when i try to run a stats count using postprocess splunk doesn't resolve the query search and i don't know why ?
this is my dashboard :
<form>
  <label>Post Process Search</label>
  <description>Each panel post processes the base search through a separate search pipeline.</description>
  <search id="internal_data">
      <query>index=_internal </query>
  </search>
  <fieldset autoRun="true" submitButton="false">
    <input type="time" searchWhenChanged="true">
      <default>
        <earliest>0</earliest>
        <latest>now</latest>
      </default>
    </input>
  </fieldset>
  <row>
     <table>
      <title>Top Sourcetypes</title>
      <search base="internal_data">
          <query>stats count(uri_path)</query>
      </search>
    </table>
    <chart>
      <title>Events over Time</title>
      <search base="internal_data">
          <query>timechart count</query>
      </search>
      <option name="charting.chart">column</option>
    </chart>
  </row>
</form>
Hi,
its a little tricky. Splunk runs all Dashboard searches in fast mode. So for your search index=_internal no fields are extracted during search time. This means you cannot do a stats command on "uri_path" because splunk just dont know the field in your postprocess search. just do
"index=_internal | fields *" for your basesearch and it will work.
regards
Hi,
its a little tricky. Splunk runs all Dashboard searches in fast mode. So for your search index=_internal no fields are extracted during search time. This means you cannot do a stats command on "uri_path" because splunk just dont know the field in your postprocess search. just do
"index=_internal | fields *" for your basesearch and it will work.
regards
thx ^^ it worl perfectly
Basically you must apply a transforming command in your base search fields, stats, etc. Keep in mind that their is 100,000 event limit when using post process searches.
but it's possible to extend this limit?
Limits are controlled through limits.conf. I've never been able to ID a corresponding setting.
