We just upgraded to Splunk 8, and now when clicking "Show Source" in an Event Action, it goes to an error page. "Oops.
Looks like this view is using Advanced XML, which has been removed from Splunk Enterprise." It works in the "Search & Reporting" app, but not in our custom app we use (although I don't see any differences between the two). Any way to fix the link in the app?
Was this view written in Advanced XML by any chance? If it is the case, it was first deprecated in 6.3 years ago and it is now completely removed in Splunk 8.0. As a result, it has be rewritten in Simple XML in order to continue to function in Splunk 8.0.
I know, i've seen the doc. But how do i determine if it was written in advanced xml? It's not listed in the views, it's on the main search page.
Are you able to see the source of your dashboard?
SimpleXML is a subset of Advanced XML, so if you see any tags outside what is listed here,
chances are that it is in Advanced XML and has to be rewritten.
It looks like the "search" page is the one with the issue. I tried adding ?showsource to the end of my search page url, and at the end after doing a search, but it just refreshes the page.
When I click on Show Source in an event, a url similiar to this shows up briefly before going to the OOPS page:
Adding ?showsource to that link just directs to the OOPS page. Some of our "search" dashboards are broken too, but adding ?showsource just redirects to the OOPS page as well.
The "show source" links calls up a dashboard view that lives in
If you created your app as a copy of the native "search" app, and didn't remove the "default" directory-- then Splunk can't find the original showsource.xml
Removing the "default" directory (specifically /data/ui/views-- but you should also not have the other stuff from Search app in there), let's splunk find the correct file, which has system-wide visibility (so every app can use it).
Edit: that bit about the "advanced XML error"
Thanks to @nick for pointing out--the showsource.xml view has been updated in more recent versions of Splunk, but copying it explicitly from an older version as I had is why specifically that error shows up.
Thanks so much! There were some customizations in the default folder that i wasn't sure if were safe to delete. Deleting the data folder didn't work, so i copied the views from the search app to our custom app. Now "Show Source" works. Still have a few dashboards throwing the error, but at least making progress.
If you have customizations, they should be in /local...if not, perhaps you can move them there?
You could try just cp-ing off the default folder to a tmp folder, and see how that goes?
Tried that, and show source stopped working. Removed the default and local folders from the app, and show source still wouldn't work.