Splunk Search

Error on search when using table

larryaucoin
Observer

Since upgrading to 9.1.2, I am no longer able to see table output on the Splunk Search.  Even with the most simplistic search.  I receive the message "Failed to load source for Statistics Table visualization."

I am able to see "Events" and also able to use "fields", just not table.  Note that this works when viewing in a Studio Dashboard, so the issue seems to be limited to the Search app.

Labels (1)
0 Karma

IgorBR
Engager

I'm sure you've already solved this one, but maybe it'll help someone else down the line

We've ran into a similar issue lately - in our case it was caused by a pre-9.x copy of search.xml in $SPLUNK_HOME/etc/apps/search/local/ui/dashboards

 

 

0 Karma

thunt1104
Engager

I have having this issue with 9.1.1 as well.  We upgraded to 9.1.1, just before 9.1.2 came out.  Upgraded from 8.2.5.  Getting the same message, "Failed to load source for Statistics Table visualization".

0 Karma
Get Updates on the Splunk Community!

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...

[Live Demo] Watch SOC transformation in action with the reimagined Splunk Enterprise ...

Overwhelmed SOC? Splunk ES Has Your Back Tool sprawl, alert fatigue, and endless context switching are making ...

What’s New & Next in Splunk SOAR

Security teams today are dealing with more alerts, more tools, and more pressure than ever.  Join us on ...