<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Receiving a Duplicate labels causing conflict error in Dashboards &amp; Visualizations</title>
    <link>https://community.splunk.com/t5/Dashboards-Visualizations/Receiving-a-Duplicate-labels-causing-conflict-error/m-p/132324#M7818</link>
    <description>&lt;P&gt;Finally, the &lt;CODE&gt;fields source&lt;/CODE&gt; in that search is unnecessary - &lt;CODE&gt;top&lt;/CODE&gt; on its own already returns only the source field &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 01 Jun 2015 09:38:13 GMT</pubDate>
    <dc:creator>jeffland</dc:creator>
    <dc:date>2015-06-01T09:38:13Z</dc:date>
    <item>
      <title>Receiving a Duplicate labels causing conflict error</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Receiving-a-Duplicate-labels-causing-conflict-error/m-p/132321#M7815</link>
      <description>&lt;P&gt;I've created a dashboard with a drop down so the user can select different sources. But I'm receiving a "Duplicate labels causing conflict" error, how do I stop this.&lt;/P&gt;

&lt;P&gt;I've already read the post listed here: &lt;BR /&gt;
&lt;A href="http://answers.splunk.com/answers/221599/duplicate-labels-causing-conflict.html"&gt;http://answers.splunk.com/answers/221599/duplicate-labels-causing-conflict.html&lt;/A&gt;&lt;BR /&gt;
but this didn't resolve my issue.&lt;/P&gt;

&lt;P&gt;Here's my XML code:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;&amp;lt;form&amp;gt;
  &amp;lt;label&amp;gt;TEST&amp;lt;/label&amp;gt;
  &amp;lt;description&amp;gt;description&amp;lt;/description&amp;gt;
  &amp;lt;fieldset autoRun="true" submitButton="false"&amp;gt;
    &amp;lt;input type="dropdown" token="source" searchWhenChanged="true"&amp;gt;
      &amp;lt;label&amp;gt;Select a Source:&amp;lt;/label&amp;gt;
      &amp;lt;search&amp;gt;
        &amp;lt;query&amp;gt;index="test_inputs" sourcetype="Qualys_Desktop" source="*-MS-*" | fields source&amp;lt;/query&amp;gt;
        &amp;lt;earliest&amp;gt;-6mon&amp;lt;/earliest&amp;gt;
        &amp;lt;latest&amp;gt;now&amp;lt;/latest&amp;gt;
      &amp;lt;/search&amp;gt;
      &amp;lt;fieldForLabel&amp;gt;source&amp;lt;/fieldForLabel&amp;gt;
      &amp;lt;fieldForValue&amp;gt;source&amp;lt;/fieldForValue&amp;gt;
    &amp;lt;/input&amp;gt;
  &amp;lt;/fieldset&amp;gt;
  &amp;lt;row&amp;gt;
    &amp;lt;panel&amp;gt;
      &amp;lt;single&amp;gt;
        &amp;lt;title&amp;gt;Total &amp;lt;/title&amp;gt;
        &amp;lt;search&amp;gt;
          &amp;amp;lt;query&amp;amp;gt;index="test_inputs" source="$source$" Type="Vuln" | stats count&amp;amp;lt;/query&amp;amp;gt;
          &amp;lt;earliest&amp;gt;0&amp;lt;/earliest&amp;gt;
          &amp;lt;latest&amp;gt;&amp;lt;/latest&amp;gt;
        &amp;lt;/search&amp;gt;
        &amp;lt;option name="drilldown"&amp;gt;none&amp;lt;/option&amp;gt;
        &amp;lt;option name="linkView"&amp;gt;search&amp;lt;/option&amp;gt;
      &amp;lt;/single&amp;gt;
    &amp;lt;/panel&amp;gt;
    &amp;lt;panel&amp;gt;
      &amp;lt;single&amp;gt;
        &amp;lt;title&amp;gt;Total unique&amp;lt;/title&amp;gt;
        &amp;lt;search&amp;gt;
          &amp;amp;lt;query&amp;amp;gt;index="test_inputs" source="$source$" Type="Vuln" | stats distinct_count(Title)&amp;amp;lt;/query&amp;amp;gt;
          &amp;lt;earliest&amp;gt;0&amp;lt;/earliest&amp;gt;
          &amp;lt;latest&amp;gt;&amp;lt;/latest&amp;gt;
        &amp;lt;/search&amp;gt;
        &amp;lt;option name="drilldown"&amp;gt;none&amp;lt;/option&amp;gt;
        &amp;lt;option name="linkView"&amp;gt;search&amp;lt;/option&amp;gt;
      &amp;lt;/single&amp;gt;
    &amp;lt;/panel&amp;gt;
  &amp;lt;/row&amp;gt;
&amp;lt;/form&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Mon, 01 Jun 2015 08:53:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Receiving-a-Duplicate-labels-causing-conflict-error/m-p/132321#M7815</guid>
      <dc:creator>MichaelPriest</dc:creator>
      <dc:date>2015-06-01T08:53:21Z</dc:date>
    </item>
    <item>
      <title>Re: Receiving a Duplicate labels causing conflict error</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Receiving-a-Duplicate-labels-causing-conflict-error/m-p/132322#M7816</link>
      <description>&lt;P&gt;Did you run the search that populates your dropdown by hand, and if yes what does it return? Maybe there are indeed sources with the same name. I would reccommend to use searches with &lt;CODE&gt;top&lt;/CODE&gt; to populate dropdowns, because that way you get rid of duplicates and it should be faster than a combination of &lt;CODE&gt;table&lt;/CODE&gt; and &lt;CODE&gt;dedup&lt;/CODE&gt;.&lt;/P&gt;</description>
      <pubDate>Mon, 01 Jun 2015 09:04:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Receiving-a-Duplicate-labels-causing-conflict-error/m-p/132322#M7816</guid>
      <dc:creator>jeffland</dc:creator>
      <dc:date>2015-06-01T09:04:53Z</dc:date>
    </item>
    <item>
      <title>Re: Receiving a Duplicate labels causing conflict error</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Receiving-a-Duplicate-labels-causing-conflict-error/m-p/132323#M7817</link>
      <description>&lt;P&gt;Thanks very much, I altered my search so it included a top, it's more efficient too:&lt;/P&gt;

