Dashboards & Visualizations

Chained Searches in a Dashboard

raidercom
Communicator

Hi:

I am testing out the new dashboard options with Dashboard Studio, and I am a bit confused as to how a feature works.  I want to use a base search 'index=nginx source="/var/log/nginx/access.log"', I have that setup in DataSource.  I then want to chain that to multiple modifiers.  For this end, I added a Chain search '| stats count by status', linked to the Parent Search above, I also created another chain search '| search splunk*' for some testing.

If I create a dashboard panel graph (pie), and link it to the stats search, it says it can't find any data 'Search ran successfully, but no results were returned'.  If I click the magnifying glass from that, it returns results.

If I have a table panel, and use the splunk search chain search, it finds results.  If I have a chained search that uses '| search site=splunk*', despite that field existing, it finds no results, but the magnifying glass does.  Can auto extracted fields not be used in this manner?

The data in the source logs are all in the format <key>="value" for easy auto extraction of the fields.

Thank you for any assistance/information you can provide.

Labels (3)
0 Karma
1 Solution

raidercom
Communicator

Found the issue

Didn't notice this one line in the documentation:

If the base search is a non-transforming search, you must explicitly state in the base search what fields will be used in the chain search using the fields command.

from https://docs.splunk.com/Documentation/Splunk/8.2.1/DashStudio/dsChain

View solution in original post

0 Karma

raidercom
Communicator

Found the issue

Didn't notice this one line in the documentation:

If the base search is a non-transforming search, you must explicitly state in the base search what fields will be used in the chain search using the fields command.

from https://docs.splunk.com/Documentation/Splunk/8.2.1/DashStudio/dsChain

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Take Action Automatically on Splunk Alerts with Red Hat Ansible Automation Platform

 Are you ready to revolutionize your IT operations? As digital transformation accelerates, the demand for ...

Calling All Security Pros: Ready to Race Through Boston?

Hey Splunkers, .conf25 is heading to Boston and we’re kicking things off with something bold, competitive, and ...

Beyond Detection: How Splunk and Cisco Integrated Security Platforms Transform ...

Financial services organizations face an impossible equation: maintain 99.9% uptime for mission-critical ...