Hello,
today I have found a bug(?) in the "New Search" function from the Table view.
What I do mean with the "New Search" function:
Run a search and select the table view (not raw or list). Then click on one of the shown values of a field, for example the value of a host field, and select "New Search".
Now a new search starts with the selected field+value, but instead of using the same index(es) from the view before, only a * will be used.
As we do not have defined any default indexes in our environment those searches won't return any results, because no index is included ín the search. Is there a possibility how I can reconfigure this, instead of a plain asterisk?
Best Regards.
The same happens with 9.4.1 - perhaps it is a feature? But, tbh, it sounds like a bug. Raise a ticket and see what support say?
Hi,
we do use Version 9.2.4.
The behaviour is independent of the search complexity. It also doesn't change if I search internal logs or through several indexes. The index(es) will always be replaced by an *
The behaviour is also the same within the list view, so it's not only table view related.
BR
Hi
Which version of Splunk are you running? For me when I click on a "New Search" in either table view or list view I get the same behaviour, which in my example did index=_internal (Which I had searched) and added the field I clicked.
Does it differ if you have a more complex query?
🌟 Did this answer help you? If so, please consider:
Your feedback encourages the volunteers in this community to continue contributing