All Apps and Add-ons

Status Indicator not working fine

giorgiovolpini
New Member

Hi,

we have a strange behaviour with status indicator visualization on a dashboard.

We have two status indicator with the same search, but the first use a base search for the first part of the search (eg: index=main).

The first visualize the status indicator with a color and the second with another color, but if i open the searches they have the same result set.

Is it a bug or we have to set something?

Thank you

0 Karma

giorgiovolpini
New Member

Hi,

I found the problem: the base search was index=myindex; but using this kind of search in a base search there is a limit about the number of fields. So I added "| fields myfield1 myfield2" after the first part, where myfield1 and myfield2 are the fields used in the sub-searches that populate status indicators.

So, i solved 🙂

Bye

0 Karma

niketn
Legend

@giorgiovolpini please accept your own answer to mark this question as answered.

PS: Be aware that Status Indicator with Post Process search where base search returns too many results may lead to truncated result.

____________________________________________
| makeresults | eval message= "Happy Splunking!!!"
0 Karma

efavreau
Motivator

@giorgiovolpini Please show the XML involved with both panels.

###

If this reply helps you, an upvote would be appreciated.
0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...