Splunk Search

Why is the table in dashboard reporting "No results found" when there are in fact results found?

Contributor

We have a table in a dashboard that shows "No results found." when in fact there are results for the search based on the search inspector and when open in search for the panel is executed. Any hints on what might be causing this issue? A Splunk bug? We are running Splunk 7.0.0.

alt text

0 Karma

I suspect your dashboard is configured to display an events table, but you are returning a stats table. Can you edit the dashboard and ensure this is set as a stats table?

Hey @simpkins1958 - did this turn out to be the issue, or do you still need help?

0 Karma

Champion

This is probably more likely than my answer. 🙂

0 Karma

Champion

I wonder if you're running into a known issue, SPL-142964.

This recent answers post discusses something similar.

This issue was fixed in 6.6.4. Are you running a version lower than this?

0 Karma

Contributor

We are running 7.0.0.

0 Karma

Champion

I'm also seeing it was fixed in 7.0.1, so you may still be affected. Look in your search.log for lines like:

08-30-2017 12:58:47.035 ERROR Timeliner - Ignored 2 events because they were after the commit time (0).
08-30-2017 12:58:38.909 WARN SearchResultCollator - Collector X produced chunk with startTime 1503348584.000000 when our cursor time was already 0.000000, time ordering has failed!
0 Karma