Dashboards & Visualizations

Query runs ok in dashboard but not in "New Search"

hamilton1979
Engager

Hi all,

I receive the following error when I try to run my query as a "New Search". The query runs fine without issue in my dashboard!

Error in 'eval' command: The expression is malformed. Expected ).

I've copied my query in below, replacing what could be deemed sensitive data with XXXXX.

index=XXXXXX sourcetype="XXXXXXXXX" uri_path = "/XXX/portal/screen/AjaxScreen/action/GetXXXXXX*" | bin _time span=10m | eval resp_time = mvindex(split(other," "),0) | eval resp_time_sec = (resp_time/1000000) | convert ctime(_time) as Time timeformat="%d%m %H"| stats perc50(resp_time_sec) as median_resp by _time | eval Critical = if(median_resp>4,median_resp,0) | eval Warning = if(median_resp>2.5 AND median_resp<=4 ,median_resp,0) | eval OK = if(median_resp<=2.5,median_resp,0) | table _time,Critical,Warning,OK

Could someone help shed some light why the behavior is different in the dashboard vs. Search?

Tags (1)
0 Karma

kamlesh_vaghela
SplunkTrust
SplunkTrust

@hamilton1979

Can you please share sample Panel code from your dashboard XML?

0 Karma
Get Updates on the Splunk Community!

What the End of Support for Splunk Add-on Builder Means for You

Hello Splunk Community! We want to share an important update regarding the future of the Splunk Add-on Builder ...

Solve, Learn, Repeat: New Puzzle Channel Now Live

Welcome to the Splunk Puzzle PlaygroundIf you are anything like me, you love to solve problems, and what ...

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...