<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Web Intelligence application NO data in Distributed environment in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Web-Intelligence-application-NO-data-in-Distributed-environment/m-p/70983#M70652</link>
    <description>&lt;P&gt;Hey Araitz- I met you @ .conf this year, but any way.. &lt;/P&gt;

&lt;OL&gt;
&lt;LI&gt;&lt;P&gt;did you want me to do this search in the web app or the search app. I am not sure if it makes a difference.&lt;/P&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;P&gt;In the search app i do an search for sourcetype=iis and it returns all the w3c fields and others in the field picker.&lt;/P&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;P&gt;The sourcetype being assigned is iis.. and some instances there is iis-2,3... etc but I am fixing those as I run into them &lt;/P&gt;&lt;/LI&gt;
&lt;/OL&gt;

&lt;P&gt;Thanks&lt;/P&gt;</description>
    <pubDate>Wed, 26 Sep 2012 16:45:04 GMT</pubDate>
    <dc:creator>paul_1994</dc:creator>
    <dc:date>2012-09-26T16:45:04Z</dc:date>
    <item>
      <title>Web Intelligence application NO data in Distributed environment</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Web-Intelligence-application-NO-data-in-Distributed-environment/m-p/70981#M70650</link>
      <description>&lt;P&gt;I have installed the app on my search heads and created the indexes on my indexers. I have verified on my indexer from the manger that events are being created and I have searched the indexes on the indexer and search head and returned information, but the app is still empty. &lt;/P&gt;

&lt;P&gt;Result of search on the summary indexes If this helps&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;09/25/2012 15:40:00, search_name="Web Traffic by host fivemin summary - regenerator", search_now=1348613100.000, info_min_time=1348612800.000, info_max_time=1348613100.000, info_search_time=1348613119.944, hits=240, myhost=******, sourcename="V:\\Logfiles\\W3SVC1910282147\\ex120925.log", report="\"WA webtraffic host summary index\"" 
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Any Help would be appreciated..&lt;/P&gt;</description>
      <pubDate>Tue, 25 Sep 2012 22:48:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Web-Intelligence-application-NO-data-in-Distributed-environment/m-p/70981#M70650</guid>
      <dc:creator>paul_1994</dc:creator>
      <dc:date>2012-09-25T22:48:40Z</dc:date>
    </item>
    <item>
      <title>Re: Web Intelligence application NO data in Distributed environment</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Web-Intelligence-application-NO-data-in-Distributed-environment/m-p/70982#M70651</link>
      <description>&lt;P&gt;My guess is that your IIS fields are not being extracted properly.  When you search your IIS logs using the flashtimeline view, do you see fields like 'cookie', 'referer', 'uri', etc in the field picker?  What is the sourcetype that your IIS logs are being assigned?&lt;/P&gt;</description>
      <pubDate>Wed, 26 Sep 2012 05:52:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Web-Intelligence-application-NO-data-in-Distributed-environment/m-p/70982#M70651</guid>
      <dc:creator>araitz</dc:creator>
      <dc:date>2012-09-26T05:52:53Z</dc:date>
    </item>
    <item>
      <title>Re: Web Intelligence application NO data in Distributed environment</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Web-Intelligence-application-NO-data-in-Distributed-environment/m-p/70983#M70652</link>
      <description>&lt;P&gt;Hey Araitz- I met you @ .conf this year, but any way.. &lt;/P&gt;

&lt;OL&gt;
&lt;LI&gt;&lt;P&gt;did you want me to do this search in the web app or the search app. I am not sure if it makes a difference.&lt;/P&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;P&gt;In the search app i do an search for sourcetype=iis and it returns all the w3c fields and others in the field picker.&lt;/P&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;P&gt;The sourcetype being assigned is iis.. and some instances there is iis-2,3... etc but I am fixing those as I run into them &lt;/P&gt;&lt;/LI&gt;
&lt;/OL&gt;

&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Wed, 26 Sep 2012 16:45:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Web-Intelligence-application-NO-data-in-Distributed-environment/m-p/70983#M70652</guid>
      <dc:creator>paul_1994</dc:creator>
      <dc:date>2012-09-26T16:45:04Z</dc:date>
    </item>
    <item>
      <title>Re: Web Intelligence application NO data in Distributed environment</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Web-Intelligence-application-NO-data-in-Distributed-environment/m-p/70984#M70653</link>
      <description>&lt;P&gt;So I thought I would follow up on my question. I worked with support and found out a couple of things.&lt;/P&gt;

&lt;OL&gt;
&lt;LI&gt;you need to make sure your logs are being transformed correctly via props and transform&lt;/LI&gt;
&lt;LI&gt;A lot of the searches depend on the correct Field aliases being defined&lt;/LI&gt;
&lt;/OL&gt;

&lt;P&gt;For the Field aliases I had to change the defaults to match my environment with custom sourcetypes.&lt;/P&gt;

&lt;P&gt;for example here is a default alias for the WI&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;(?:::){0}iis-&lt;/STRONG&gt;* : FIELDALIAS-clientip&lt;/P&gt;

&lt;P&gt;I had to clone the one above and create this one&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;iis&lt;/STRONG&gt; : FIELDALIAS-iis-clientip&lt;/P&gt;

&lt;P&gt;because my sourcetype for iis was "iis" not "iis-***"&lt;/P&gt;</description>
      <pubDate>Fri, 28 Sep 2012 19:11:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Web-Intelligence-application-NO-data-in-Distributed-environment/m-p/70984#M70653</guid>
      <dc:creator>paul_1994</dc:creator>
      <dc:date>2012-09-28T19:11:28Z</dc:date>
    </item>
  </channel>
</rss>

