Dashboards & Visualizations

Unable to save log view from Log Observer

b0lle
Engager

Hey, 

I recently wanted to add a new log-view to an existing Dashboard at which I own. So, from the Log Oberserver, I created the query, clicked "Save" -> "Save to Dashboard", selected my Dashboard, activated the "Log View" radio button and clicked "Save an go to Dashboard".

This is the error I am facing: "Alert
Chart cannot be saved to the selected dashboard. Check your permissions and try again. If the problem persists, contact support."

I checked those permissions on the Dashboard and those are "Everyone can read or write".

Has anyone an idea whats going on and how to solve this issue?

Thanks!

Labels (1)
0 Karma

b0lle
Engager

anyone?

I also contacted Splunk Support some weeks ago and got no response

0 Karma

livehybrid
SplunkTrust
SplunkTrust

Hi @b0lle 

Is it possible for you to view the Developer Console for your browser and select the Network tab. When you click the button to save the panel to the dashboard can you see the API call being made? Can you check what the response is that is returned? It might give a bit more information.

🌟 Did this answer help you? If so, please consider:

  • Adding karma to show it was useful
  • Marking it as the solution if it resolved your issue
  • Commenting if you need any clarification

Your feedback encourages the volunteers in this community to continue contributing

b0lle
Engager

Hey, 

the response is: {
"code" : 400,
"message" : "Column name cannot be null or empty"
}

With this knowledge I deselected my columns one by one and found out that I can create the log-view in a dashboard, but only with the default columns "time" and "severity". If I try to select any of my custom columns it throws the mentioned error.

 

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...