Splunk Search

Issue with updating dashboard with new results

Trex1
Explorer

Hi there,

I've set up a dashboard with various columns, one of them outputs a  number field which has a comma(,) in it. I can remove the comma using the following command rex field=SurveyAnswers mode=sed "s/\,//g"  where SurveyAnswers is the table name. This works fine in a separate search, however the same command doesn't work when I try to update it in my dashboard and save. Any ideas ??? Thanks

Labels (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Please share the full dashboard query where SurveyAnswers is being modified.

---
If this reply helps you, Karma would be appreciated.
0 Karma

Trex1
Explorer

HI @richgalloway  here is the query. 

index=adobe sourcetype=marketing "voiceofcustomerdetail" records(s)
|rex field=_raw "^(?:[^\t\n]*\t){6}(?P<SurveyAnswers>[^ ]+)"
|sort -_time
|eval Date = strftime(_time,"%Y-%m-%d %H:%M:%S")
|eval Status=if(isnotNull(Date),"Processed","NOK")

|rex mode=sed field=SurveyAnswers "s/,//"
|table Date SurveyAnswers Status

0 Karma
Get Updates on the Splunk Community!

Update Your SOAR Apps for Python 3.13: What Community Developers Need to Know

To Community SOAR App Developers - we're reaching out with an important update regarding Python 3.9's ...

October Community Champions: A Shoutout to Our Contributors!

As October comes to a close, we want to take a moment to celebrate the people who make the Splunk Community ...

Automatic Discovery Part 2: Setup and Best Practices

In Part 1 of this series, we covered what Automatic Discovery is and why it’s critical for observability at ...