Splunk Search

Chart does not appear the same on a report?

Dark_Ichigo
Builder

when writing a search to create a chart, We all then tend to integrate it into a dashboard as a report.
My problem is that when I click "Show Chart" I get what I want, but when I add it to the dashboard as a report I dont get the same result even though my Advanced XML code only contains code for charting and no other extras added to not complicate things even more because of this issue.

0 Karma
1 Solution

Dark_Ichigo
Builder

Found the issue, apparently there was a Single value Module that was in the way of the above "ConvertToIntention" modules, this led to some values of a number of fields, were not successfully delivered to the search Macro to generate the desired chart.

View solution in original post

0 Karma

Dark_Ichigo
Builder

Found the issue, apparently there was a Single value Module that was in the way of the above "ConvertToIntention" modules, this led to some values of a number of fields, were not successfully delivered to the search Macro to generate the desired chart.

0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk, and empower your SOC to reach new heights! Duration: 1 hour  Prepare to ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...