Dashboards & Visualizations

How to prevent Splunk from removing spaces in dashboard searches?

New Member

Hi Everyone,

I have problem with search command in dashboard panel.

When I put below search:

source=isp_portal Message="Request Url - http*"

it works then I save dashboards

After saving the search, it does not work and look like below (without space)

source=isp_portal Message="Request Url-http*"

What should I set to prevent removing spaces in searches?

Thanks in advance for help

0 Karma

Contributor

For your dashboard try replacing space with

source=isp_portal Message="Request Url - http*"

New Member

Hi cmeriman,

Splunk Version ............................................6.5.1S
Splunk Build ............................................f74036626f0c

Firstt i put Reports (with search which works) into dashboard ( Panel powered by Inline Search).
After couple of minutes , when I refreshing dashboard the reports does not presented data.
Then I click Edit Search in particular reports in dashboard and I see search string without spaces.

0 Karma

Super Champion

If you have the search saved as a report and it is working, why not keep it as a report in the dashboard panel instead of an inline search? Otherwise have you tried editing the search to put the spaces back in? I've never had a problem before, but I normally keep reports as reports in my dashboard panels instead of converting them.

0 Karma

Super Champion

what version of Splunk are you on? Did you save it to a dashboard from the search bar or create a new search while editing a dashboard?

0 Karma