Dashboards & Visualizations

Cannot identify unexpected close tag

kphansdge
Engager

Hi,

 

I am trying to make use of this dashboard from this forum thread:

Solved: Ever wonder which dashboards are being used and wh... - Splunk Community

but I am running into an error saying "Unexpected close tag" on this line:

 

<query>index="_internal" user!="-" sourcetype=splunkd_ui_access "en-US/app" | rex field=referer "en-US/app/(?<app>[^/]+)/(?<dashboard>[^?/\s]+)" | search dashboard!="job_management" dashboard!="dbinfo" dashboard!="*en-US" dashboard!="search" dashboard!="home"

 

Please advise.

 

Also I am adding this directly to the Source of a dashboard instead of a search is that right?

0 Karma
1 Solution

ITWhisperer
SplunkTrust
SplunkTrust

<query>index="_internal" user!="-" sourcetype=splunkd_ui_access "en-US/app" | rex field=referer "en-US/app/(?<app>[^/]+)/(?<dashboard>[^?/\s]+)" | search dashboard!="job_management" dashboard!="dbinfo" dashboard!="*en-US" dashboard!="search" dashboard!="home"

View solution in original post

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

It looks like this might be from the source view of the dashboard, in which case, the < and > in the rex expression should be converted to &lt; and &gt; respectively, or edit the search from ui mode and paste the search in?

0 Karma

kphansdge
Engager

@ITWhisperer wrote:

It looks like this might be from the source view of the dashboard, in which case, the < and > in the rex expression should be converted to &lt; and &gt; respectively, or edit the search from ui mode and paste the search in?


Thank you for your response. I'm looking at the code and I don't see <  and > in the rex expression could you please elaborate? I'm fairly new to coding

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

<query>index="_internal" user!="-" sourcetype=splunkd_ui_access "en-US/app" | rex field=referer "en-US/app/(?<app>[^/]+)/(?<dashboard>[^?/\s]+)" | search dashboard!="job_management" dashboard!="dbinfo" dashboard!="*en-US" dashboard!="search" dashboard!="home"

0 Karma

kphansdge
Engager

Thank you! It's working successfully. 🙂

0 Karma
Get Updates on the Splunk Community!

Introducing New Splunkbase Governance!

Splunk apps are essential for maximizing the value of your Splunk Experience. Whether you’re using the default ...

Splunk Edge Processor | Popular Use Cases to Get Started with Edge Processor

Splunk Edge Processor offers more efficient, flexible data transformation – helping you reduce noise, control ...

3 Ways to Make OpenTelemetry Even Better

My role as an Observability Specialist at Splunk provides me with the opportunity to work with customers of ...