Dashboards & Visualizations

Why does the dashboard show no data, but opening the saved search or running it manually produces results?

jvishwak
Path Finder

I'm not able to see saved search data in a dashboard, but when I open the the same search and manually execute the search, it's giving proper results. When I open the saved search, then it also shows the results.

Permissions and all are looking fine.

Any suggestions why this could be happening?

Tags (2)
0 Karma

renjith_nair
Legend

It's possible that you have search time field extraction and in that case you have to specify the fields explicitly in the search since dashboards runs in fastmode.

Another possibility is to add "" to your field names. Sometimes strings have to be quoted for splunk to identify , especially in dashboard xmls

---
What goes around comes around. If it helps, hit it with Karma 🙂

phadnett_splunk
Splunk Employee
Splunk Employee

Are there any messages in the UI that might help us determine why? Does this happen consistently, even during different times of the day?

0 Karma

sundareshr
Legend

Check job inspector for clues.

0 Karma
Get Updates on the Splunk Community!

CX Day is Coming!

Customer Experience (CX) Day is on October 7th!! We're so excited to bring back another day full of wonderful ...

Strengthen Your Future: A Look Back at Splunk 10 Innovations and .conf25 Highlights!

The Big One: Splunk 10 is Here!  The moment many of you have been waiting for has arrived! We are thrilled to ...

Now Offering the AI Assistant Usage Dashboard in Cloud Monitoring Console

Today, we’re excited to announce the release of a brand new AI assistant usage dashboard in Cloud Monitoring ...