Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

"No search query provided" when using base search in a dashboard

$
0
0
OK, so I've been working away on this one for a little while now and can't see what I've missed. I've created a base search, but it doesn't return any results. Rather, it reads "No search query provided", please refer following code sample:
-24h@hnow**
index=sec_antivirus sourcetype="antivirus:symantec:ids" Event_Description="$event_desc_token$" user="$user_token$" | fields *$time_token.earliest$$time_token.latest$All Eventsstats count
Please help. many thanks, P

Viewing all articles
Browse latest Browse all 47296

Trending Articles