Splunk Search

Why is the table in dashboard reporting "No results found" when there are in fact results found?

simpkins1958
Contributor

We have a table in a dashboard that shows "No results found." when in fact there are results for the search based on the search inspector and when open in search for the panel is executed. Any hints on what might be causing this issue? A Splunk bug? We are running Splunk 7.0.0.

alt text

0 Karma

elliotproebstel
Champion

I suspect your dashboard is configured to display an events table, but you are returning a stats table. Can you edit the dashboard and ensure this is set as a stats table?

elliotproebstel
Champion

Hey @simpkins1958 - did this turn out to be the issue, or do you still need help?

0 Karma

micahkemp
Champion

This is probably more likely than my answer. 🙂

0 Karma

micahkemp
Champion

I wonder if you're running into a known issue, SPL-142964.

This recent answers post discusses something similar.

This issue was fixed in 6.6.4. Are you running a version lower than this?

0 Karma

simpkins1958
Contributor

We are running 7.0.0.

0 Karma

micahkemp
Champion

I'm also seeing it was fixed in 7.0.1, so you may still be affected. Look in your search.log for lines like:

08-30-2017 12:58:47.035 ERROR Timeliner - Ignored 2 events because they were after the commit time (0).
08-30-2017 12:58:38.909 WARN SearchResultCollator - Collector X produced chunk with startTime 1503348584.000000 when our cursor time was already 0.000000, time ordering has failed!
0 Karma
Get Updates on the Splunk Community!

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

🔐 Trust at Every Hop: How mTLS in Splunk Enterprise 10.0 Makes Security Simpler

From Idea to Implementation: Why Splunk Built mTLS into Splunk Enterprise 10.0  mTLS wasn’t just a checkbox ...