Dashboards & Visualizations

Debugging dashboard queries

lassel
Communicator

I am working on a dashboard with dynamic input fields.
It would be very useful to see the actual query that Splunk is running, based on my input fields.

Is it possible to display the query?

0 Karma
1 Solution

jeffland
SplunkTrust
SplunkTrust

One way to do it is go to Activity -> Jobs which will show you the recent searches.

View solution in original post

Runals
Motivator

Are you wanting to see the query dynamically within the dashboard for people using it OR are you asking more from a troubleshooting perspective? For troubleshooting what I tend to do is adjust my inputs in order to get the query to run and then click the magnifying glass in the lower left corner of the dashboard panel. That opens the query into another browser tab and allows me to see what Splunk is trying to run.

lassel
Communicator

I like this answer too!

0 Karma

jeffland
SplunkTrust
SplunkTrust

One way to do it is go to Activity -> Jobs which will show you the recent searches.

vganjare
Builder

You can check the actual query ran in Job Inspector. It is present in Search Properties under eventSearch

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...