<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk App for Jenkins: Why do I have to log into the indexers in order to see data returned in my dashboards? in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-for-Jenkins-Why-do-I-have-to-log-into-the-indexers-in/m-p/277050#M32486</link>
    <description>&lt;P&gt;This sounds like either you do not have access to the relevant indexes via the search head or your search heads are not retrieving the data from the required indexer servers.&lt;/P&gt;

&lt;P&gt;Have you clicked on the search icon/magnifying glass within a dashboard panel and checked if the search works within the search head?&lt;/P&gt;

&lt;P&gt;If you cannot see any data try searching to see if you have access to data from the required index:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;| tstats count groupby index
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;To be more specific you can do:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;| tstats count where index=&amp;lt;thejenkinsindexgoeshere&amp;gt; groupby index
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;And see if you obtain results, if not we just need to determine why you cannot access that index...&lt;/P&gt;</description>
    <pubDate>Sat, 04 Feb 2017 21:05:42 GMT</pubDate>
    <dc:creator>gjanders</dc:creator>
    <dc:date>2017-02-04T21:05:42Z</dc:date>
    <item>
      <title>Splunk App for Jenkins: Why do I have to log into the indexers in order to see data returned in my dashboards?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-for-Jenkins-Why-do-I-have-to-log-into-the-indexers-in/m-p/277049#M32485</link>
      <description>&lt;P&gt;I have the Splunk App for Jenkins installed on my search heads, indexers, and heavy forwarders.  It appears that the only place that anything is getting data back in the dashboards is when i log into the indexers and use the app there.&lt;/P&gt;</description>
      <pubDate>Fri, 03 Feb 2017 21:32:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-for-Jenkins-Why-do-I-have-to-log-into-the-indexers-in/m-p/277049#M32485</guid>
      <dc:creator>mikefettis</dc:creator>
      <dc:date>2017-02-03T21:32:43Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk App for Jenkins: Why do I have to log into the indexers in order to see data returned in my dashboards?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-for-Jenkins-Why-do-I-have-to-log-into-the-indexers-in/m-p/277050#M32486</link>
      <description>&lt;P&gt;This sounds like either you do not have access to the relevant indexes via the search head or your search heads are not retrieving the data from the required indexer servers.&lt;/P&gt;

&lt;P&gt;Have you clicked on the search icon/magnifying glass within a dashboard panel and checked if the search works within the search head?&lt;/P&gt;

&lt;P&gt;If you cannot see any data try searching to see if you have access to data from the required index:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;| tstats count groupby index
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;To be more specific you can do:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;| tstats count where index=&amp;lt;thejenkinsindexgoeshere&amp;gt; groupby index
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;And see if you obtain results, if not we just need to determine why you cannot access that index...&lt;/P&gt;</description>
      <pubDate>Sat, 04 Feb 2017 21:05:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-for-Jenkins-Why-do-I-have-to-log-into-the-indexers-in/m-p/277050#M32486</guid>
      <dc:creator>gjanders</dc:creator>
      <dc:date>2017-02-04T21:05:42Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk App for Jenkins: Why do I have to log into the indexers in order to see data returned in my dashboards?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-for-Jenkins-Why-do-I-have-to-log-into-the-indexers-in/m-p/277051#M32487</link>
      <description>&lt;P&gt;running from the search head , and the query "| tstats count where index=jenkins_statistics groupby index" i get back plenty of data so &lt;BR /&gt;
&lt;IMG src="https://community.splunk.com/storage/temp/182171-screen-shot-2017-02-06-at-83612-am.png" alt="alt text" /&gt;&lt;/P&gt;

&lt;P&gt;i know the search heads can access the indexes it almost seemed to me like an event extraction isn't working properly.  I looked at some of the searches that the dashboard had generated &lt;BR /&gt;
this search returns nothing "index=jenkins_statistics event_tag=job_event (type=started OR type=completed)" but if i tear it down to just &lt;BR /&gt;
"index=jenkins_statistics job_event " i can see events &lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 12:44:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-for-Jenkins-Why-do-I-have-to-log-into-the-indexers-in/m-p/277051#M32487</guid>
      <dc:creator>mikefettis</dc:creator>
      <dc:date>2020-09-29T12:44:38Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk App for Jenkins: Why do I have to log into the indexers in order to see data returned in my dashboards?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-for-Jenkins-Why-do-I-have-to-log-into-the-indexers-in/m-p/277052#M32488</link>
      <description>&lt;P&gt;Interesting, if you do view the events within the jenkins_statistics do you see the fields tag, event_tag or type ?&lt;/P&gt;

&lt;P&gt;If not then the issue is straightforward.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 12:44:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-for-Jenkins-Why-do-I-have-to-log-into-the-indexers-in/m-p/277052#M32488</guid>
      <dc:creator>gjanders</dc:creator>
      <dc:date>2020-09-29T12:44:47Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk App for Jenkins: Why do I have to log into the indexers in order to see data returned in my dashboards?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-for-Jenkins-Why-do-I-have-to-log-into-the-indexers-in/m-p/277053#M32489</link>
      <description>&lt;P&gt;what is the sourcetype for the event?&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index="jenkins_statistics" job_event |table sourcetype,_raw
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;if you are using latest jenkins plugin with default settings, it should be json:jenkins, which is defined in the app as&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[json:jenkins]
pulldown_type = true
INDEXED_EXTRACTIONS = json
KV_MODE = none
TRUNCATE = 0
category = Structured
description = JavaScript Object Notation format.
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;If the splunk http event collector instance version is prior to 6.5.0, can you try modify jenkins config to use sourcetype json:jenkins:old? it can be done via &lt;/P&gt;

&lt;P&gt;Advanced-&amp;gt;Custom Metadata and choose values like below:&lt;BR /&gt;
Data Source: Default&lt;BR /&gt;
Config Item: Source Type&lt;BR /&gt;
Value: json:jenkins:old&lt;/P&gt;

&lt;P&gt;if you are using splunk 6.5.x, can you check the bundle replication log on search head for errors&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index="_internal" source="*/splunkd.log" DistributedBundleReplicationManager
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Tue, 07 Feb 2017 10:18:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-for-Jenkins-Why-do-I-have-to-log-into-the-indexers-in/m-p/277053#M32489</guid>
      <dc:creator>txiao_splunk</dc:creator>
      <dc:date>2017-02-07T10:18:06Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk App for Jenkins: Why do I have to log into the indexers in order to see data returned in my dashboards?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-for-Jenkins-Why-do-I-have-to-log-into-the-indexers-in/m-p/277054#M32490</link>
      <description>&lt;P&gt;The heavy forwarders that jenkins was connected to were running splunk 6.3.&lt;BR /&gt;&lt;BR /&gt;
The search heads and indexers were all running 6.5.&lt;BR /&gt;
After I upgraded the heavy forwarders to 6.5 the search heads began rendering the jenkins dashboards properly. &lt;/P&gt;</description>
      <pubDate>Wed, 08 Feb 2017 15:48:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-for-Jenkins-Why-do-I-have-to-log-into-the-indexers-in/m-p/277054#M32490</guid>
      <dc:creator>mikefettis</dc:creator>
      <dc:date>2017-02-08T15:48:01Z</dc:date>
    </item>
  </channel>
</rss>

