<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Web Intelligence - No Results found... in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Web-Intelligence-No-Results-found/m-p/92464#M71217</link>
    <description>&lt;P&gt;Is there a list of fields that Web Intelligence is looking for?&lt;/P&gt;</description>
    <pubDate>Wed, 09 Nov 2011 08:47:47 GMT</pubDate>
    <dc:creator>fatmcgav</dc:creator>
    <dc:date>2011-11-09T08:47:47Z</dc:date>
    <item>
      <title>Web Intelligence - No Results found...</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Web-Intelligence-No-Results-found/m-p/92450#M71203</link>
      <description>&lt;P&gt;Hi there, &lt;/P&gt;

&lt;P&gt;I'm currently evaluating Splunk for our environment, and have found the promising looking Web Intelligence app... &lt;/P&gt;

&lt;P&gt;However i'm struggling to get it to show up any data... &lt;/P&gt;

&lt;P&gt;I've copied several of our apache access logs onto the Splunk host, and indexed the data through the 'Files &amp;amp; Directories' data input method... &lt;BR /&gt;
I can see the data in the standard search app, however when I try to use Web Intelligence it just shows "No results found"... &lt;/P&gt;

&lt;P&gt;Any ideas???&lt;/P&gt;

&lt;P&gt;Cheers&lt;BR /&gt;
Gavin &lt;/P&gt;</description>
      <pubDate>Fri, 14 Oct 2011 14:55:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Web-Intelligence-No-Results-found/m-p/92450#M71203</guid>
      <dc:creator>fatmcgav</dc:creator>
      <dc:date>2011-10-14T14:55:17Z</dc:date>
    </item>
    <item>
      <title>Re: Web Intelligence - No Results found...</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Web-Intelligence-No-Results-found/m-p/92451#M71204</link>
      <description>&lt;P&gt;Have you gone through the setup workflow for the app (located at /app/webintelligence/setup)?  Using this, you can enter in the correct sources/sourcetypes for your access logs as well as other filters you may want to set, and then use the Preview buttons to ensure that your setting are correct.&lt;/P&gt;</description>
      <pubDate>Fri, 14 Oct 2011 15:27:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Web-Intelligence-No-Results-found/m-p/92451#M71204</guid>
      <dc:creator>araitz</dc:creator>
      <dc:date>2011-10-14T15:27:58Z</dc:date>
    </item>
    <item>
      <title>Re: Web Intelligence - No Results found...</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Web-Intelligence-No-Results-found/m-p/92452#M71205</link>
      <description>&lt;P&gt;Yeh, ran through the setup workflow at the point of installing the app... &lt;/P&gt;

