All Apps and Add-ons

Status Indicator not working fine

giorgiovolpini
New Member

Hi,

we have a strange behaviour with status indicator visualization on a dashboard.

We have two status indicator with the same search, but the first use a base search for the first part of the search (eg: index=main).

The first visualize the status indicator with a color and the second with another color, but if i open the searches they have the same result set.

Is it a bug or we have to set something?

Thank you

0 Karma

giorgiovolpini
New Member

Hi,

I found the problem: the base search was index=myindex; but using this kind of search in a base search there is a limit about the number of fields. So I added "| fields myfield1 myfield2" after the first part, where myfield1 and myfield2 are the fields used in the sub-searches that populate status indicators.

So, i solved 🙂

Bye

0 Karma

niketn
Legend

@giorgiovolpini please accept your own answer to mark this question as answered.

PS: Be aware that Status Indicator with Post Process search where base search returns too many results may lead to truncated result.

____________________________________________
| makeresults | eval message= "Happy Splunking!!!"
0 Karma

efavreau
Motivator

@giorgiovolpini Please show the XML involved with both panels.

###

If this reply helps you, an upvote would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...