Dashboards & Visualizations

results not updated when value change with input type dropdown and using basesearch

matthieu_araman
Communicator

Hello,

I'm using the following form with Splunk 6.2

one basesearch name "basequery".
This search returns less than 10000 answers and is fast.
I use an dropdown input type populated by field from basequery.
I've activated autorun, searchwhenchanged, ...
Then I've a list of panel populated by searches which are based on the resultats from basequery + filter from dropdown + specific by dashboard
So I created another basesearch name "basequery2" filtering results with $field$ value
then the other searches are based on basequery2

The problem I face is that when I select a new value, I see the values visually refresh but the filter is not applied.
If I click on search, which open the complete request in another window, the search is correct and filtered.

If I inline the basequery2 into each search it works and refresh correctly but I don't find it very efficient and less readable even if the results come pretty fast.
.
If there's a way to force the value updated in the basesearch basequery2 and have the results updated correctly or is this a bug/limitation of the current release ?

Tags (2)
0 Karma

auradk
Path Finder

Thanks for follow up. I did the same.

0 Karma

auradk
Path Finder

Did you ever solve this, i face the same problem.

0 Karma

matthieu_araman
Communicator

No, I workarounded it by inlining.
I think it was with 6.2.0 and didn't retest with last versions (like the current 6.2.3)

0 Karma

stephanefotso
Motivator

Can i see your dashboard code? please?

SGF
0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...