Dashboards & Visualizations

Why "done" tag is disappeared when I edit panel's search in UI.

yutaka1005
Builder

I created dashboard has two panels like below.

  1. Panel displaying results in table view
  2. Panel showing the count of result of panel1

To display Panel2, I use the <done> ~ </done> tag in the source of Panel1 like below.

<done><eval token="arg1">$job.resultCount$</eval></done>

However, editing the search in the panel1 on the UI editing screen will cause the <done> ~ </done> tag to disappear.

Why is it happen?
Is there a workaround?

If anyone knows, it would be greatly appreciated if you could tell me.

1 Solution

AKG1_old1
Builder

This is a bug in Splunk. Any sections like done,finalized,progress,error are getting disappeared when edit through GUI. I have logged bug to Splunk under "SPL-147251".

View solution in original post

0 Karma

AKG1_old1
Builder

This is a bug in Splunk. Any sections like done,finalized,progress,error are getting disappeared when edit through GUI. I have logged bug to Splunk under "SPL-147251".

0 Karma

yutaka1005
Builder

Thank you for answering!

Do you mean that you reported a bug to Splunk? Or is it already registered as Known Issues?

Also, as a result of contacting support, etc., did you know that it was a bug?

0 Karma

AKG1_old1
Builder

yeah, I have reported it to Splunk and they have acknowledged it as bug . I 'll follow up on this bug.

0 Karma

AKG1_old1
Builder

Guys, This issue has been fixed in Enterprise 7.0.3

gowtham495
Path Finder

@agoyal thank you. I am having same issue. is there any workaround instead of updating to v7.0.3

(Actually, my second panel depends on token from first panel)

0 Karma

yutaka1005
Builder

When I edited the search from source, the <done> tag did not disappear.
Is this the only workaround?

0 Karma

niketn
Legend

I have also noticed this issue intermittently in 7.0. What version are you using? You can add a Bug tag to this question and if you have valid Splunk Entitlement you can reach out to Splunk Support.

____________________________________________
| makeresults | eval message= "Happy Splunking!!!"
0 Karma

yutaka1005
Builder

I noticed this issue in ver 7.0 and 6.6.3.

Perhaps, I think that the corresponding department related to the web framework is not Splunk support.
So we need to wait for someone inside Splunk to mention about this issue.

0 Karma

AKG1_old1
Builder

It's been fixed in 7.0.3

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

What Is Splunk? Here’s What You Can Do with Splunk

Hey Splunk Community, we know you know Splunk. You likely leverage its unparalleled ability to ingest, index, ...

Level Up Your .conf25: Splunk Arcade Comes to Boston

With .conf25 right around the corner in Boston, there’s a lot to look forward to — inspiring keynotes, ...

Manual Instrumentation with Splunk Observability Cloud: How to Instrument Frontend ...

Although it might seem daunting, as we’ve seen in this series, manual instrumentation can be straightforward ...