Dashboards & Visualizations

403 Forbidden, Open in Search from Dashboard, Issues with Rex Command

bcatwork
Path Finder

Hi, I have a performance metrics dashboard created in simple-xml, all tables/charts must be accessible when selecting 'open in search'.

I have found that all search strings containing a rex command toss a 403 access forbidden error when I try to 'open in search'. All other visuals work as expected when opening in search. When deconstructing the URL and removing the rex commands, I am able to refresh and successfully route to the search app.

Here is an example of a field extraction I perform using the rex command.

rex field=_raw "DOMAIN: (?<DOMAIN>.*)"

Are there known issues involved with the rex command and simple-xml? This seems like a character issue (specifically <>)? In code, I use & lt; & gt ; (without spacing) to represent, these are converted to <> in the URI. I need them to stay as html character entities in the URI to successfully 'open in search', not be converted to <>.

Any thoughts or suggestions???

0 Karma
1 Solution

bcatwork
Path Finder

I found this issue has been resolved when upgrading to Splunk 6.2.

I never found a fix item that matched this issue description, but I imagine it was a known Splunk issue as it has been resolved.

View solution in original post

0 Karma

bcatwork
Path Finder

I found this issue has been resolved when upgrading to Splunk 6.2.

I never found a fix item that matched this issue description, but I imagine it was a known Splunk issue as it has been resolved.

0 Karma

splunkn
Communicator

Many thanks. But we have the upgraded version 6.2.3. But still no luck 😞

0 Karma

splunkn
Communicator

Any ideas regarding this. is it known Splunk issue?

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...