Dashboards & Visualizations

Unable to save log view from Log Observer

b0lle
Engager

Hey, 

I recently wanted to add a new log-view to an existing Dashboard at which I own. So, from the Log Oberserver, I created the query, clicked "Save" -> "Save to Dashboard", selected my Dashboard, activated the "Log View" radio button and clicked "Save an go to Dashboard".

This is the error I am facing: "Alert
Chart cannot be saved to the selected dashboard. Check your permissions and try again. If the problem persists, contact support."

I checked those permissions on the Dashboard and those are "Everyone can read or write".

Has anyone an idea whats going on and how to solve this issue?

Thanks!

Labels (1)
0 Karma

b0lle
Engager

anyone?

I also contacted Splunk Support some weeks ago and got no response

0 Karma

livehybrid
SplunkTrust
SplunkTrust

Hi @b0lle 

Is it possible for you to view the Developer Console for your browser and select the Network tab. When you click the button to save the panel to the dashboard can you see the API call being made? Can you check what the response is that is returned? It might give a bit more information.

🌟 Did this answer help you? If so, please consider:

  • Adding karma to show it was useful
  • Marking it as the solution if it resolved your issue
  • Commenting if you need any clarification

Your feedback encourages the volunteers in this community to continue contributing

b0lle
Engager

Hey, 

the response is: {
"code" : 400,
"message" : "Column name cannot be null or empty"
}

With this knowledge I deselected my columns one by one and found out that I can create the log-view in a dashboard, but only with the default columns "time" and "severity". If I try to select any of my custom columns it throws the mentioned error.

 

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Developer Spotlight with Denis Gladkikh

From Splunk Engineer to Kubernetes App Builder Denis GladkikhWhat happens when a lifelong developer turns a ...

Governing Enterprise AI, Bringing Cisco Telemetry Home, and More from Splunk Lantern

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...