All Apps and Add-ons

Leading Pipe Search and forms

rmcdougal
Path Finder

I know that saved search macros have difficulties with leading pipes but what about forms? The reason I ask is I am attempting to create a form and I am finding it doesn't work.

Here is my form XML

<form>
  <label>AD Search</label>
  <searchTemplate><![CDATA[ |ldapsearch domain=AD search="(&(objectClass=user)(sAMAccountName=$username$))" | table sAMAccountName,personalTitle,displayName,givenName,sn,suffix,mail,telephoneNumber,mobile,manager,priority,department,category,watchlist,whenCreated,endDate]]>
    </searchTemplate>
  <fieldset>
      <input type="text" token="username" />
  </fieldset>
  <row>
      <event>
            <title>Results</title>
            <option name="count">50</option>
      </event>
  </row>
</form>

ahall_splunk
Splunk Employee
Splunk Employee

Firstly, remove the space from the beginning of the search. Secondly, you have not specified an earliest and latest - even though the search does not care what these are, they still need to be present. The search will not be dispatches without them.

ericrobinson
Path Finder

Anyone get an answer to this pipe question? It is also dropping for me as part of a form search

0 Karma

ahall_splunk
Splunk Employee
Splunk Employee

What version of Splunk are you using?

I'm also having an issue with v5.0.1 Simple XML - it doesn't like spaces at the beginning of the pipeline, so you may want to try removing that space at the start of your searchTemplate block.

0 Karma

lguinn2
Legend

That's pretty important for the rest of us to know!

0 Karma

rmcdougal
Path Finder
0 Karma

lguinn2
Legend

Have you written a custom command named ldapsearch? If so, it's probably something about the settings for that command.

If you haven't, then you shouldn't be starting your searchTemplate string with a |

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In January, the Splunk Threat Research Team had one release of new security content via the Splunk ES Content ...

Expert Tips from Splunk Professional Services, Ensuring Compliance, and More New ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Observability Release Update: AI Assistant, AppD + Observability Cloud Integrations & ...

This month’s releases across the Splunk Observability portfolio deliver earlier detection and faster ...