<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Dashboards not working in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Dashboards-not-working/m-p/343205#M41472</link>
    <description>&lt;P&gt;And this is on the same search head as the Network Traffic App? can you post some screenshots of the particular dashboard you are having issues with?&lt;/P&gt;</description>
    <pubDate>Tue, 12 Dec 2017 17:10:31 GMT</pubDate>
    <dc:creator>dshpritz</dc:creator>
    <dc:date>2017-12-12T17:10:31Z</dc:date>
    <item>
      <title>Dashboards not working</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Dashboards-not-working/m-p/343202#M41469</link>
      <description>&lt;P&gt;Hello.&lt;BR /&gt;
The problem is that dashboards not show any data.&lt;/P&gt;

&lt;P&gt;I have:&lt;BR /&gt;
&lt;EM&gt;Common Information Model Add-on&lt;/EM&gt;&lt;BR /&gt;
&lt;EM&gt;Accelerations on the Network_Traffic data model&lt;/EM&gt;&lt;BR /&gt;
&lt;EM&gt;Field extractions and tags on my network traffic events are correct (or not, but I can see data in Network_Traffic data model by Pivot)&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Dec 2017 13:28:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Dashboards-not-working/m-p/343202#M41469</guid>
      <dc:creator>test_qweqwe</dc:creator>
      <dc:date>2017-12-12T13:28:59Z</dc:date>
    </item>
    <item>
      <title>Re: Dashboards not working</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Dashboards-not-working/m-p/343203#M41470</link>
      <description>&lt;P&gt;Have you accelerated the Network_Traffic data model? You can run the following to test:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;| tstats summariesonly=true allow_old_summaries=true count from datamodel=Network_Traffic
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;This should be run over the time range you for which you would like to see reports. This will give you a count of the number of events present in the accelerated data model. If that number is zero, there there is nothing in there, so the accelerations have either not been configured, or have not completed. If the number seems like it may be accurate for the number of events you expect to see, then there is something else going on.&lt;/P&gt;

&lt;P&gt;Thanks,&lt;/P&gt;

&lt;P&gt;Dave&lt;/P&gt;</description>
      <pubDate>Tue, 12 Dec 2017 14:02:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Dashboards-not-working/m-p/343203#M41470</guid>
      <dc:creator>dshpritz</dc:creator>
      <dc:date>2017-12-12T14:02:09Z</dc:date>
    </item>
    <item>
      <title>Re: Dashboards not working</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Dashboards-not-working/m-p/343204#M41471</link>
      <description>&lt;P&gt;Yeap, I accelerated the Network_Traffic.&lt;BR /&gt;
This results was by 1 sec - &lt;A href="http://prntscr.com/hmk6zq"&gt;http://prntscr.com/hmk6zq&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Dec 2017 17:08:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Dashboards-not-working/m-p/343204#M41471</guid>
      <dc:creator>test_qweqwe</dc:creator>
      <dc:date>2017-12-12T17:08:37Z</dc:date>
    </item>
    <item>
      <title>Re: Dashboards not working</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Dashboards-not-working/m-p/343205#M41472</link>
      <description>&lt;P&gt;And this is on the same search head as the Network Traffic App? can you post some screenshots of the particular dashboard you are having issues with?&lt;/P&gt;</description>
      <pubDate>Tue, 12 Dec 2017 17:10:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Dashboards-not-working/m-p/343205#M41472</guid>
      <dc:creator>dshpritz</dc:creator>
      <dc:date>2017-12-12T17:10:31Z</dc:date>
    </item>
    <item>
      <title>Re: Dashboards not working</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Dashboards-not-working/m-p/343206#M41473</link>
      <description>&lt;P&gt;Yeap. &lt;A href="http://prntscr.com/hmm3e6"&gt;http://prntscr.com/hmm3e6&lt;/A&gt;&lt;BR /&gt;
&lt;A href="http://prntscr.com/hmm1m4"&gt;http://prntscr.com/hmm1m4&lt;/A&gt; - such results with all dashboards of Network Traffic App&lt;BR /&gt;
&lt;A href="http://prntscr.com/hmm4vo"&gt;http://prntscr.com/hmm4vo&lt;/A&gt; - maybe the problem with macros?&lt;/P&gt;</description>
      <pubDate>Tue, 12 Dec 2017 19:04:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Dashboards-not-working/m-p/343206#M41473</guid>
      <dc:creator>test_qweqwe</dc:creator>
      <dc:date>2017-12-12T19:04:47Z</dc:date>
    </item>
    <item>
      <title>Re: Dashboards not working</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Dashboards-not-working/m-p/343207#M41474</link>
      <description>&lt;P&gt;From that screenshot, it looks like some of your fields may not be mapped correctly, but it's a hard thing to try to fix over answers. What kind of results do you get if you run:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;| tstats summariesonly=true allow_old_summaries=true count from datamodel=Network_Traffic by All_Traffic.action
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;vs&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;| tstats summariesonly=true allow_old_summaries=false count from datamodel=Network_Traffic by All_Traffic.action
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Tue, 12 Dec 2017 19:10:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Dashboards-not-working/m-p/343207#M41474</guid>
      <dc:creator>dshpritz</dc:creator>
      <dc:date>2017-12-12T19:10:09Z</dc:date>
    </item>
    <item>
      <title>Re: Dashboards not working</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Dashboards-not-working/m-p/343208#M41475</link>
      <description>&lt;P&gt;&lt;A href="http://prntscr.com/hmmelh"&gt;http://prntscr.com/hmmelh&lt;/A&gt;&lt;BR /&gt;
vs&lt;BR /&gt;
&lt;A href="http://prntscr.com/hmmf06"&gt;http://prntscr.com/hmmf06&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Dec 2017 19:26:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Dashboards-not-working/m-p/343208#M41475</guid>
      <dc:creator>test_qweqwe</dc:creator>
      <dc:date>2017-12-12T19:26:08Z</dc:date>
    </item>
    <item>
      <title>Re: Dashboards not working</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Dashboards-not-working/m-p/343209#M41476</link>
      <description>&lt;P&gt;From those, it looks like there are two things:&lt;/P&gt;

