This is because Splunk is not encoding the search string properly within the XML source for the dashboard and leave the "?" or "&" characters in as actual characters.
Error message on SplunkWeb is "Unbalanced quotes."
This is an issue reported to Splunk, found to be outstanding in 7.2 & 7.3.
The workaround is , go and edit the xml view file, such as $SPLUNK_HOME/etc/users//local/data/ui/views/.xml
You can use this to get encoding values for characters - https://www.urlencoder.org. I.e) ? = %3F
This is an issue reported to Splunk, found to be outstanding in 7.2 & 7.3.
The workaround is , go and edit the xml view file, such as $SPLUNK_HOME/etc/users//local/data/ui/views/.xml
You can use this to get encoding values for characters - https://www.urlencoder.org. I.e) ? = %3F