We have a table in a dashboard that shows "No results found." when in fact there are results for the search based on the search inspector and when open in search for the panel is executed. Any hints on what might be causing this issue? A Splunk bug? We are running Splunk 7.0.0.
I suspect your dashboard is configured to display an events table, but you are returning a stats table. Can you edit the dashboard and ensure this is set as a stats table?
Hey @simpkins1958 - did this turn out to be the issue, or do you still need help?
This is probably more likely than my answer. 🙂
I wonder if you're running into a known issue, SPL-142964.
This recent answers post discusses something similar.
This issue was fixed in 6.6.4. Are you running a version lower than this?
We are running 7.0.0.
I'm also seeing it was fixed in 7.0.1, so you may still be affected. Look in your search.log for lines like:
08-30-2017 12:58:47.035 ERROR Timeliner - Ignored 2 events because they were after the commit time (0).
08-30-2017 12:58:38.909 WARN SearchResultCollator - Collector X produced chunk with startTime 1503348584.000000 when our cursor time was already 0.000000, time ordering has failed!