<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Content Pack for Windows Dashboards and Reports data not showing in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Content-Pack-for-Windows-Dashboards-and-Reports-data-not-showing/m-p/695905#M80955</link>
    <description>&lt;P&gt;Tom everything seems to be working fine.&lt;BR /&gt;Your help was crucial in finding the problem.&lt;BR /&gt;Thank you very much&lt;/P&gt;</description>
    <pubDate>Sun, 11 Aug 2024 03:40:54 GMT</pubDate>
    <dc:creator>karampatsis</dc:creator>
    <dc:date>2024-08-11T03:40:54Z</dc:date>
    <item>
      <title>Content Pack for Windows Dashboards and Reports data not showing</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Content-Pack-for-Windows-Dashboards-and-Reports-data-not-showing/m-p/694080#M80868</link>
      <description>&lt;P&gt;Hello, I am using Splunk Enterprise with IT Essentials Work, Windows Addon and&amp;nbsp;Content Pack for Windows Dashboards and Reports. I made all the necessary configurations for&amp;nbsp;Content Pack for Windows Dashboards and Reports but still I can not see any data in dashboards or the reports.&amp;nbsp;&lt;/P&gt;&lt;P&gt;In eventtypes.conf file in&amp;nbsp;&lt;SPAN&gt;DA-ITSI-CP-windows-dashboards/local folder i made the following changes&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;[windows_index_windows]&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;definition&lt;/SPAN&gt;&lt;SPAN&gt;=&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;index&lt;/SPAN&gt;&lt;SPAN&gt;=&lt;/SPAN&gt;&lt;SPAN&gt;windows&amp;nbsp;OR&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;index&lt;/SPAN&gt;&lt;SPAN&gt;=&lt;/SPAN&gt;&lt;SPAN&gt;main&lt;/SPAN&gt;&lt;/DIV&gt;&lt;BR /&gt;&lt;DIV&gt;&lt;SPAN&gt;[perfmon_index_windows]&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;definition&lt;/SPAN&gt;&lt;SPAN&gt;=&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;index&lt;/SPAN&gt;&lt;SPAN&gt;=&lt;/SPAN&gt;&lt;SPAN&gt;perfmon&amp;nbsp;OR&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;index&lt;/SPAN&gt;&lt;SPAN&gt;=&lt;/SPAN&gt;&lt;SPAN&gt;itsi_im_metrics&lt;/SPAN&gt;&lt;/DIV&gt;&lt;BR /&gt;&lt;DIV&gt;&lt;SPAN&gt;[wineventlog_index_windows]&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;definition&lt;/SPAN&gt;&lt;SPAN&gt;=&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;index&lt;/SPAN&gt;&lt;SPAN&gt;=&lt;/SPAN&gt;&lt;SPAN&gt;wineventlog&amp;nbsp;OR&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;index&lt;/SPAN&gt;&lt;SPAN&gt;=&lt;/SPAN&gt;&lt;SPAN&gt;main&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;The think the problem starts from the fact that eventtypes are not recognized in searches. &lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;For example the search&amp;nbsp;&amp;nbsp;(eventtype=msad-successful-user-logons OR eventtype=msad-failed-user-logons) returns nothing. &lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;In eventttypes.conf the above stanza is:&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;[msad-successful-user-logons]&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;search&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;=&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;eventtype&lt;/SPAN&gt;&lt;SPAN&gt;=&lt;/SPAN&gt;&lt;SPAN&gt;wineventlog_index_windows&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;eventtype&lt;/SPAN&gt;&lt;SPAN&gt;=&lt;/SPAN&gt;&lt;SPAN&gt;wineventlog_security&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;EventCode&lt;/SPAN&gt;&lt;SPAN&gt;=&lt;/SPAN&gt;&lt;SPAN&gt;4624&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;user!=&lt;/SPAN&gt;&lt;SPAN&gt;"*$"&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;If i run the search: &lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;index=main&amp;nbsp;EventCode=4624&amp;nbsp;user!="*$" i get results.&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;Can someone help me to solve the problem?&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;Thanks&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;BR /&gt;&lt;DIV&gt;&lt;SPAN&gt;[msad_index_windows]&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;search&lt;/SPAN&gt;&lt;SPAN&gt;=&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;index&lt;/SPAN&gt;&lt;SPAN&gt;=&lt;/SPAN&gt;&lt;SPAN&gt;msad&amp;nbsp;OR&amp;nbsp;index=main&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Tue, 23 Jul 2024 15:47:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Content-Pack-for-Windows-Dashboards-and-Reports-data-not-showing/m-p/694080#M80868</guid>
      <dc:creator>karampatsis</dc:creator>
      <dc:date>2024-07-23T15:47:20Z</dc:date>
    </item>
    <item>