&lt;P&gt;The Sourcetype is set to "sourcetype="access_c*"". Previewing this shows data for the past day. &lt;/P&gt;</description>
      <pubDate>Fri, 14 Oct 2011 15:32:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Web-Intelligence-No-Results-found/m-p/92452#M71205</guid>
      <dc:creator>fatmcgav</dc:creator>
      <dc:date>2011-10-14T15:32:46Z</dc:date>
    </item>
    <item>
      <title>Re: Web Intelligence - No Results found...</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Web-Intelligence-No-Results-found/m-p/92453#M71206</link>
      <description>&lt;P&gt;Which particular view is showing "No Results Found"?  Are you sure you aren't using a real-time window or other time range that is outside the range of your data?&lt;/P&gt;</description>
      <pubDate>Fri, 14 Oct 2011 15:39:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Web-Intelligence-No-Results-found/m-p/92453#M71206</guid>
      <dc:creator>araitz</dc:creator>
      <dc:date>2011-10-14T15:39:05Z</dc:date>
    </item>
    <item>
      <title>Re: Web Intelligence - No Results found...</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Web-Intelligence-No-Results-found/m-p/92454#M71207</link>
      <description>&lt;P&gt;They all show "No results found" unfortunately... I've set the date range to "Today", as the access log was imported for today...&lt;/P&gt;</description>
      <pubDate>Fri, 14 Oct 2011 16:39:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Web-Intelligence-No-Results-found/m-p/92454#M71207</guid>
      <dc:creator>fatmcgav</dc:creator>
      <dc:date>2011-10-14T16:39:03Z</dc:date>
    </item>
    <item>
      <title>Re: Web Intelligence - No Results found...</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Web-Intelligence-No-Results-found/m-p/92455#M71208</link>
      <description>&lt;P&gt;If you hover your mouse next to "No results found", you should see a "More Info..." link.  If you click on this link, what does the search that is being run look like?&lt;/P&gt;</description>
      <pubDate>Fri, 14 Oct 2011 16:41:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Web-Intelligence-No-Results-found/m-p/92455#M71208</guid>
      <dc:creator>araitz</dc:creator>
      <dc:date>2011-10-14T16:41:41Z</dc:date>
    </item>
    <item>
      <title>Re: Web Intelligence - No Results found...</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Web-Intelligence-No-Results-found/m-p/92456#M71209</link>
      <description>&lt;P&gt;The search being run is:&lt;BR /&gt;
" search host=* [ stats count | addinfo | eval range=info_max_time - info_min_time | eval search=if(range&amp;lt;=3605, "index=wi_summary_fivemin", if(range&amp;lt;=(86400+3600),"index=wi_summary_hourly","index=wi_summary_daily")) ] source="Pageview*" sourcename="*"  | top  uri "&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 09:59:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Web-Intelligence-No-Results-found/m-p/92456#M71209</guid>
      <dc:creator>fatmcgav</dc:creator>
      <dc:date>2020-09-28T09:59:35Z</dc:date>
    </item>
    <item>
      <title>Re: Web Intelligence - No Results found...</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Web-Intelligence-No-Results-found/m-p/92457#M71210</link>
      <description>&lt;P&gt;It seems like you are trying to access views that rely on summarized data.  After you set up the app, did you follow the instructions for backfilling the summary indexes?&lt;/P&gt;</description>
      <pubDate>Mon, 17 Oct 2011 16:33:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Web-Intelligence-No-Results-found/m-p/92457#M71210</guid>
      <dc:creator>araitz</dc:creator>
      <dc:date>2011-10-17T16:33:07Z</dc:date>
    </item>
    <item>
      <title>Re: Web Intelligence - No Results found...</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Web-Intelligence-No-Results-found/m-p/92458#M71211</link>
      <description>&lt;P&gt;I'm having the same issues.  I'm quite curious to know what's going on, and eager for a solution (the app looks so interesting).  I'm new to splunk but it seems like the search can't be right - like it's composed incorrectly.  For instance why would the subsearch begin with 'stats count' ... shouldn't that be the target of a search?&lt;/P&gt;</description>
      <pubDate>Thu, 27 Oct 2011 21:11:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Web-Intelligence-No-Results-found/m-p/92458#M71211</guid>
      <dc:creator>chiangs</dc:creator>
      <dc:date>2011-10-27T21:11:56Z</dc:date>
    </item>
    <item>
      <title>Re: Web Intelligence - No Results found...</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Web-Intelligence-No-Results-found/m-p/92459#M71212</link>
      <description>&lt;P&gt;many of the views in web intelligence rely on summarized data.  The 'stats count' is a bit strange.  Did you follow the directions to summarize your data?  Do you see anything in the summary indexes?&lt;/P&gt;</description>
      <pubDate>Thu, 27 Oct 2011 22:28:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Web-Intelligence-No-Results-found/m-p/92459#M71212</guid>
      <dc:creator>araitz</dc:creator>
      <dc:date>2011-10-27T22:28:21Z</dc:date>
    </item>
    <item>
      <title>Re: Web Intelligence - No Results found...</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Web-Intelligence-No-Results-found/m-p/92460#M71213</link>
      <description>&lt;P&gt;the views relying on the summarized data won't show for me to, even after running the  backfill_all scripts. Preview option is showing data as it should be.&lt;/P&gt;</description>
      <pubDate>Tue, 08 Nov 2011 20:43:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Web-Intelligence-No-Results-found/m-p/92460#M71213</guid>
      <dc:creator>RobertWi</dc:creator>
      <dc:date>2011-11-08T20:43:17Z</dc:date>
    </item>
    <item>
      <title>Re: Web Intelligence - No Results found...</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Web-Intelligence-No-Results-found/m-p/92461#M71214</link>
      <description>&lt;P&gt;As an update, I've got decent data running into splunk using the f5 for networks app and associated iRule... &lt;/P&gt;

&lt;P&gt;How can I get the data formatted such that Web Intelligence supports it? Is it a case of creating some field alias'? &lt;/P&gt;

