Dashboards & Visualizations

Cannot identify unexpected close tag

kphansdge
Engager

Hi,

 

I am trying to make use of this dashboard from this forum thread:

Solved: Ever wonder which dashboards are being used and wh... - Splunk Community

but I am running into an error saying "Unexpected close tag" on this line:

 

<query>index="_internal" user!="-" sourcetype=splunkd_ui_access "en-US/app" | rex field=referer "en-US/app/(?<app>[^/]+)/(?<dashboard>[^?/\s]+)" | search dashboard!="job_management" dashboard!="dbinfo" dashboard!="*en-US" dashboard!="search" dashboard!="home"

 

Please advise.

 

Also I am adding this directly to the Source of a dashboard instead of a search is that right?

0 Karma
1 Solution

ITWhisperer
SplunkTrust
SplunkTrust

<query>index="_internal" user!="-" sourcetype=splunkd_ui_access "en-US/app" | rex field=referer "en-US/app/(?<app>[^/]+)/(?<dashboard>[^?/\s]+)" | search dashboard!="job_management" dashboard!="dbinfo" dashboard!="*en-US" dashboard!="search" dashboard!="home"

View solution in original post

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

It looks like this might be from the source view of the dashboard, in which case, the < and > in the rex expression should be converted to &lt; and &gt; respectively, or edit the search from ui mode and paste the search in?

0 Karma

kphansdge
Engager

@ITWhisperer wrote:

It looks like this might be from the source view of the dashboard, in which case, the < and > in the rex expression should be converted to &lt; and &gt; respectively, or edit the search from ui mode and paste the search in?


Thank you for your response. I'm looking at the code and I don't see <  and > in the rex expression could you please elaborate? I'm fairly new to coding

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

<query>index="_internal" user!="-" sourcetype=splunkd_ui_access "en-US/app" | rex field=referer "en-US/app/(?<app>[^/]+)/(?<dashboard>[^?/\s]+)" | search dashboard!="job_management" dashboard!="dbinfo" dashboard!="*en-US" dashboard!="search" dashboard!="home"

0 Karma

kphansdge
Engager

Thank you! It's working successfully. 🙂

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Data Management Digest – August 2026

MichelleCorpora_1-1788182384472.png Welcome to the August 2026 edition of Data Management Digest! August was a ...

Your Feedback. Our Roadmap. Visit the PX Feedback Booth at .conf26

You use Splunk every day, come and help shape what's next.  Save Your Seat: Product-Focused Sessions at ...

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...