Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

Search using map wont work in Dashboard "search is waiting for input"

$
0
0
Hi all, Thank you in advance. I have a search using map that works fine in search, but when i add it as a dashboard (whether i add it exactly the same or with other tokens for fields) is doesn't work and says " search is waiting for input" I think it might have something to do with the time/timepicker Search: sourcetype="mcafee:wg:kv" src=10.42.61.130 dhost=*realtimeboard.com | eval mystarttime=_time-.1 | eval myendtime=_time+.1 | map search="search sourcetype="mcafee:wg:kv" src=10.42.61.130 _time<$myendtime$ _time>$mystarttime$" | table _time,MWG_Time_Log,host,action,rule,user,url,url_protocol,http_method,body,dhost,src,http_content_type | sort -_time Dashboard XML Source - ignore all the other input tokens as the only one im using in the search is timepicker until i get it working ====================================================
-24h@hnowAll DomainsPARLNET*IN ()*"",hosthost| tstats dc(host) where sourcetype=mcafee:wg:kv by host-7d@hnow******AllAllowedBlocked**All Rules*IN ()*"",rulerulesourcetype=mcafee:wg:kv | dedup rule | table rule-7d@hnow*Search URLSearch Domain/dhosturlurl
sourcetype="mcafee:wg:kv" src=10.42.61.130 dhost=*realtimeboard.com | eval mystarttime=_time-.1 | eval myendtime=_time+.1 | map search="search sourcetype="mcafee:wg:kv" src=10.42.61.130 _time<$myendtime$ _time>$mystarttime$" | table _time,MWG_Time_Log,host,action,rule,user,url,url_protocol,http_method,body,dhost,src,http_content_type | sort -_time$tracetime.earliest$$tracetime.latest$
=============================================================== Thanks, any direction or help would be much appreciated. Gerald

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>