Activity Feed
- Got Karma for Why is Drilldown to new dashboard not interpreting token value with whitespace properly?. 03-20-2024 06:01 AM
- Got Karma for Reset all inputs to default in dashboard studio?. 12-19-2023 10:19 AM
- Got Karma for Reset all inputs to default in dashboard studio?. 02-02-2023 11:57 AM
- Posted Reset all inputs to default in dashboard studio? on Dashboards & Visualizations. 02-02-2023 11:38 AM
- Posted Why is Drilldown to new dashboard not interpreting token value with whitespace properly? on Dashboards & Visualizations. 01-06-2023 07:11 AM
- Got Karma for Default LINE_BREAKER broken?. 06-05-2020 12:48 AM
- Got Karma for Re: Should I use root events, root transactions, or root searches to set up my data model?. 06-05-2020 12:48 AM
- Got Karma for How to change the label for a Submit button in HTML?. 06-05-2020 12:47 AM
- Got Karma for DB Connect in a Clustered Environment: Why am I getting missing python script errors, failed configuration bundle distribution and duplicate data?. 06-05-2020 12:47 AM
- Got Karma for DB Connect in a Clustered Environment: Why am I getting missing python script errors, failed configuration bundle distribution and duplicate data?. 06-05-2020 12:47 AM
- Got Karma for How to calculate total duration for overlapping transactions. 06-05-2020 12:47 AM
- Posted Restrict searches from unowned search head in indexer cluster on Deployment Architecture. 10-22-2019 02:34 PM
- Tagged Restrict searches from unowned search head in indexer cluster on Deployment Architecture. 10-22-2019 02:34 PM
- Tagged Restrict searches from unowned search head in indexer cluster on Deployment Architecture. 10-22-2019 02:34 PM
- Posted Re: Should I use root events, root transactions, or root searches to set up my data model? on Splunk Search. 05-09-2017 01:16 PM
- Posted Re: Splunk Common Information Model (CIM): Why is data model acceleration not working for Email data model? on Splunk Enterprise Security. 04-18-2017 05:33 AM
- Posted Splunk Common Information Model (CIM): Why is data model acceleration not working for Email data model? on Splunk Enterprise Security. 04-17-2017 12:47 PM
- Tagged Splunk Common Information Model (CIM): Why is data model acceleration not working for Email data model? on Splunk Enterprise Security. 04-17-2017 12:47 PM
- Posted Re: Splunk Enterprise Security: Is it recommended to turn data model acceleration on or use correlation search for the Identity Management data model? on Splunk Enterprise Security. 03-21-2017 06:47 AM
- Posted Re: Splunk Enterprise Security: Is it recommended to turn data model acceleration on or use correlation search for the Identity Management data model? on Splunk Enterprise Security. 03-20-2017 11:35 AM
Topics I've Started
Subject | Karma | Author | Latest Post |
---|---|---|---|
2 | |||
1 | |||
0 | |||
0 | |||
0 | |||
1 | |||
0 | |||
0 | |||
1 | |||
0 |
02-02-2023
11:38 AM
2 Karma
Is there a way to one-click reset all inputs back to their default values in dashboard studio? I have 7 different inputs (dropdowns and text) that are being used as filter criteria for a table. I would like a way to click "something" and have them all set back to their respective default values. I have done something similar for another dashboard that resets tokens that have been set based on clicked rows in charts/tables (just using a single value panel and setting all of the tokens), but I don't see a way to do this for inputs. Reloading the dashboard doesn't set them back to default either. It requires exiting the dashboard and relaunching.
Thanks
Craig
... View more
Labels
- Labels:
-
Dashboard Studio
-
token
01-06-2023
07:11 AM
1 Karma
I have created a dashboard in Dashboard Studio and have configured a "Link to dashboard" drilldown. It works fine when the token value does not have any whitespace in it but does not work when there are spaces. The URL that is generated from the drilldown has a format of "firstword%2Bsecondword" and when I show the token value in the second dashboard, it is translated to "firstword+secondword". This causes the search to return 0 results due to the "+" in the value. How do I configure this so that there is a space in the value instead of a "+"?
Thanks
... View more
Labels
- Labels:
-
dashboard
-
Dashboard Studio
-
drilldown
-
token
11-13-2019
02:26 PM
No, the search restrictions are controlled by their search-head, so they can allow access to what they want.
If you were the admin of their SH, you could enforce role permissions and restrictions.
... View more
09-13-2017
10:34 PM
Hi cwilmoth:
I met similar problems like you, the data model WEB can not be accelerated. But it works opposite to yours. the WEB completes the accerleration immediately and it shows 'done'. But indeed it did not accelerate anything.
I copy the WEB to WEB2, and it works fine.
Did you solve this problems?
... View more
03-21-2017
06:47 AM
Ah. Datamodel commands do not use accelerations. That answers my question. Thanks jwelch.
... View more
05-09-2017
01:16 PM
1 Karma
Iguinn,
From the Knowledge Manager manual:
Datasets can only be accelerated if they contain at least one root event hierarchy or one **root search hierarchy that only includes streaming commands. Dataset hierarchies based on root search datasets that include nonstreaming commands and root transaction datasets are not accelerated
Doesn't that mean that root search datasets can in fact be accelerated? I am asking because it does not look like the CIM Malware Operations dataset is accelerating for us (which would agree with your previous statement), but the manual seems to imply that it should.
... View more
06-14-2016
09:32 AM
There's a second change, the without list has should linemerge set to true while the with list has it set to false. This tells Splunk to merge lines back together to whole events after applying the line breaker. Try setting should linemerge to false without setting the line breaker.
... View more
05-17-2016
10:18 AM
According to Splunk support, this will be fixed in the 6.3.5 release which is not out yet...
... View more
02-02-2016
09:17 PM
If any of the answers worked for you, can you accept it so that the thread can be closed?
... View more
10-16-2015
07:37 AM
1 Karma
OK, I have had the same problem and like you I had not clues in any of the logs. I used your fix of killing the process and letting it restart and yup, started getting data again.
I used to have this problem on Another Siem, so I'm wondering if it has something to do with eStreamer rather than the collector....
... View more
04-17-2015
02:57 PM
Take a look at Splunk Utilization Monitor (SUM) on splunkbase: https://splunkbase.splunk.com/app/2678/
It has a dashboard that can help you isolate what is consuming your license.
... View more
02-02-2015
03:12 PM
Its not "supported" in shc mode but I have gotten it somewhat working.
There are a couple of ways to do this.
Either have a locally maintained install on each member OR use a shared splunk.secret file on each member and use a deployer based unique database.conf file. You will need one of the systems to originally generate the password hashes that are used so they are consistent across all the members.
I have run into a couple of weird issues I am trying to resolve with this configuration however.
... View more
08-30-2018
03:13 PM
The problem with your second part is that, in Internet Explorer 11, the change of the label fires itself a DOMSubtreeModified event, which creates an infinite loop and freezes the browser.
Plus DOMSubtreeModified and similar events are deprecated.
Here's something that works better :
var submitButton = $("#submit button");
submitButton.text("Update");
new MutationObserver(function() {
this.disconnect();
submitButton.text("Update");
this.observe(submitButton[0], {childList: true});
}).observe(submitButton[0], {childList: true});
... View more