All Apps and Add-ons

Leading Pipe Search and forms

rmcdougal
Path Finder

I know that saved search macros have difficulties with leading pipes but what about forms? The reason I ask is I am attempting to create a form and I am finding it doesn't work.

Here is my form XML

<form>
  <label>AD Search</label>
  <searchTemplate><![CDATA[ |ldapsearch domain=AD search="(&(objectClass=user)(sAMAccountName=$username$))" | table sAMAccountName,personalTitle,displayName,givenName,sn,suffix,mail,telephoneNumber,mobile,manager,priority,department,category,watchlist,whenCreated,endDate]]>
    </searchTemplate>
  <fieldset>
      <input type="text" token="username" />
  </fieldset>
  <row>
      <event>
            <title>Results</title>
            <option name="count">50</option>
      </event>
  </row>
</form>

ahall_splunk
Splunk Employee
Splunk Employee

Firstly, remove the space from the beginning of the search. Secondly, you have not specified an earliest and latest - even though the search does not care what these are, they still need to be present. The search will not be dispatches without them.

ericrobinson
Path Finder

Anyone get an answer to this pipe question? It is also dropping for me as part of a form search

0 Karma

ahall_splunk
Splunk Employee
Splunk Employee

What version of Splunk are you using?

I'm also having an issue with v5.0.1 Simple XML - it doesn't like spaces at the beginning of the pipeline, so you may want to try removing that space at the start of your searchTemplate block.

0 Karma

lguinn2
Legend

That's pretty important for the rest of us to know!

0 Karma

rmcdougal
Path Finder
0 Karma

lguinn2
Legend

Have you written a custom command named ldapsearch? If so, it's probably something about the settings for that command.

If you haven't, then you shouldn't be starting your searchTemplate string with a |

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to December Tech Talks, Office Hours, and Webinars!

❄️ Celebrate the season with our December lineup of Community Office Hours, Tech Talks, and Webinars! ...

Splunk and Fraud

Watch Now!Watch an insightful webinar where we delve into the innovative approaches to solving fraud using the ...

Continuing Innovation & New Integrations Unlock Full Stack Observability For Your ...

You’ve probably heard the latest about AppDynamics joining the Splunk Observability portfolio, deepening our ...