Splunk Search

My search returns results, but when I save it as a dashboard panel to display a visualization, why does it display nothing or "waiting for data"?

Hindoo
Path Finder

Hello

I enter in the search:

index =main | timechart count by sourcetype

And I "save as" a dashboard panel ...
When I go to see my dashboard, why is nothing displayed?

chimell
Motivator

Hi

for accessing to dashboards

Just click on this link for more information
https://answers.splunk.com/answers/102913/controlling-access-to-dashboard-and-search-capability.html

0 Karma

hettervik
Builder

Hi Hindoo. It looks like I got the exact same problem that you got. Did you figure this out?

0 Karma

hettervik
Builder
0 Karma

treywebb
Explorer

Are you viewing the dashboard as the same user? When you run the search normally are you seeing results? Can you provide any messages or errors displayed when viewing the dashboard?

0 Karma

juvetm
Communicator

which version of splunk are you using

0 Karma

Hindoo
Path Finder

i use splunk 6.1.2
yes the same user , and when i run the search i see the resullt .
There is no error , it display ''waiting for data"
when the panel content is statistics , it's ok , the statistics are displaying but when for exemple the panel content is Pie , it display "waiting for data" or nothing

Raghav2384
Motivator

what's the variance you get? It tends to truncate if there are too many results. Try shortening your time window...start with Last 15minutes and increase gradually.

Hope this helps!

Thanks,
Raghav

0 Karma

Hindoo
Path Finder

Hi Raghav
I tried but no result

0 Karma

juvetm
Communicator

hw many search query did you have in the dashboard

0 Karma

juvetm
Communicator

Are you viewing the dashboard as the same user?

0 Karma

hettervik
Builder

Hi. I have the same problem as Hindoo. You ask if the same user is used. Could there be a missing capability that prevents me from seeing results in the dashboard panel, even though I can see the results when the panel is opened in search?

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...