Some years ago I've created a (beautiful!) dashboard, with multiple panels, which presented related data at different angles. Some upgrades of the Splunk-server later (currently using Splunk Enterprise 9.1.5), all of the panels -- except for the one, that shows the raw results of the base search -- stopped working... The common base-search is defined as: <form version="1.1" theme="dark">
<label>Curve Calibration Problems</label>
<search id="common">
<query>index=$mnemonic$
AND sourcetype="FOO"
...
| eval Curve=replace(Description, ".* curve ([^\(]+) \(.*", "\1")
</query>
<earliest>$range.earliest$</earliest>
<latest>$range.latest$</latest>
</search> And then the panels add to it like this, for one example: <panel>
<title>Graph of count of errors for $mnemonic$</title>
<chart>
<search base="common">
<query>top limit=50 Curve</query>
</search>
... Note, how the base search's ID is "common", which is exactly the value referred to as base. Again, the base search itself works correctly. But, when I attempt to edit the panel now, the search-expression is shown only as just that query, that used to be added to the base: If I click on the "Run Search" link in the above window, I see, that, indeed, only that expression is searched for, predictably yielding no results. It seems like something has changed in Splunk, how do I restore this dashboard to working order?
... View more