=400" role="button" title="DarrellR_0-1738337165388.png" alt="DarrellR_0-1738337165388.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 31 Jan 2025 15:26:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-Dashboard-search-returns-null/m-p/710351#M58112</guid>
      <dc:creator>DarrellR</dc:creator>
      <dc:date>2025-01-31T15:26:15Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Dashboard - search returns null</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-Dashboard-search-returns-null/m-p/710352#M58113</link>
      <description>&lt;P&gt;Here is the source for the 2nd panel&lt;/P&gt;&lt;P&gt;&amp;lt;chart&amp;gt;&lt;BR /&gt;&amp;lt;title&amp;gt;SchedConnect Messages to {nnnn]&amp;lt;/title&amp;gt;&lt;BR /&gt;&amp;lt;search&amp;gt;&lt;BR /&gt;&amp;lt;query&amp;gt;index="emh_prd" ACXForm="TTYIN:MULEOUT:TTYOUT" XXXXXX AND .YYYYYY&lt;BR /&gt;| timechart count by DR1&amp;lt;/query&amp;gt;&lt;BR /&gt;&amp;lt;earliest&amp;gt;$TimePickerKielToken.earliest$&amp;lt;/earliest&amp;gt;&lt;BR /&gt;&amp;lt;latest&amp;gt;$TimePickerKielToken.latest$&amp;lt;/latest&amp;gt;&lt;BR /&gt;&amp;lt;refresh&amp;gt;1m&amp;lt;/refresh&amp;gt;&lt;BR /&gt;&amp;lt;refreshType&amp;gt;delay&amp;lt;/refreshType&amp;gt;&lt;BR /&gt;&amp;lt;/search&amp;gt;&lt;BR /&gt;&amp;lt;option name="charting.axisTitleX.text"&amp;gt;Time&amp;lt;/option&amp;gt;&lt;BR /&gt;&amp;lt;option name="charting.axisTitleX.visibility"&amp;gt;visible&amp;lt;/option&amp;gt;&lt;BR /&gt;&amp;lt;option name="charting.axisTitleY.visibility"&amp;gt;visible&amp;lt;/option&amp;gt;&lt;BR /&gt;&amp;lt;option name="charting.axisTitleY2.visibility"&amp;gt;visible&amp;lt;/option&amp;gt;&lt;BR /&gt;&amp;lt;option name="charting.chart"&amp;gt;column&amp;lt;/option&amp;gt;&lt;BR /&gt;&amp;lt;option name="charting.drilldown"&amp;gt;all&amp;lt;/option&amp;gt;&lt;BR /&gt;&amp;lt;option name="charting.legend.placement"&amp;gt;right&amp;lt;/option&amp;gt;&lt;BR /&gt;&amp;lt;option name="refresh.display"&amp;gt;progressbar&amp;lt;/option&amp;gt;&lt;BR /&gt;&amp;lt;option name="trellis.enabled"&amp;gt;0&amp;lt;/option&amp;gt;&lt;BR /&gt;&amp;lt;option name="trellis.size"&amp;gt;medium&amp;lt;/option&amp;gt;&lt;BR /&gt;&amp;lt;/chart&amp;gt;&lt;BR /&gt;&amp;lt;/panel&amp;gt;&lt;BR /&gt;&amp;lt;panel&amp;gt;&lt;BR /&gt;&amp;lt;chart&amp;gt;&lt;/P&gt;</description>
      <pubDate>Fri, 31 Jan 2025 15:28:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-Dashboard-search-returns-null/m-p/710352#M58113</guid>
      <dc:creator>DarrellR</dc:creator>
      <dc:date>2025-01-31T15:28:28Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Dashboard - search returns null</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-Dashboard-search-returns-null/m-p/710353#M58114</link>
      <description>&lt;P&gt;here is the source for the 1st panel&lt;/P&gt;&lt;P&gt;&amp;lt;row&amp;gt;&lt;BR /&gt;&amp;lt;panel&amp;gt;&lt;BR /&gt;&amp;lt;chart&amp;gt;&lt;BR /&gt;&amp;lt;title&amp;gt;SchedConnect Messages to [nnnnn]&amp;lt;/title&amp;gt;&lt;BR /&gt;&amp;lt;search&amp;gt;&lt;BR /&gt;&amp;lt;query&amp;gt;index="emh_prd" ACXForm="TTYIN:MULEOUT:TTYOUT" XXXXXX AND .YYYYYY&lt;BR /&gt;| timechart count by DR1&amp;lt;/query&amp;gt;&lt;BR /&gt;&amp;lt;earliest&amp;gt;$TimePickerKielToken.earliest$&amp;lt;/earliest&amp;gt;&lt;BR /&gt;&amp;lt;latest&amp;gt;$TimePickerKielToken.latest$&amp;lt;/latest&amp;gt;&lt;BR /&gt;&amp;lt;refresh&amp;gt;1m&amp;lt;/refresh&amp;gt;&lt;BR /&gt;&amp;lt;refreshType&amp;gt;delay&amp;lt;/refreshType&amp;gt;&lt;BR /&gt;&amp;lt;/search&amp;gt;&lt;BR /&gt;&amp;lt;option name="charting.axisTitleX.text"&amp;gt;Time&amp;lt;/option&amp;gt;&lt;BR /&gt;&amp;lt;option name="charting.chart"&amp;gt;column&amp;lt;/option&amp;gt;&lt;BR /&gt;&amp;lt;option name="charting.drilldown"&amp;gt;all&amp;lt;/option&amp;gt;&lt;BR /&gt;&amp;lt;option name="charting.legend.placement"&amp;gt;right&amp;lt;/option&amp;gt;&lt;BR /&gt;&amp;lt;option name="refresh.display"&amp;gt;progressbar&amp;lt;/option&amp;gt;&lt;BR /&gt;&amp;lt;/chart&amp;gt;&lt;BR /&gt;&amp;lt;/panel&amp;gt;&lt;BR /&gt;&amp;lt;panel&amp;gt;&lt;BR /&gt;&amp;lt;chart&amp;gt;&lt;/P&gt;</description>
