-
Notifications
You must be signed in to change notification settings - Fork 8.2k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
The derivequeries panel always broadcasts all events #558
Comments
Can you attach your dashboard schema? This isn't how it works from a code perspective, it looks like you might still have a * query. Remember, derivequeries adds new queries, it doesn't get rid of any you already have.
|
Here is an sample dashboard schema for Windows Events : I see this in the JSON schema :
Is this 0 query due to events with no EventID field ? Does this broadcast a "*" query to all panels ? |
There is no broadcasting anymore, your 0 query is effectively a match all, goto the query panel and remove it. Its there because every dashboard must have a query on load, and if there isn't one, a match all is created. |
The derivequeries panel always broadcasts all events in addition to the facet results, whatever mode is selected. For example, with a table filter, if we enter this query : "host:server1" and select the "action" field with an AND mode, the table inspector shows this in the query :
So the table panel shows everything, even though we enter a "host:server1" query.
The table query should be :
It also doesn't work if the host:server1 is added in a filter panel.
The text was updated successfully, but these errors were encountered: