I keep having issues where Splunk will remove the space after: field - ... which then messes up the query.
I edit the source and place one or two spaces between 'field' and '-' and which will then show correct output but then when I close the dashboard, it reverts back and removes the spaces to | field-
Am I missing something or is there a way to fix this issue? I suppose I could do a |fields and list all the fields I want to keep but that shouldn't be the answer.
Any suggestions as to why this is occurring? I have several dashboards doing this.
... View more