I have just upgraded to Splunk 6.0. When I do a form search it has completely different behaviour in comparison to Splunk 5.
In Splunk 5 blank fields were like behaving as if there was * in the search query and all results were returned. Now if I do the same thing in Splunk 6.0 I get this error:
Search query is not fully resolved.
Even when I just launch the view I get the same error.
Yes this is
Yeah this is a subtle change in the two versions
To work around use an empty default:
<input type="text" token="get3">
<label>Get from drilldown: Count</label>
<default></default>
</input>
I should have more accurately stated, this does solve the problem when searching, if I take * as the default, but the problem still remains on launching the form.
What is your xml?
This did not resolve the problem.
Is this view written in the <form>
flavor of Simple XML?