All Apps and Add-ons

Sideview HTML disappears when inside a search with 0 results! (v. 2+)

Jason
Motivator

I have a dashboard using a HiddenSavedSearch and many HiddenPostProcess modues underneath it. Inside each postprocess I have a SideView HTML module showing a static title and a button with the result of the postprocess.

Currently, most of the postprocesses return no result.

In the previous version of SideView, 1.3.4, the HTML is visible, showing the title and an empty button. This is good.

In the current version of SideView, 2.1.2, the HTML element disappears after the dashboard finishes loading. (The title and empty button are visible for a second while it is loading, but then all disappear.) This is bad, as the user can not even see what data is missing, since the title is gone.

What can be done to fix this?

1 Solution

sideview
SplunkTrust
SplunkTrust

I'm not sure. Can you post the XML or email it to me at nick[at]sideviewapps.com ? It sounds like something else is going on.

I took a pass through my tests and I don't see anything that could be causing it. Definitely send the XML - I can think of some longshot ideas where you might have been inadvertently exploiting a side-effect that was later taken away...

UPDATE::::

Since I didn't hear back, I took a look through. I created a little testcase using the Splunk modules HiddenSavedSearch and HiddenPostProcess, and the Sideview HTML module. And although the modules seem to work together fine once I got the postProcess searches valid, I did find something odd at the API level along the way that might be what you've hit?.

What I found is that if you have a search language syntax error in the postProcess search that you send to the Splunk server, instead of returning a nice error message, the server actually returns a 404 status. This 404 response code is very unexpected. Although I haven't succeeded in finding a case where the HTML module's text completely dissappears, it might be a contributing factor here.

So my suggestion (besides posting or emailing the XML) is to take a very close look at the postProcess searches that you're sending and I suspect that there are some unbalanced quotes in them or something that might trigger a parse error from the Splunk server.

(and sorry for updating this answer a few times already)

View solution in original post

sideview
SplunkTrust
SplunkTrust

I'm not sure. Can you post the XML or email it to me at nick[at]sideviewapps.com ? It sounds like something else is going on.

I took a pass through my tests and I don't see anything that could be causing it. Definitely send the XML - I can think of some longshot ideas where you might have been inadvertently exploiting a side-effect that was later taken away...

UPDATE::::

Since I didn't hear back, I took a look through. I created a little testcase using the Splunk modules HiddenSavedSearch and HiddenPostProcess, and the Sideview HTML module. And although the modules seem to work together fine once I got the postProcess searches valid, I did find something odd at the API level along the way that might be what you've hit?.

What I found is that if you have a search language syntax error in the postProcess search that you send to the Splunk server, instead of returning a nice error message, the server actually returns a 404 status. This 404 response code is very unexpected. Although I haven't succeeded in finding a case where the HTML module's text completely dissappears, it might be a contributing factor here.

So my suggestion (besides posting or emailing the XML) is to take a very close look at the postProcess searches that you're sending and I suspect that there are some unbalanced quotes in them or something that might trigger a parse error from the Splunk server.

(and sorry for updating this answer a few times already)

Jason
Motivator

Thanks Nick.

0 Karma

sideview
SplunkTrust
SplunkTrust

It turns out that this was indeed a bug in Sideview Utils 2.1.X. However it was fixed in Sideview Utils 2.2, and the 2.2 version came out late last week. So upgrading to 2.2 will fix this problem.

http://sideviewapps.com/apps/sideview-utils/

My apologies to Jason for the bug, and for the fact that it took me a while to figure out why I couldn't reproduce the bug on my local environment (which was of course running 2.2).

Jason
Motivator

Thanks Nick - email sent. I look forward to hearing if it's a bug or can be fixed by a different configuration.

0 Karma
Get Updates on the Splunk Community!

What's new in Splunk Cloud Platform 9.1.2312?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.1.2312! Analysts can ...

What’s New in Splunk Security Essentials 3.8.0?

Splunk Security Essentials (SSE) is an app that can amplify the power of your existing Splunk Cloud Platform, ...

Let’s Get You Certified – Vegas-Style at .conf24

Are you ready to level up your Splunk game? Then, let’s get you certified live at .conf24 – our annual user ...