&lt;OL&gt;
&lt;LI&gt;The action field is not being extracted properly for the source data&lt;/LI&gt;
&lt;LI&gt;You should edit the &lt;CODE&gt;network_traffic_tstats&lt;/CODE&gt; and &lt;CODE&gt;network_traffic_tstats_pre&lt;/CODE&gt; to include the &lt;CODE&gt;allow_old_summaries=true&lt;/CODE&gt; at the end (it defaults to false, but if your DMAs are rebuilding or in process, setting it to &lt;CODE&gt;true&lt;/CODE&gt; can help display data in a more prompt manner. &lt;/LI&gt;
&lt;/OL&gt;</description>
      <pubDate>Tue, 12 Dec 2017 19:30:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Dashboards-not-working/m-p/343209#M41476</guid>
      <dc:creator>dshpritz</dc:creator>
      <dc:date>2017-12-12T19:30:58Z</dc:date>
    </item>
    <item>
      <title>Re: Dashboards not working</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Dashboards-not-working/m-p/343210#M41477</link>
      <description>&lt;P&gt;oh, now it's looks better &lt;span class="lia-unicode-emoji" title=":grinning_squinting_face:"&gt;😆&lt;/span&gt;&lt;BR /&gt;
&lt;A href="http://prntscr.com/hmn91e"&gt;http://prntscr.com/hmn91e&lt;/A&gt;&lt;BR /&gt;
&lt;A href="http://prntscr.com/hmn9y3"&gt;http://prntscr.com/hmn9y3&lt;/A&gt;&lt;BR /&gt;
&lt;A href="http://prntscr.com/hmncjc"&gt;http://prntscr.com/hmncjc&lt;/A&gt;&lt;BR /&gt;
&lt;A href="http://prntscr.com/hmncxb"&gt;http://prntscr.com/hmncxb&lt;/A&gt;&lt;BR /&gt;
&lt;A href="http://prntscr.com/hmnd7f"&gt;http://prntscr.com/hmnd7f&lt;/A&gt;&lt;BR /&gt;
&lt;A href="http://prntscr.com/hmnev0"&gt;http://prntscr.com/hmnev0&lt;/A&gt;&lt;BR /&gt;
&lt;A href="http://prntscr.com/hmnf80"&gt;http://prntscr.com/hmnf80&lt;/A&gt;&lt;BR /&gt;
&lt;A href="http://prntscr.com/hmnhzz"&gt;http://prntscr.com/hmnhzz&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;and ye, i need fix some fields. What should i do to fix it?&lt;/P&gt;</description>
      <pubDate>Tue, 12 Dec 2017 20:35:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Dashboards-not-working/m-p/343210#M41477</guid>
      <dc:creator>test_qweqwe</dc:creator>
      <dc:date>2017-12-12T20:35:15Z</dc:date>
    </item>
    <item>
      <title>Re: Dashboards not working</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Dashboards-not-working/m-p/343211#M41478</link>
      <description>&lt;P&gt;And can you more detail explain me why it works with &lt;CODE&gt;allow_old_summaries=true&lt;/CODE&gt; and not work by default macros?&lt;/P&gt;</description>
      <pubDate>Tue, 12 Dec 2017 20:44:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Dashboards-not-working/m-p/343211#M41478</guid>
      <dc:creator>test_qweqwe</dc:creator>
      <dc:date>2017-12-12T20:44:00Z</dc:date>
    </item>
    <item>
      <title>Re: Dashboards not working</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Dashboards-not-working/m-p/343212#M41479</link>
      <description>&lt;P&gt;To fix the fields you will need to fix the field extractions in the source data. &lt;/P&gt;

&lt;P&gt;For the &lt;CODE&gt;allow_old_summaries&lt;/CODE&gt; argument, from the &lt;A href="https://docs.splunk.com/Documentation/Splunk/7.0.1/SearchReference/Tstats"&gt;docs page for tstats&lt;/A&gt;:&lt;/P&gt;

&lt;BLOCKQUOTE&gt;
&lt;P&gt;To return results from summary&lt;BR /&gt;
directories only when those&lt;BR /&gt;
directories are up-to-date, set this&lt;BR /&gt;
parameter to false. If the data model&lt;BR /&gt;
definition has changed, summary&lt;BR /&gt;
directories that are older than the&lt;BR /&gt;
new definition are not used when&lt;BR /&gt;
producing output from tstats. This&lt;BR /&gt;
default ensures that the output from&lt;BR /&gt;
tstats will always reflect your&lt;BR /&gt;
current configuration. When set to&lt;BR /&gt;
true, tstats will use both current&lt;BR /&gt;
summary data and summary data that was&lt;BR /&gt;
generated prior to the definition&lt;BR /&gt;
change. Essentially this is an&lt;BR /&gt;
advanced performance feature for cases&lt;BR /&gt;
where you know that the old summaries&lt;BR /&gt;
are "good enough".&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;</description>
      <pubDate>Tue, 12 Dec 2017 20:48:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Dashboards-not-working/m-p/343212#M41479</guid>
      <dc:creator>dshpritz</dc:creator>
      <dc:date>2017-12-12T20:48:52Z</dc:date>
    </item>
  </channel>
</rss>

