Hi at all,
I noted that in all my forms with Post Process Search, the Export in CSV button is disabled, even if I force it with link.exportResults.visible=true option.
Anyone know if this is expected behavior or I have to modify something?
One workaround is to use loadjob:
Put this in your base search -
Then use -
| loadjob $baseid$ |
Not sure of the implications for search performance, but it ungrays your download button.
@aldonnelley thanks for your suggestion, I am already using something similar but with named scheduled search which is kind of stupid work-around (because of performance impact) but your idea seems slightly better.
I understand you are dynamically reloading the job resulting from the base search SID but I am not clear (from your explanation) how you do save base search SID into baseid token. Could you please clarify ?
Looks like the code block got stripped.
Set up the base search on your dashboard like this:
<search> <query> | myquerygoeshere </query> <done> <set token="sid">$job.sid$</set> </done> </search>
then use loadjob to load the base search and extend it as you wish.
@aldonnelley, I was very happy about your idea then I found an unexpected side effect...
In my case, "myquerygoeshere" does include misc. input tokens to dynamically filter dashboard content...
with your proposal, I just realised that the "done" event handler is only executed once. If I do change input contents, the base search is re-evaluated as expected... But "sid" token will stick to its original value.
Any idea how to work-around that ?
Note: I put the filtering logic here because it is common to many panels in my dashboard. So moving and duplicating filtering logic into each panel depending on this base search would not be good.
As of 01/2019, In Splunk 7.1.2,
Using Bases for Dashboard panel searches still breaks the export functionality.
This has been a known issue for at least three years.
Are there any plans to fix this feature @splunk ?
This is still an issue today.
Could this function, even if it has to run the search again? Perhaps a dashboard option to enable it, which is off by default? Please?
I don't think this is possible (i.e. you're seeing correct behavior). I believe I had read that somewhere, I just can't seem to find the source at the moment. Also see this older question, the topic discussed there is about Advanced XML, but I think it still applies.