All Apps and Add-ons

"Host Input" dropdown

andreibanaru
Explorer

The host input dropdown in the Netskope App shows an error that it "Cound not create search.".

By looking at the dashboard xml source we observe:

            <label>Host Input</label>
            <default>*</default>
            <choice value="*">All</choice>
            <search>
                <query>| `netskope_configured_inputs`</query>
                <earliest>$time_range.earliest$</earliest>
                <latest>$time_range.latest$</latest>
            </search>

If we remove the leading pipe (|) from the query the error is gone.

The dropdown will now show the FQDN of the Netskope server which feeds the events. I'm wondering if this is the expected behavior. I would have expected to see the computer names under this dropdown.

alt text

0 Karma

aplura_llc_supp
Communicator

v1.1.0 and v1.0.5 do contain this bug. The macro behind the dropdown was reconfigured, but this dropdown was missed. Look for a new maintenance release to fix this.

The app will also change from "Host Input" to something more clear, as it was intended to be the source Netskope tenant.

The macro should be changed to:

[netskope_configured_inputs]
definition = tstats count where sourcetype=netskope:* by host | fields host

Thanks!

0 Karma

aplura_llc_supp
Communicator

@andreibanaru v1.1.1 was released to fix that bug. Thanks.

0 Karma

aplura_llc_supp
Communicator

@andreibanaru What is the version you are using?

0 Karma

andreibanaru
Explorer

Version 1.0.5

0 Karma

aplura_llc_supp
Communicator

This bug is also present in v1.1.0, so it will be fixed in v1.1.1.

0 Karma

andreibanaru
Explorer

Yeah, we've just installed 1.1.0 and we have the same behavior.

0 Karma

dkeck
Influencer

HI,

depends on how your macro is set up, if it also starts with a pipe, its logical that it will not work if you have two.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Index This | What travels the world but is also stuck in place?

April 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Discover New Use Cases: Unlock Greater Value from Your Existing Splunk Data

Realizing the full potential of your Splunk investment requires more than just understanding current usage; it ...

Continue Your Journey: Join Session 2 of the Data Management and Federation Bootcamp ...

As data volumes continue to grow and environments become more distributed, managing and optimizing data ...