&lt;P&gt;index="test_inputs" sourcetype="Qualys_Desktop" source="&lt;EM&gt;-MS-&lt;/EM&gt;" | fields source | top source limit=15&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 20:06:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Receiving-a-Duplicate-labels-causing-conflict-error/m-p/132323#M7817</guid>
      <dc:creator>MichaelPriest</dc:creator>
      <dc:date>2020-09-28T20:06:51Z</dc:date>
    </item>
    <item>
      <title>Re: Receiving a Duplicate labels causing conflict error</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Receiving-a-Duplicate-labels-causing-conflict-error/m-p/132324#M7818</link>
      <description>&lt;P&gt;Finally, the &lt;CODE&gt;fields source&lt;/CODE&gt; in that search is unnecessary - &lt;CODE&gt;top&lt;/CODE&gt; on its own already returns only the source field &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 01 Jun 2015 09:38:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Receiving-a-Duplicate-labels-causing-conflict-error/m-p/132324#M7818</guid>
      <dc:creator>jeffland</dc:creator>
      <dc:date>2015-06-01T09:38:13Z</dc:date>
    </item>
    <item>
      <title>Re: Receiving a Duplicate labels causing conflict error</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Receiving-a-Duplicate-labels-causing-conflict-error/m-p/132325#M7819</link>
      <description>&lt;P&gt;Thanks very much&lt;/P&gt;</description>
      <pubDate>Mon, 01 Jun 2015 09:43:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Receiving-a-Duplicate-labels-causing-conflict-error/m-p/132325#M7819</guid>
      <dc:creator>MichaelPriest</dc:creator>
      <dc:date>2015-06-01T09:43:08Z</dc:date>
    </item>
    <item>
      <title>Re: Receiving a Duplicate labels causing conflict error</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Receiving-a-Duplicate-labels-causing-conflict-error/m-p/132326#M7820</link>
      <description>&lt;P&gt;Hello jeffland,&lt;/P&gt;

&lt;P&gt;So, I'm having the same problem with my search criteria as well. So, i was wondering if you could help out.&lt;BR /&gt;
For some reason - I get the same "duplicate values appearing" for some reason.Not sure what i'm doing wrong.&lt;BR /&gt;
here is my xml for your perusal:&lt;/P&gt;

&lt;P&gt;User Activity&lt;BR /&gt;
  Utilization by user activities&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;&amp;lt;input type="dropdown" token="user" searchWhenChanged="true"&amp;gt;
  &amp;lt;label&amp;gt;User_Activity_by_Time&amp;lt;/label&amp;gt;
  &amp;lt;search&amp;gt;
    &amp;lt;query&amp;gt;| pivot File_Server_Accessibility EventObject count(user) AS "Count of user" SPLITROW _time AS _time PERIOD minute SPLITCOL user FILTER user is * SORT 100 _time ROWSUMMARY 0 COLSUMMARY 0 NUMCOLS 50 SHOWOTHER 1 | search user!="NULL" | top 0 user  &amp;lt;/query&amp;gt;
    &amp;lt;earliest&amp;gt;-60m@m&amp;lt;/earliest&amp;gt;
    &amp;lt;latest&amp;gt;now&amp;lt;/latest&amp;gt;
  &amp;lt;/search&amp;gt;
  &amp;lt;fieldForLabel&amp;gt;user&amp;lt;/fieldForLabel&amp;gt; 
  &amp;lt;fieldForValue&amp;gt;user&amp;lt;/fieldForValue&amp;gt;   
  &amp;lt;choice value="*"&amp;gt;All&amp;lt;/choice&amp;gt;
  &amp;lt;default&amp;gt;*&amp;lt;/default&amp;gt;
&amp;lt;/input&amp;gt;
&amp;lt;input type="time" searchWhenChanged="true"&amp;gt;
  &amp;lt;label&amp;gt;&amp;lt;/label&amp;gt;
  &amp;lt;default&amp;gt;
    &amp;lt;earliest&amp;gt;-4h@m&amp;lt;/earliest&amp;gt;
    &amp;lt;latest&amp;gt;now&amp;lt;/latest&amp;gt;
  &amp;lt;/default&amp;gt;
&amp;lt;/input&amp;gt;



