Splunk Search

Why does adding to search clear existing search?

stianahj
Engager

Hi,

There seems to be an error in Cloud Splunk, can anyone reproduce?

  1. Make a search that returns some data (in JSON). E.g: index="dev" source="TestService"
  2. On the result, click one field in the JSON which should bring up a box. Then, next to "Add to search" click on the arrow.

Expected result is that a new tab opens in your browser with the new command added to the existing query (example search string below). This is what happens in on-prem Splunk instances.

 

 

index="dev" source="TestService" | spath LogLevel | search LogLevel=Information

 

 

Actual result in Splunk Cloud version is that the existing search is cleared and a new search is performed with only the new command

 

 

spath LogLevel | search LogLevel=Information

 

 

0 Karma
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...