Dashboards & Visualizations

Why "done" tag is disappeared when I edit panel's search in UI.

yutaka1005
Builder

I created dashboard has two panels like below.

  1. Panel displaying results in table view
  2. Panel showing the count of result of panel1

To display Panel2, I use the <done> ~ </done> tag in the source of Panel1 like below.

<done><eval token="arg1">$job.resultCount$</eval></done>

However, editing the search in the panel1 on the UI editing screen will cause the <done> ~ </done> tag to disappear.

Why is it happen?
Is there a workaround?

If anyone knows, it would be greatly appreciated if you could tell me.

1 Solution

AKG1_old1
Builder

This is a bug in Splunk. Any sections like done,finalized,progress,error are getting disappeared when edit through GUI. I have logged bug to Splunk under "SPL-147251".

View solution in original post

0 Karma

AKG1_old1
Builder

This is a bug in Splunk. Any sections like done,finalized,progress,error are getting disappeared when edit through GUI. I have logged bug to Splunk under "SPL-147251".

0 Karma

yutaka1005
Builder

Thank you for answering!

Do you mean that you reported a bug to Splunk? Or is it already registered as Known Issues?

Also, as a result of contacting support, etc., did you know that it was a bug?

0 Karma

AKG1_old1
Builder

yeah, I have reported it to Splunk and they have acknowledged it as bug . I 'll follow up on this bug.

0 Karma

AKG1_old1
Builder

Guys, This issue has been fixed in Enterprise 7.0.3

gowtham495
Path Finder

@agoyal thank you. I am having same issue. is there any workaround instead of updating to v7.0.3

(Actually, my second panel depends on token from first panel)

0 Karma

yutaka1005
Builder

When I edited the search from source, the <done> tag did not disappear.
Is this the only workaround?

0 Karma

niketn
Legend

I have also noticed this issue intermittently in 7.0. What version are you using? You can add a Bug tag to this question and if you have valid Splunk Entitlement you can reach out to Splunk Support.

____________________________________________
| makeresults | eval message= "Happy Splunking!!!"
0 Karma

yutaka1005
Builder

I noticed this issue in ver 7.0 and 6.6.3.

Perhaps, I think that the corresponding department related to the web framework is not Splunk support.
So we need to wait for someone inside Splunk to mention about this issue.

0 Karma

AKG1_old1
Builder

It's been fixed in 7.0.3

0 Karma
Get Updates on the Splunk Community!

Introducing Splunk Enterprise 9.2

WATCH HERE! Watch this Tech Talk to learn about the latest features and enhancements shipped in the new Splunk ...

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...