Dashboards & Visualizations

Error in User input for dashboard to check a specific IP

codywsj
Loves-to-Learn

Hi, i am having an error of getting this user input for a drop-down to work where i am unable to find any errors within my code. Can somebody help me for this error?

 This is the error i am getting.

codywsj_0-1593524482948.png

This is my search query

(sourcetype="windows event logs" OR sourcetype="General-linux-sql.log" OR sourcetype="csv")
| eval spec_IP=case ([|search sourcetype="General-linux-sql.log"],
[| rex field=_raw "\[(?<IP_addr>\d+.\d+.\d+.\d+)\]"],
[| search sourcetype="csv"],
[| rex field=_raw ",(?<src_ip>\d{1,3}.\d{1,3}.\d{1,3}.\d{1,3}),\d{1,3}.\d{1,3}.\d{1,3}.\d{1,3},,,"],
[| search sourcetype="windows event logs"],
[| search *"Account Locked"*
| rex field=_raw "\[(?<acc_ip>\d+.\d+.\d+.\d+)\]"]
)
| stats count by Specific_IP


Labels (4)
Tags (2)
0 Karma

richgalloway
SplunkTrust
SplunkTrust
That error can happen if one or more of the subsearches returns no results. Check each subsearch to make sure it works by itself - I am suspicious of the "| rex ... " subsearches. Remember that subsearches execute before the main search so they must be valid stand-alone searches.
---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Get the T-shirt to Prove You Survived Splunk University Bootcamp

As if Splunk University, in Las Vegas, in-person, with three days of bootcamps and labs weren’t enough, now ...

Wondering How to Build Resiliency in the Cloud?

IT leaders are choosing Splunk Cloud as an ideal cloud transformation platform to drive business resilience,  ...