Sorry, I copied/pasted the working XML.
I just rebuilt the panel and it's no working again. Here is the full XML. The top panel (Cisco / VMware overlay) is the one that is "waiting for input."
<dashboard>
<label>Cloud Ops</label>
<description>Created by Adam</description>
<row>
<panel>
<html>
<div style="background-color:#00aeef; font-family: Georgia, serif; letter-spacing: 2px; color:#fff; padding:10px; border-radius:5px; border: 1px solid #6d6e71; font-size:20em;">
<center>
<h1>CLOUD OPS</h1>
</center>
</div>
</html>
</panel>
</row>
<row>
<panel>
<chart>
<title>VMware / Cisco Overlay</title>
<search>
<query>(index=* OR index=_*) ((index=* OR index=_*) ((index=* OR index=_*) ((source=cisco:ucs:faultInst* severity=critical) OR (sourcetype=vmware:esxlog* error NOT warning)))) | rename Application AS EventObject.Application Level AS EventObject.Level Message AS EventObject.Message Object AS EventObject.Object Offset AS EventObject.Offset Vpxa AS EventObject.Vpxa ack AS EventObject.ack address AS EventObject.address app AS EventObject.app arg AS EventObject.arg body AS EventObject.body cType AS EventObject.cType cause AS EventObject.cause changeSet AS EventObject.changeSet code AS EventObject.code created AS EventObject.created date_hour AS EventObject.date_hour date_mday AS EventObject.date_mday date_minute AS EventObject.date_minute date_month AS EventObject.date_month date_second AS EventObject.date_second date_wday AS EventObject.date_wday date_year AS EventObject.date_year date_zone AS EventObject.date_zone descr AS EventObject.descr description AS EventObject.description dest AS EventObject.dest dn AS EventObject.dn dynamicType AS EventObject.dynamicType eventtype AS EventObject.eventtype explanation AS EventObject.explanation faultCause AS EventObject.faultCause faultMessage AS EventObject.faultMessage highestSeverity AS EventObject.highestSeverity id AS EventObject.id index AS EventObject.index key AS EventObject.key lastTransition AS EventObject.lastTransition lc AS EventObject.lc linecount AS EventObject.linecount message AS EventObject.message msg AS EventObject.msg occur AS EventObject.occur opID AS EventObject.opID origSeverity AS EventObject.origSeverity prevSeverity AS EventObject.prevSeverity punct AS EventObject.punct reason AS EventObject.reason rule AS EventObject.rule severity AS EventObject.severity site AS EventObject.site splunk_server AS EventObject.splunk_server src AS EventObject.src subject AS EventObject.subject system_name AS EventObject.system_name tag AS EventObject.tag tag::eventtype AS EventObject.tag::eventtype tags AS EventObject.tags timeendpos AS EventObject.timeendpos timestamp AS EventObject.timestamp timestartpos AS EventObject.timestartpos type AS EventObject.type user AS EventObject.user | eval "host"='host', "_time"='_time' | timechart dedup_splitvals=t limit=100 useother=t count AS "Errors by Host" by "host" format=$VAL$:::$AGG$ | sort limit=100 _time | fields _time *</query>
<earliest>rt-24h</earliest>
<latest>rt</latest>
</search>
<option name="charting.axisLabelsX.majorLabelStyle.overflowMode">ellipsisNone</option>
<option name="charting.axisLabelsX.majorLabelStyle.rotation">0</option>
<option name="charting.axisTitleX.visibility">visible</option>
<option name="charting.axisTitleY.text">Errors by Host</option>
<option name="charting.axisTitleY.visibility">visible</option>
<option name="charting.axisTitleY2.visibility">visible</option>
<option name="charting.axisX.scale">linear</option>
<option name="charting.axisY.scale">linear</option>
<option name="charting.axisY2.enabled">0</option>
<option name="charting.axisY2.scale">inherit</option>
<option name="charting.chart">area</option>
<option name="charting.chart.bubbleMaximumSize">50</option>
<option name="charting.chart.bubbleMinimumSize">10</option>
<option name="charting.chart.bubbleSizeBy">area</option>
<option name="charting.chart.nullValueMode">connect</option>
<option name="charting.chart.overlayFields">10.10.10.15</option>
