Hi,
There seems to be an error in Cloud Splunk, can anyone reproduce?
Make a search that returns some data (in JSON). E.g: index="dev" source="TestService"
On the result, click one field in the JSON which should bring up a box. Then, next to "Add to search" click on the arrow.
Expected result is that a new tab opens in your browser with the new command added to the existing query (example search string below). This is what happens in on-prem Splunk instances.
index="dev" source="TestService" | spath LogLevel | search LogLevel=Information
Actual result in Splunk Cloud version is that the existing search is cleared and a new search is performed with only the new command
spath LogLevel | search LogLevel=Information
... View more