      <pubDate>Fri, 31 Jan 2025 15:29:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-Dashboard-search-returns-null/m-p/710353#M58114</guid>
      <dc:creator>DarrellR</dc:creator>
      <dc:date>2025-01-31T15:29:35Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Dashboard - search returns null</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-Dashboard-search-returns-null/m-p/710354#M58115</link>
      <description>&lt;P&gt;Here is the source code all together for those panels - left to right, might be easier to debug&lt;/P&gt;&lt;P&gt;&amp;lt;row&amp;gt;&lt;BR /&gt;&amp;lt;panel&amp;gt;&lt;BR /&gt;&amp;lt;chart&amp;gt;&lt;BR /&gt;&amp;lt;title&amp;gt;SchedConnect Messages to [nnnnn]&amp;lt;/title&amp;gt;&lt;BR /&gt;&amp;lt;search&amp;gt;&lt;BR /&gt;&amp;lt;query&amp;gt;index="emh_prd" ACXForm="TTYIN:MULEOUT:TTYOUT" XXXXXX AND .YYYYYY&lt;BR /&gt;| timechart count by DR1&amp;lt;/query&amp;gt;&lt;BR /&gt;&amp;lt;earliest&amp;gt;$TimePickerKielToken.earliest$&amp;lt;/earliest&amp;gt;&lt;BR /&gt;&amp;lt;latest&amp;gt;$TimePickerKielToken.latest$&amp;lt;/latest&amp;gt;&lt;BR /&gt;&amp;lt;refresh&amp;gt;1m&amp;lt;/refresh&amp;gt;&lt;BR /&gt;&amp;lt;refreshType&amp;gt;delay&amp;lt;/refreshType&amp;gt;&lt;BR /&gt;&amp;lt;/search&amp;gt;&lt;BR /&gt;&amp;lt;option name="charting.axisTitleX.text"&amp;gt;Time&amp;lt;/option&amp;gt;&lt;BR /&gt;&amp;lt;option name="charting.chart"&amp;gt;column&amp;lt;/option&amp;gt;&lt;BR /&gt;&amp;lt;option name="charting.drilldown"&amp;gt;all&amp;lt;/option&amp;gt;&lt;BR /&gt;&amp;lt;option name="charting.legend.placement"&amp;gt;right&amp;lt;/option&amp;gt;&lt;BR /&gt;&amp;lt;option name="refresh.display"&amp;gt;progressbar&amp;lt;/option&amp;gt;&lt;BR /&gt;&amp;lt;/chart&amp;gt;&lt;BR /&gt;&amp;lt;/panel&amp;gt;&lt;BR /&gt;&amp;lt;panel&amp;gt;&lt;BR /&gt;&amp;lt;chart&amp;gt;&lt;BR /&gt;&amp;lt;title&amp;gt;SchedConnect Messages to {nnnnn]&amp;lt;/title&amp;gt;&lt;BR /&gt;&amp;lt;search&amp;gt;&lt;BR /&gt;&amp;lt;query&amp;gt;index="emh_prd" ACXForm="TTYIN:MULEOUT:TTYOUT" XXXXXX AND .YYYYY&lt;BR /&gt;| timechart count by DR1&amp;lt;/query&amp;gt;&lt;BR /&gt;&amp;lt;earliest&amp;gt;$TimePickerKielToken.earliest$&amp;lt;/earliest&amp;gt;&lt;BR /&gt;&amp;lt;latest&amp;gt;$TimePickerKielToken.latest$&amp;lt;/latest&amp;gt;&lt;BR /&gt;&amp;lt;refresh&amp;gt;1m&amp;lt;/refresh&amp;gt;&lt;BR /&gt;&amp;lt;refreshType&amp;gt;delay&amp;lt;/refreshType&amp;gt;&lt;BR /&gt;&amp;lt;/search&amp;gt;&lt;BR /&gt;&amp;lt;option name="charting.axisTitleX.text"&amp;gt;Time&amp;lt;/option&amp;gt;&lt;BR /&gt;&amp;lt;option name="charting.axisTitleX.visibility"&amp;gt;visible&amp;lt;/option&amp;gt;&lt;BR /&gt;&amp;lt;option name="charting.axisTitleY.visibility"&amp;gt;visible&amp;lt;/option&amp;gt;&lt;BR /&gt;&amp;lt;option name="charting.axisTitleY2.visibility"&amp;gt;visible&amp;lt;/option&amp;gt;&lt;BR /&gt;&amp;lt;option name="charting.chart"&amp;gt;column&amp;lt;/option&amp;gt;&lt;BR /&gt;&amp;lt;option name="charting.drilldown"&amp;gt;all&amp;lt;/option&amp;gt;&lt;BR /&gt;&amp;lt;option name="charting.legend.placement"&amp;gt;right&amp;lt;/option&amp;gt;&lt;BR /&gt;&amp;lt;option name="refresh.display"&amp;gt;progressbar&amp;lt;/option&amp;gt;&lt;BR /&gt;&amp;lt;/chart&amp;gt;&lt;BR /&gt;&amp;lt;/panel&amp;gt;&lt;BR /&gt;&amp;lt;panel&amp;gt;&lt;BR /&gt;&amp;lt;chart&amp;gt;&lt;BR /&gt;&amp;lt;title&amp;gt;SchedConnect Messages to [nnnnn]&amp;lt;/title&amp;gt;&lt;BR /&gt;&amp;lt;search&amp;gt;&lt;BR /&gt;&amp;lt;query&amp;gt;index="emh_prd" ACXForm="TTYIN:MULEOUT:TTYOUT" XXXXXX AND .YYYYYY&lt;BR /&gt;| timechart count by DR1&amp;lt;/query&amp;gt;&lt;BR /&gt;&amp;lt;earliest&amp;gt;$TimePickerKielToken.earliest$&amp;lt;/earliest&amp;gt;&lt;BR /&gt;&amp;lt;latest&amp;gt;$TimePickerKielToken.latest$&amp;lt;/latest&amp;gt;&lt;BR /&gt;&amp;lt;refresh&amp;gt;1m&amp;lt;/refresh&amp;gt;&lt;BR /&gt;&amp;lt;refreshType&amp;gt;delay&amp;lt;/refreshType&amp;gt;&lt;BR /&gt;&amp;lt;/search&amp;gt;&lt;BR /&gt;&amp;lt;option name="charting.axisTitleX.text"&amp;gt;Time&amp;lt;/option&amp;gt;&lt;BR /&gt;&amp;lt;option name="charting.chart"&amp;gt;column&amp;lt;/option&amp;gt;&lt;BR /&gt;&amp;lt;option name="charting.drilldown"&amp;gt;all&amp;lt;/option&amp;gt;&lt;BR /&gt;&amp;lt;option name="refresh.display"&amp;gt;progressbar&amp;lt;/option&amp;gt;&lt;BR /&gt;&amp;lt;/chart&amp;gt;&lt;BR /&gt;&amp;lt;/panel&amp;gt;&lt;/P&gt;</description>
      <pubDate>Fri, 31 Jan 2025 15:43:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-Dashboard-search-returns-null/m-p/710354#M58115</guid>
      <dc:creator>DarrellR</dc:creator>
      <dc:date>2025-01-31T15:43:52Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Dashboard - search returns null</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-Dashboard-search-returns-null/m-p/710355#M58116</link>
      <description>&lt;P&gt;Thanx. Next time when you paste something please use &amp;lt;/&amp;gt; code block to avoid character changes etc.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Based on those I suppose that your data haven't correct values what you are looking for. You should check it by clicking magnifying class on right bottom corner of your dashboard's individual panel. This opens exactly same search you to separate window/tab and you can see what events it found. Then you can debug it by e.g. commenting rows away from bottom to top.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 31 Jan 2025 15:48:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-Dashboard-search-returns-null/m-p/710355#M58116</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2025-01-31T15:48:58Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Dashboard - search returns null</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-Dashboard-search-returns-null/m-p/710356#M58117</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/214410"&gt;@isoutamo&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I will do that next time I post, thank you.&amp;nbsp; I have checked the search and aside from the XXXXXX values being the address for the different vendors, each panel uses the exact same search, it is just for 1 I get NULL values even though the messages are there when I look at the events&lt;/P&gt;</description>
      <pubDate>Fri, 31 Jan 2025 16:01:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-Dashboard-search-returns-null/m-p/710356#M58117</guid>
      <dc:creator>DarrellR</dc:creator>
      <dc:date>2025-01-31T16:01:29Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Dashboard - search returns null</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-Dashboard-search-returns-null/m-p/710390#M58125</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/276030"&gt;@DarrellR&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;as also&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/214410"&gt;@isoutamo&lt;/a&gt;&amp;nbsp;said, you should put it in the main search.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Sat, 01 Feb 2025 07:00:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-Dashboard-search-returns-null/m-p/710390#M58125</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2025-02-01T07:00:19Z</dc:date>
    </item>
  </channel>
</rss>

