Reporting

Savedsearch shows up in Job Management as search string rather than what the search is saved as.

essklau
Path Finder

Hi,

I have a search

index=net earliest=-1d@d latest=@d sourcetype=cisco_asa "*TEARDOWN*"  transport!=ICMP src_ip=10.0.0.0/8 AND dest_ip!=10.0.0.0/8|localop|lookup dnsLookup ip as dest_ip OUTPUTNEW host as hostname |eval Endpoints=src_ip.":".src_port." to ".dest_ip.":".dest_port." (".hostname.")" | eval MB=(bytes_in/1024/1024) | stats max(MB) as "Connection Size(MB)" by Endpoints|rename "Endpoints" as "Source IP:Port to Dest IP:Port" |sort - "Connection Size(MB)" limit=25

which is scheduled to run once/day. When it does run, it shows up in the Jobs panel as the search string, rather than the name it is saved as. I feel like this might be a clue in a larger troubleshoot i'm trying to do. Has anyone seen this before?

Bigger picture: the search results don't load my dashboard, unlike all other dashboards including one extremely similar search.

Thanks

Tags (2)
0 Karma

jimodonald
Contributor

I've seen similar behavior on 6.1.1 when I moved a dashboard using saved searches to a different search head. To fix it, i converted the dashboard to Advanced XML and it worked. Unfortunately I can't say why it works that way and I have not ranked it important enough to open a ticket with Splunk.

Try making an Advanced XML version of your dashboard and see if that works. I'll be interested to hear if your results match mine.

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...