Getting Data In

Event: Show source loading ....

chrisitanmoleck
Path Finder

Hello,

if I try to show the source of an event, splunk shows only "loading ...".
I took care, that the result is finalized.

We are using Splunk 8.0.1.

Edit:
I start a search with "host=..." and time=last 24h
I open an event -> event actions -> show source (event.png)
Now the loading screen will not display any result/source, just "loading ...." (show-source.png)

chrisitanmoleck
Path Finder

Splunk support:
The Bug is solved on the next version that should be 8.0.2.
So the option would be to upgrade Splunk whenever this release comes out, we do not have an estimated date at the moment.

chrisitanmoleck
Path Finder

After updating to 8.0.2, the problem is solved!

niketn
Legend

@chrisitanmolecki would it be possible for you to elaborate your issue? How, where and what is the issue? If possible please attach screenshots.

____________________________________________
| makeresults | eval message= "Happy Splunking!!!"

las
Contributor

We see the exact same problem also on 8.0.1
@chrisitanmolecki have you opened a case with support?

las
Contributor

We are using windows Server 2016, that might have an impact

0 Karma

chrisitanmoleck
Path Finder

@las
We are using Suse Linux Enterprise Server 12 Sp4

0 Karma

niketn
Legend

So if both of you have same issue, even though I am not able to re-produce, this still seems like a bug. Work with Splunk Support! Do let us know the outcome.

____________________________________________
| makeresults | eval message= "Happy Splunking!!!"

chrisitanmoleck
Path Finder

@niketnilay
OK I will contact the support.
Cheers mate

0 Karma

chrisitanmoleck
Path Finder

@las No we haven't.

0 Karma

niketn
Legend

@chrisitanmolecki I tried the same and I was able to see the raw data under Show Source. I am also on 8.0.1. I had tried index=_internal host=*.

What is the exact query you have run?
Also how many events did you have?
Did you click on Show Source after you had pulled all the events?
Have you tried with index= and searching with shorter duration or may be with | head 1 to see Show Source works for you?
How about changing browsers to test?

____________________________________________
| makeresults | eval message= "Happy Splunking!!!"

chrisitanmoleck
Path Finder

@niketnilay

index=_internal host=* 

Not working

What is the exact query you have run?

host=foo

The issue occurs at every host

Also how many events did you have?
Thats very different. From a few to several thousands.

Did you click on Show Source after you had pulled all the events?
No I pulled at out just one event

Have you tried with index= and searching with shorter duration or may be with | head 1 to see Show Source works for you?
That change nothing

How about changing browsers to test?
Same at IE11, FF65.0 and GC78.0

0 Karma

chrisitanmoleck
Path Finder

@niketnilay Now it should be more expressive

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Build the Future of Agentic AI: Join the Splunk Agentic Ops Hackathon

AI is changing how teams investigate incidents, detect threats, automate workflows, and build intelligent ...

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...