&lt;P&gt;Cheers&lt;BR /&gt;
Gav &lt;/P&gt;</description>
      <pubDate>Tue, 08 Nov 2011 21:17:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Web-Intelligence-No-Results-found/m-p/92461#M71214</guid>
      <dc:creator>fatmcgav</dc:creator>
      <dc:date>2011-11-08T21:17:39Z</dc:date>
    </item>
    <item>
      <title>Re: Web Intelligence - No Results found...</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Web-Intelligence-No-Results-found/m-p/92462#M71215</link>
      <description>&lt;P&gt;Yes, you will want to alias fields similar to how the app does in default/props.conf.&lt;/P&gt;</description>
      <pubDate>Tue, 08 Nov 2011 23:46:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Web-Intelligence-No-Results-found/m-p/92462#M71215</guid>
      <dc:creator>araitz</dc:creator>
      <dc:date>2011-11-08T23:46:10Z</dc:date>
    </item>
    <item>
      <title>Re: Web Intelligence - No Results found...</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Web-Intelligence-No-Results-found/m-p/92463#M71216</link>
      <description>&lt;P&gt;Do you see any data if you search for a timerange that's less than 5 minutes? For most of the views, any timerange that's over 5 minutes searches against summary indexes. A simple way to sanity check that your app is configured correctly is to try and search for a timerange when you know there is data and that spans less than 5 minutes. &lt;/P&gt;</description>
      <pubDate>Wed, 09 Nov 2011 00:01:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Web-Intelligence-No-Results-found/m-p/92463#M71216</guid>
      <dc:creator>Archana</dc:creator>
      <dc:date>2011-11-09T00:01:47Z</dc:date>
    </item>
    <item>
      <title>Re: Web Intelligence - No Results found...</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Web-Intelligence-No-Results-found/m-p/92464#M71217</link>
      <description>&lt;P&gt;Is there a list of fields that Web Intelligence is looking for?&lt;/P&gt;</description>
      <pubDate>Wed, 09 Nov 2011 08:47:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Web-Intelligence-No-Results-found/m-p/92464#M71217</guid>
      <dc:creator>fatmcgav</dc:creator>
      <dc:date>2011-11-09T08:47:47Z</dc:date>
    </item>
    <item>
      <title>Re: Web Intelligence - No Results found...</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Web-Intelligence-No-Results-found/m-p/92465#M71218</link>
      <description>&lt;P&gt;Data I use isn't realtime. Using a couple of acceslog from the day before in the 01u00 to 01u00 timeframe.&lt;/P&gt;</description>
      <pubDate>Thu, 10 Nov 2011 06:01:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Web-Intelligence-No-Results-found/m-p/92465#M71218</guid>
      <dc:creator>RobertWi</dc:creator>
      <dc:date>2011-11-10T06:01:55Z</dc:date>
    </item>
    <item>
      <title>Re: Web Intelligence - No Results found...</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Web-Intelligence-No-Results-found/m-p/92466#M71219</link>
      <description>&lt;P&gt;There is not a definitive list, but by and large the fields conform to the fields extracted from access_combined or access_common Apache logs (clientip, cookie, referer_domain, etc).&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 10:04:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Web-Intelligence-No-Results-found/m-p/92466#M71219</guid>
      <dc:creator>araitz</dc:creator>
      <dc:date>2020-09-28T10:04:51Z</dc:date>
    </item>
    <item>
      <title>Re: Web Intelligence - No Results found...</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Web-Intelligence-No-Results-found/m-p/92467#M71220</link>
      <description>&lt;P&gt;Mmm, ok... Based a lot of this on the iis log format then...&lt;BR /&gt;
Got these in my local/props.conf file:&lt;BR /&gt;
[F5_SPLUNK_iRULE]&lt;BR /&gt;
FIELDALIAS-ClientAddress = client_address AS clientip&lt;BR /&gt;
FIELDALIAS-HTTP Method = http_method AS method&lt;BR /&gt;
FIELDALIAS-HTTP Status = http_status AS status&lt;BR /&gt;
FIELDALIAS-Referrer = referrer AS referer&lt;BR /&gt;
FIELDALIAS-URL = url AS uri&lt;BR /&gt;
FIELDALIAS-uri_path = url AS uri_path&lt;BR /&gt;
FIELDALIAS-useragent = user_agent AS useragent&lt;/P&gt;

&lt;P&gt;However I'm still not seeing data... I've updated WebIntelligence source to be sourcetype=F5_SPLUNK_iRULE, which shows results when I hit preview... &lt;/P&gt;

&lt;P&gt;Any ideas???&lt;/P&gt;

&lt;P&gt;Cheers&lt;BR /&gt;
Gavin&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 10:05:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Web-Intelligence-No-Results-found/m-p/92467#M71220</guid>
      <dc:creator>fatmcgav</dc:creator>
      <dc:date>2020-09-28T10:05:34Z</dc:date>
    </item>
    <item>
      <title>Re: Web Intelligence - No Results found...</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Web-Intelligence-No-Results-found/m-p/92468#M71221</link>
      <description>&lt;P&gt;Can you search, any 5 minute time range in the day before to see if you see charts showing up on dashboards? It's not an issue of realtime vs not. Basically, any timerange that exceeds 5 minutes will search summary indexes instead of the raw data.&lt;/P&gt;</description>
      <pubDate>Fri, 11 Nov 2011 18:59:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Web-Intelligence-No-Results-found/m-p/92468#M71221</guid>
      <dc:creator>Archana</dc:creator>
      <dc:date>2011-11-11T18:59:22Z</dc:date>
    </item>
    <item>
      <title>Re: Web Intelligence - No Results found...</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Web-Intelligence-No-Results-found/m-p/92469#M71222</link>
      <description>&lt;P&gt;Here is a list of field aliases that may be needed, taken from [access-extractions] in default/transforms.conf&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[access-extractions]
# matches access-common or access-combined apache logging formats
# Extracts: clientip, clientport, ident, user, req_time, method, uri, root, file, uri_domain, uri_query, version, status, bytes, referer_url, referer_domain, referer_proto, useragent, cookie, other (remaining chars)  
# Note: referer is misspelled in purpose because that is the "official" spelling for "HTTP referer"
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Thu, 13 Dec 2012 15:23:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Web-Intelligence-No-Results-found/m-p/92469#M71222</guid>
      <dc:creator>MartinHarper</dc:creator>
      <dc:date>2012-12-13T15:23:33Z</dc:date>
    </item>
  </channel>
</rss>

