Splunk Enterprise

Help with Base search / Dashboard studio?

anissabnk
Path Finder

Hello everyone, 

 

I have a question with base search in Splunk Dashboard Studio. 

I used this option to made my parent search and my chain search : 

anissabnk_0-1675180861146.png

For example, I create this search, which used the base search : SI_bs_nb_de_pc

anissabnk_1-1675180954187.png

However, I have a problem with thoses errors: 

anissabnk_2-1675181017564.png*

anissabnk_3-1675181091340.png

Can you help me please ?

An other quetsion, how to use multiple base search in a same search ? I didn't find an issue to do this in Dashboard Studio 

I need your help , thank you so much 

Labels (2)
0 Karma
Get Updates on the Splunk Community!

Message Parsing in SOCK

Introduction This blog post is part of an ongoing series on SOCK enablement. In this blog post, I will write ...

Exploring the OpenTelemetry Collector’s Kubernetes annotation-based discovery

We’ve already explored a few topics around observability in a Kubernetes environment -- Common Failures in a ...

Use ‘em or lose ‘em | Splunk training units do expire

Whether it’s hummus, a ham sandwich, or a human, almost everything in this world has an expiration date. And, ...