All Apps and Add-ons

dbxlookup not working in dashboard.

ocallender
Explorer

I created a search that uses a dbxlookup command to populate various fields and output a table. This works perfectly in search, but when I add it to a dashboard, all of the lookup fields are empty. The search string is exactly the same.

Has anyone else experienced this?

0 Karma

ocallender
Explorer

Was doing some testing to see what shows up in the logs. I noticed that when i click "open in Search" from the dashboard panel, the dbx fields didn't show until I selected verbose mode.

I found this post: https://answers.splunk.com/answers/368700/how-to-get-searches-to-run-in-smart-or-verbose-mod.html and someone sugessted using | fields * to force verbose mode in the dashboard. It worked for me. I'm getting the lookup fields now.

0 Karma

woodcock
Esteemed Legend

Don't forget to click Answer to close your question.

0 Karma

davebrooking
Contributor

My initial thought is that this sounds like it may be a permissions related issue.
What version of DBConnect are you running?
Have you checked the DBConnect logs for entries relating to the dbxlookup command? Whatever version of DBConnect you're running check the Troubleshooting section of the documentation to see what is logged and where.
Have you tried setting the DBConnect logging to DEBUG?

Is the dashboard in the same app as your working dbxlookup search?

Dave

somesoni2
Revered Legend

+1 on last question.

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...