Dashboards & Visualizations

Dashboard issues - search runs in search window, not in dashboard as an inline string.

bwakely
Explorer

Greetings all,

I've set up the splunk DB connect app (v.117),
I can query an MSSQL database / explore schema.

I can run a search command, example:
|dbquery "MYDB" limit =1000 "select 1"

I cannot get any results returned when I embed this as an inline search into a dashboard panel.
Can someone explain why a saved search works while an inline search doesn't?

(I also can't get '|metatdata hosts' working as an inline string...)

--Benji

Tags (3)

unixadmins
Engager

Poked at it more as a response to your question, and yes, I've found out what's causing it.

With the simple search "|metadata hosts" as an example:

With the visualization type set to "Events", the panel displays "Search did not return any events."
If you change the visualization type to "Statistics", it will happily display data as you'd expect.

I'm not sure of the reason why the output of |commands counts as "statistics" rather than "events",
but that would seem to be the case.

I'm going to put that down as "Confusing, but working as designed."

--Benji

landen99
Motivator

Confirming that a | dbquery search returned "Search did not return any events." while set to show as "events" but resolved when set to "statistics".

nawneel
Communicator

I also had this issue with |dbquery and it resolved as per @unixadmins's suggestions

0 Karma

edrivera3
Builder

I am having the same problem. Do you solve it? I tried to change all quotation marks to " but that didn't change anything.

0 Karma
Get Updates on the Splunk Community!

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...