Dashboards & Visualizations

403 Forbidden, Open in Search from Dashboard, Issues with Rex Command

bcatwork
Path Finder

Hi, I have a performance metrics dashboard created in simple-xml, all tables/charts must be accessible when selecting 'open in search'.

I have found that all search strings containing a rex command toss a 403 access forbidden error when I try to 'open in search'. All other visuals work as expected when opening in search. When deconstructing the URL and removing the rex commands, I am able to refresh and successfully route to the search app.

Here is an example of a field extraction I perform using the rex command.

rex field=_raw "DOMAIN: (?<DOMAIN>.*)"

Are there known issues involved with the rex command and simple-xml? This seems like a character issue (specifically <>)? In code, I use & lt; & gt ; (without spacing) to represent, these are converted to <> in the URI. I need them to stay as html character entities in the URI to successfully 'open in search', not be converted to <>.

Any thoughts or suggestions???

0 Karma
1 Solution

bcatwork
Path Finder

I found this issue has been resolved when upgrading to Splunk 6.2.

I never found a fix item that matched this issue description, but I imagine it was a known Splunk issue as it has been resolved.

View solution in original post

0 Karma

bcatwork
Path Finder

I found this issue has been resolved when upgrading to Splunk 6.2.

I never found a fix item that matched this issue description, but I imagine it was a known Splunk issue as it has been resolved.

0 Karma

splunkn
Communicator

Many thanks. But we have the upgraded version 6.2.3. But still no luck 😞

0 Karma

splunkn
Communicator

Any ideas regarding this. is it known Splunk issue?

0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk, and empower your SOC to reach new heights! Duration: 1 hour  Prepare to ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...