Dashboards & Visualizations

Why are the two base searches throw warnings in a dashboard?


I have two base searches in a dashboard, not sure if that is at all possible. But as soon as i use the second base search created, i get warnings with this :


Warning is : Unknown node is not allowed here. Before creating the second base search this warning was not existing.


I think i found the mistake, I should be using the timer tokens only in the base search whereas i was using in all the sub searches 🙂

Super Champion

You're exactly right, @macadminrohit . Base searches only require earliest and latest in the base search itself and do not expect them to be called out in any of the searches referencing them. I will move your comment to an answer if you'd like to accept it and close out the question.


I think the time picker should also be included in your base search. So that its something like this. What do you currently have?

"base search query"



Get Updates on the Splunk Community!

Splunk Observability Cloud | Unified Identity - Now Available for Existing Splunk ...

Raise your hand if you’ve already forgotten your username or password when logging into an account. (We can’t ...

Index This | How many sides does a circle have?

February 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

Registration for Splunk University is Now Open!

Are you ready for an adventure in learning?   Brace yourselves because Splunk University is back, and it's ...