<option name="charting.chart.showDataLabels">none</option>
<option name="charting.chart.sliceCollapsingThreshold">0.01</option>
<option name="charting.chart.stackMode">default</option>
<option name="charting.chart.style">shiny</option>
<option name="charting.drilldown">all</option>
<option name="charting.layout.splitSeries">0</option>
<option name="charting.layout.splitSeries.allowIndependentYRanges">0</option>
<option name="charting.legend.labelStyle.overflowMode">ellipsisMiddle</option>
<option name="charting.legend.placement">right</option>
</chart>
</panel>
</row>
<row>
<panel>
<title>VPN Authentication</title>
<table>
<title>Hosting VPN Auth Failures, Last 24 Hours</title>
<search>
<query>host=* sourcetype=UTM* sub=auth name="Authentication failed" OR "Authentication Failed" | head 5 | rex field=_raw "^\S+\s(?<Customer>\S+)"| eval Timestamp=strftime(_time,"%m-%d-%y %I:%M %p")| table user name Timestamp Customer | rename user as "User", name as "Reason" | eval Customer=case(Customer="portal","Main Firewall", Customer="portal-1","Main Firewall",Customer="ohfl","Orlando", Customer="quhi","Queens",Customer="chks","Children's Health Assoc.",Customer="mhnc","Mission",Customer="mgms","Gulfport",Customer="ocvt","OneCare",Customer="maca","MedAmerica",Customer="uttx","U. of Texas",Customer="adny","Adirondacks",Customer="cafe","CAFE",Customer="kuks","U. of Kansas",Customer="SLC-HOSTING-FW01","Hosting FW",Customer="uppa","U. of Pittsburgh",true(),"-")</query>
<earliest>rt-24h</earliest>
<latest>rtnow</latest>
</search>
<option name="wrap">undefined</option>
<option name="rowNumbers">undefined</option>
<option name="drilldown">row</option>
<option name="dataOverlayMode">none</option>
<option name="count">10</option>
</table>
</panel>
<panel>
<title>AD Authentication</title>
<table>
<title>AD Auth Failures Above 3, Last 24 Hours</title>
<search>
<query>index=wineventlog Account_Domain=* ("EventCode=4625" OR "EventCode=4740") | head 10 | stats count count(eval(EventCode=4740)) as LockedCount by user Account_Domain | search count>3 | eval Locked=if(LockedCount>1, "yes", "no") | table user count Account_Domain Locked | rename user as "User" count as "Failed Authentication Attempts" Account_Domain as "Domain"</query>
<earliest>rt-24h</earliest>
<latest>rt</latest>
</search>
<option name="wrap">true</option>
<option name="rowNumbers">false</option>
<option name="dataOverlayMode">none</option>
<option name="drilldown">cell</option>
<option name="count">10</option>
</table>
</panel>
<panel>
<title>VM Alarms</title>
<table>
<title>VM Alarms "RED", 30 Minute Window</title>
<search>
<query>sourcetype="vmware:events" alarm.name=* | head 10 | eval Timestamp=strftime(_time,"%m-%d-%y %I:%M %p") | spath to | search to=* | spath alarm.name output=alarm | spath vm.name output=vm_name | spath vm.vm.moid output=vm_moid | search host=* | stats first(to) as cur_status by Timestamp alarm vm_name | search cur_status="red" | rename alarm as Alarm, vm_name as VM, cur_status as Status</query>
<earliest>rt-30m</earliest>
<latest>rt</latest>
</search>
<option name="charting.chart">pie</option>
<option name="wrap">true</option>
<option name="rowNumbers">false</option>
<option name="dataOverlayMode">none</option>
<option name="drilldown">cell</option>
<option name="count">10</option>
</table>
</panel>
</row>
<row>
<panel>
<title>UCS Critical</title>
<table>
<title>UCS Critical Alerts, Last 24 Hours</title>
<search>
<query>source=cisco:ucs:faultInst ("critical" OR "severe" OR "major") NOT "security" | head 10 | eval Time=_time | convert ctime(Time) | table Time severity descr | rename severity as Severity, descr as Message</query>
<earliest>rt-24h</earliest>
<latest>rtnow</latest>
</search>
<option name="wrap">true</option>
<option name="rowNumbers">false</option>
<option name="dataOverlayMode">none</option>
<option name="drilldown">cell</option>
<option name="count">10</option>
</table>
</panel>
</row>
</dashboard>
... View more