&amp;lt;panel&amp;gt;
  &amp;lt;title&amp;gt;User Activity: $user$&amp;lt;/title&amp;gt;
  &amp;lt;chart&amp;gt;
    &amp;lt;search&amp;gt;
      &amp;lt;query&amp;gt;| pivot File_Server_Accessibility EventObject count(user) AS "Count of user" SPLITROW _time AS _time PERIOD minute SPLITCOL user FILTER user is * SORT 100 _time ROWSUMMARY 0 COLSUMMARY 0 NUMCOLS 50 SHOWOTHER 1  &amp;lt;/query&amp;gt;
    &amp;lt;/search&amp;gt;
    &amp;lt;option name="charting.axisLabelsX.majorLabelStyle.overflowMode"&amp;gt;ellipsisNone&amp;lt;/option&amp;gt;
    &amp;lt;option name="charting.axisLabelsX.majorLabelStyle.rotation"&amp;gt;0&amp;lt;/option&amp;gt;
    &amp;lt;option name="charting.axisTitleX.visibility"&amp;gt;visible&amp;lt;/option&amp;gt;
    &amp;lt;option name="charting.axisTitleY.text"&amp;gt;Tx IN GBps&amp;lt;/option&amp;gt;
    &amp;lt;option name="charting.axisTitleY.visibility"&amp;gt;visible&amp;lt;/option&amp;gt;
    &amp;lt;option name="charting.axisTitleY2.visibility"&amp;gt;visible&amp;lt;/option&amp;gt;
    &amp;lt;option name="charting.axisX.scale"&amp;gt;linear&amp;lt;/option&amp;gt;
    &amp;lt;option name="charting.axisY.scale"&amp;gt;linear&amp;lt;/option&amp;gt;
    &amp;lt;option name="charting.axisY2.enabled"&amp;gt;false&amp;lt;/option&amp;gt;
    &amp;lt;option name="charting.axisY2.scale"&amp;gt;inherit&amp;lt;/option&amp;gt;
    &amp;lt;option name="charting.chart"&amp;gt;area&amp;lt;/option&amp;gt;
    &amp;lt;option name="charting.chart.bubbleMaximumSize"&amp;gt;50&amp;lt;/option&amp;gt;
    &amp;lt;option name="charting.chart.bubbleMinimumSize"&amp;gt;10&amp;lt;/option&amp;gt;
    &amp;lt;option name="charting.chart.bubbleSizeBy"&amp;gt;area&amp;lt;/option&amp;gt;
    &amp;lt;option name="charting.chart.nullValueMode"&amp;gt;zero&amp;lt;/option&amp;gt;
    &amp;lt;option name="charting.chart.sliceCollapsingThreshold"&amp;gt;0.01&amp;lt;/option&amp;gt;
    &amp;lt;option name="charting.chart.stackMode"&amp;gt;default&amp;lt;/option&amp;gt;
    &amp;lt;option name="charting.chart.style"&amp;gt;shiny&amp;lt;/option&amp;gt;
    &amp;lt;option name="charting.drilldown"&amp;gt;all&amp;lt;/option&amp;gt;
    &amp;lt;option name="charting.layout.splitSeries"&amp;gt;0&amp;lt;/option&amp;gt;
    &amp;lt;option name="charting.legend.labelStyle.overflowMode"&amp;gt;ellipsisMiddle&amp;lt;/option&amp;gt;
    &amp;lt;option name="charting.legend.placement"&amp;gt;right&amp;lt;/option&amp;gt;
    &amp;lt;option name="charting.axisTitleY.text"&amp;gt;number of loggers&amp;lt;/option&amp;gt;
  &amp;lt;/chart&amp;gt;
&amp;lt;/panel&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Tue, 25 Aug 2015 23:00:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Receiving-a-Duplicate-labels-causing-conflict-error/m-p/132326#M7820</guid>
      <dc:creator>idab</dc:creator>
      <dc:date>2015-08-25T23:00:55Z</dc:date>
    </item>
    <item>
      <title>Re: Receiving a Duplicate labels causing conflict error</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Receiving-a-Duplicate-labels-causing-conflict-error/m-p/132327#M7821</link>
      <description>&lt;P&gt;That's strange, &lt;CODE&gt;top&lt;/CODE&gt; should not return duplicate values. Have you had a look and run the search manually?&lt;/P&gt;</description>
      <pubDate>Wed, 26 Aug 2015 07:04:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Receiving-a-Duplicate-labels-causing-conflict-error/m-p/132327#M7821</guid>
      <dc:creator>jeffland</dc:creator>
      <dc:date>2015-08-26T07:04:40Z</dc:date>
    </item>
  </channel>
</rss>

