Getting Data In

Event: Show source loading ....

chrisitanmoleck
Path Finder

Hello,

if I try to show the source of an event, splunk shows only "loading ...".
I took care, that the result is finalized.

We are using Splunk 8.0.1.

Edit:
I start a search with "host=..." and time=last 24h
I open an event -> event actions -> show source (event.png)
Now the loading screen will not display any result/source, just "loading ...." (show-source.png)

chrisitanmoleck
Path Finder

Splunk support:
The Bug is solved on the next version that should be 8.0.2.
So the option would be to upgrade Splunk whenever this release comes out, we do not have an estimated date at the moment.

chrisitanmoleck
Path Finder

After updating to 8.0.2, the problem is solved!

niketn
Legend

@chrisitanmolecki would it be possible for you to elaborate your issue? How, where and what is the issue? If possible please attach screenshots.

____________________________________________
| makeresults | eval message= "Happy Splunking!!!"
0 Karma

las
Contributor

We see the exact same problem also on 8.0.1
@chrisitanmolecki have you opened a case with support?

0 Karma

las
Contributor

We are using windows Server 2016, that might have an impact

0 Karma

chrisitanmoleck
Path Finder

@las
We are using Suse Linux Enterprise Server 12 Sp4

0 Karma

niketn
Legend

So if both of you have same issue, even though I am not able to re-produce, this still seems like a bug. Work with Splunk Support! Do let us know the outcome.

____________________________________________
| makeresults | eval message= "Happy Splunking!!!"
0 Karma

chrisitanmoleck
Path Finder

@niketnilay
OK I will contact the support.
Cheers mate

0 Karma

chrisitanmoleck
Path Finder

@las No we haven't.

0 Karma

niketn
Legend

@chrisitanmolecki I tried the same and I was able to see the raw data under Show Source. I am also on 8.0.1. I had tried index=_internal host=*.

What is the exact query you have run?
Also how many events did you have?
Did you click on Show Source after you had pulled all the events?
Have you tried with index= and searching with shorter duration or may be with | head 1 to see Show Source works for you?
How about changing browsers to test?

____________________________________________
| makeresults | eval message= "Happy Splunking!!!"
0 Karma

chrisitanmoleck
Path Finder

@niketnilay

index=_internal host=* 

Not working

What is the exact query you have run?

host=foo

The issue occurs at every host

Also how many events did you have?
Thats very different. From a few to several thousands.

Did you click on Show Source after you had pulled all the events?
No I pulled at out just one event

Have you tried with index= and searching with shorter duration or may be with | head 1 to see Show Source works for you?
That change nothing

How about changing browsers to test?
Same at IE11, FF65.0 and GC78.0

0 Karma

chrisitanmoleck
Path Finder

@niketnilay Now it should be more expressive

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...