<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Dashboard panel in Reporting</title>
    <link>https://community.splunk.com/t5/Reporting/Dashboard-panel/m-p/508712#M8217</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/214410"&gt;@isoutamo&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;When I am running the following query in verbose mode it giving me results but not in fast mode.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;index=symantec sourcetype=sep12:scan status=completed | stats count&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;As Dashboard panel uses fast mode.What necessary modification do I need to do to get the results in fast mode.&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Rahul&lt;/P&gt;</description>
    <pubDate>Mon, 13 Jul 2020 01:42:25 GMT</pubDate>
    <dc:creator>rahul2gupta</dc:creator>
    <dc:date>2020-07-13T01:42:25Z</dc:date>
    <item>
      <title>Dashboard panel</title>
      <link>https://community.splunk.com/t5/Reporting/Dashboard-panel/m-p/508712#M8217</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/214410"&gt;@isoutamo&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;When I am running the following query in verbose mode it giving me results but not in fast mode.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;index=symantec sourcetype=sep12:scan status=completed | stats count&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;As Dashboard panel uses fast mode.What necessary modification do I need to do to get the results in fast mode.&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Rahul&lt;/P&gt;</description>
      <pubDate>Mon, 13 Jul 2020 01:42:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/Dashboard-panel/m-p/508712#M8217</guid>
      <dc:creator>rahul2gupta</dc:creator>
      <dc:date>2020-07-13T01:42:25Z</dc:date>
    </item>
    <item>
      <title>Re: Dashboard panel</title>
      <link>https://community.splunk.com/t5/Reporting/Dashboard-panel/m-p/508721#M8218</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/222802"&gt;@rahul2gupta&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It's normally because of the extracted fields. Use "|fields " to explicitly specify the field&lt;/P&gt;&lt;P&gt;Try&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=symantec sourcetype=sep12:scan |fields status|where status=completed |stats count&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 13 Jul 2020 05:19:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/Dashboard-panel/m-p/508721#M8218</guid>
      <dc:creator>renjith_nair</dc:creator>
      <dc:date>2020-07-13T05:19:16Z</dc:date>
    </item>
    <item>
      <title>Re: Dashboard panel</title>
      <link>https://community.splunk.com/t5/Reporting/Dashboard-panel/m-p/508728#M8219</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/136781"&gt;@renjith_nair&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;I tried but it did not worked.Please find the screen shot below.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="rahul2gupta_0-1594618015069.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/9643iFFCE4316BFE4806A/image-size/medium?v=v2&amp;amp;px=400" role="button" title="rahul2gupta_0-1594618015069.png" alt="rahul2gupta_0-1594618015069.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="rahul2gupta_1-1594618092608.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/9644i9BB278C0D0CBA0AD/image-size/medium?v=v2&amp;amp;px=400" role="button" title="rahul2gupta_1-1594618092608.png" alt="rahul2gupta_1-1594618092608.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="rahul2gupta_2-1594618130946.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/9645i5655ECE9C1AAE2DD/image-size/medium?v=v2&amp;amp;px=400" role="button" title="rahul2gupta_2-1594618130946.png" alt="rahul2gupta_2-1594618130946.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Rahul&lt;/P&gt;</description>
      <pubDate>Mon, 13 Jul 2020 05:29:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/Dashboard-panel/m-p/508728#M8219</guid>
      <dc:creator>rahul2gupta</dc:creator>
      <dc:date>2020-07-13T05:29:25Z</dc:date>
    </item>
    <item>
      <title>Re: Dashboard panel</title>
      <link>https://community.splunk.com/t5/Reporting/Dashboard-panel/m-p/508731#M8221</link>
      <description>&lt;P&gt;Can you try this in fast mode and see if you are getting events with status?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=symantec sourcetype="sep12:scan" status=*&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;OR&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=symantec sourcetype="sep12:scan" |fields *&lt;/LI-CODE&gt;</description>
      <pubDate>Mon, 13 Jul 2020 05:41:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/Dashboard-panel/m-p/508731#M8221</guid>
      <dc:creator>renjith_nair</dc:creator>
      <dc:date>2020-07-13T05:41:27Z</dc:date>
    </item>
    <item>
      <title>Re: Dashboard panel</title>
      <link>https://community.splunk.com/t5/Reporting/Dashboard-panel/m-p/508738#M8222</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/136781"&gt;@renjith_nair&lt;/a&gt;&amp;nbsp;.&lt;/P&gt;&lt;P&gt;I ran the following query&amp;nbsp;&lt;STRONG&gt;index=symantec sourcetype="sep12:scan" |fields * &lt;/STRONG&gt;and I could able to get events in fast mode.&lt;/P&gt;&lt;P&gt;Please find the screen shot below.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="dash.PNG" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/9646iE176A3056D041E8E/image-size/large?v=v2&amp;amp;px=999" role="button" title="dash.PNG" alt="dash.PNG" /&gt;&lt;/span&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;But it did not worked for&amp;nbsp;&lt;STRONG&gt;index=symantec sourcetype="sep12:scan" status=*&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="dash1.PNG" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/9647i7D34A38184D717CC/image-size/large?v=v2&amp;amp;px=999" role="button" title="dash1.PNG" alt="dash1.PNG" /&gt;&lt;/span&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Rahul&lt;/P&gt;</description>
      <pubDate>Mon, 13 Jul 2020 06:34:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/Dashboard-panel/m-p/508738#M8222</guid>
      <dc:creator>rahul2gupta</dc:creator>
      <dc:date>2020-07-13T06:34:18Z</dc:date>
    </item>
    <item>
      <title>Re: Dashboard panel</title>
      <link>https://community.splunk.com/t5/Reporting/Dashboard-panel/m-p/508747#M8223</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/222802"&gt;@rahul2gupta&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;So you might have multiple field extraction and hence it needs explicit mention about fields&lt;/P&gt;&lt;P&gt;So you may use&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=symantec sourcetype="sep12:scan" |fields * 
|where status="completed"&lt;/LI-CODE&gt;</description>
      <pubDate>Mon, 13 Jul 2020 07:32:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/Dashboard-panel/m-p/508747#M8223</guid>
      <dc:creator>renjith_nair</dc:creator>
      <dc:date>2020-07-13T07:32:56Z</dc:date>
    </item>
    <item>
      <title>Re: Dashboard panel</title>
      <link>https://community.splunk.com/t5/Reporting/Dashboard-panel/m-p/508748#M8224</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/136781"&gt;@renjith_nair&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;I used the following query&amp;nbsp;index=symantec sourcetype=sep12:scan status=completed |fields * |stats count&lt;/P&gt;&lt;P&gt;and it worked.&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Rahul&lt;/P&gt;</description>
      <pubDate>Mon, 13 Jul 2020 07:45:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/Dashboard-panel/m-p/508748#M8224</guid>
      <dc:creator>rahul2gupta</dc:creator>
      <dc:date>2020-07-13T07:45:55Z</dc:date>
    </item>
  </channel>
</rss>

