@sainag_splunk is correct. This has to be a bug in 9.2. I'm about to upgrade to 9.3, so I rushed a bunch of tests. The results suggest that it has something to do with search results or with input...
See more...
@sainag_splunk is correct. This has to be a bug in 9.2. I'm about to upgrade to 9.3, so I rushed a bunch of tests. The results suggest that it has something to do with search results or with input. 9.2.2 9.3.1 Basic search like makeresults, tstats, no input No problem No problem Some complex searches, with inputs No problem (Not tested) Latest dashboard with some other searches, similar inputs Cannot Open in Search (N/A) Code copy of problematic dashboard Cannot Open in Search No problem Recreattion of problematic dashboard Cannot Open in Search (N/A) So, the last two rows are really interesting and took quite some time. I copied the entire JSON from a problematic dashboard to a test instance running 9.3.1 that has similar test data, and saw no problem. Then, I tried several methods to recreate that problematic dashboard in the 9.2.2 instance. First, I simply copied JSON to a new test board and saw the same problem. I thought there might be something wrong with the code. So, I copied individual searches and inputs, in two different ways. They all give the same problematic results.