      <title>Re: Content Pack for Windows Dashboards and Reports data not showing</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Content-Pack-for-Windows-Dashboards-and-Reports-data-not-showing/m-p/694179#M80874</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;With these sorts of issues it's best to work your way down to eliminate the possible causes.&lt;/P&gt;&lt;P&gt;Take an exemplar broken search from the dashboard and try to run it manually:&lt;BR /&gt;&lt;EM&gt;eventtype=msad-successful-user-logons&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;If that doesn't work try to run the definition manually:&lt;BR /&gt;&lt;/SPAN&gt;&lt;EM&gt;eventtype=wineventlog_index_windows&amp;nbsp;eventtype=wineventlog_security&amp;nbsp;EventCode=4624&amp;nbsp;user!="*$"&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;If that works, make sure the &lt;/SPAN&gt;&lt;EM&gt;msad-successful-user-logons &lt;/EM&gt;&lt;SPAN&gt;definition is correct and shared properly. If not, try expanding your index eventtype:&lt;BR /&gt;&lt;/SPAN&gt;&lt;EM&gt;(index=msad&amp;nbsp;OR&amp;nbsp;index=main) eventtype=wineventlog_security&amp;nbsp;EventCode=4624&amp;nbsp;user!="*$"&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;If that works, make sure your&amp;nbsp;definition is correct and shared properly. If not, try expanding the wineventlog_security eventtype:&lt;BR /&gt;&lt;/SPAN&gt;&lt;EM&gt;(index=msad&amp;nbsp;OR&amp;nbsp;index=main) (search = source=WinEventLog:Security OR source=WMI:WinEventLog:Security OR source=XmlWinEventLog:Security) EventCode=4624&amp;nbsp;user!="*$"&lt;/EM&gt;&lt;/P&gt;&lt;DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;If that works, make sure Splunk_TA_windows is installed the&amp;nbsp;wineventlog_security eventtype is working. If that doesn't work then your problem is not with the eventtype definitions, but rather with the data itself. Things to try:&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN&gt;Do you have Splunk_TA_windows installed on your indexers/search heads?&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Are the source's renamed correctly as per TA_Windows&amp;nbsp;ta-windows-fix-xml-source definition and the requirements of the wineventlog_security&amp;nbsp;eventtype?&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Are your indexes correct and populated within the search timeframe?&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;SPAN&gt;Finally, if you still can't get results, try stripping of key values from the search to check if the search is working:&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;EM&gt;(index=msad&amp;nbsp;OR&amp;nbsp;index=main) (search = source=WinEventLog:Security OR source=WMI:WinEventLog:Security OR source=XmlWinEventLog:Security)&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;If you get results, the problem is with the field extractions:&lt;SPAN&gt;&lt;EM&gt;&amp;nbsp;EventCode=4624&amp;nbsp;user!="*$"&amp;nbsp;&lt;/EM&gt;&lt;/SPAN&gt;check that Splunk_TA_windows is working as expected, check your inputs, props and transforms are all aligned.&lt;BR /&gt;&lt;BR /&gt;Good luck!&lt;/P&gt;</description>
      <pubDate>Wed, 24 Jul 2024 10:33:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Content-Pack-for-Windows-Dashboards-and-Reports-data-not-showing/m-p/694179#M80874</guid>
      <dc:creator>Tom_Lundie</dc:creator>
      <dc:date>2024-07-24T10:33:05Z</dc:date>
    </item>
    <item>
      <title>Re: Content Pack for Windows Dashboards and Reports data not showing</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Content-Pack-for-Windows-Dashboards-and-Reports-data-not-showing/m-p/694959#M80920</link>
      <description>&lt;P&gt;Hello Tom,&lt;/P&gt;&lt;P&gt;thank you very much for your answer.&lt;/P&gt;&lt;P&gt;Τesting the ones you sent me I noticed that if I search for example for:&lt;/P&gt;&lt;P&gt;eventtype=wineventlog_index_windows eventtype=wineventlog_security&lt;/P&gt;&lt;P&gt;I do not get any results, the same if I make a search for:&amp;nbsp; eventtype=wineventlog_index.&lt;/P&gt;&lt;P&gt;But if I try for : eventtype=wineventlog_security&amp;nbsp; I am getting results.&lt;/P&gt;&lt;P&gt;In eventtypes.conf file in&amp;nbsp;&lt;SPAN&gt;DA-ITSI-CP-windows-dashboards/local folder i made the following changes&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;[windows_index_windows]&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;definition&lt;/SPAN&gt;&lt;SPAN&gt;=&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;index&lt;/SPAN&gt;&lt;SPAN&gt;=&lt;/SPAN&gt;&lt;SPAN&gt;windows&amp;nbsp;OR&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;index&lt;/SPAN&gt;&lt;SPAN&gt;=&lt;/SPAN&gt;&lt;SPAN&gt;main&lt;/SPAN&gt;&lt;/DIV&gt;&lt;BR /&gt;&lt;DIV&gt;&lt;SPAN&gt;[perfmon_index_windows]&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;definition&lt;/SPAN&gt;&lt;SPAN&gt;=&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;index&lt;/SPAN&gt;&lt;SPAN&gt;=&lt;/SPAN&gt;&lt;SPAN&gt;perfmon&amp;nbsp;OR&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;index&lt;/SPAN&gt;&lt;SPAN&gt;=&lt;/SPAN&gt;&lt;SPAN&gt;itsi_im_metrics&lt;/SPAN&gt;&lt;/DIV&gt;&lt;BR /&gt;&lt;DIV&gt;&lt;SPAN&gt;[wineventlog_index_windows]&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;definition&lt;/SPAN&gt;&lt;SPAN&gt;=&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;index&lt;/SPAN&gt;&lt;SPAN&gt;=&lt;/SPAN&gt;&lt;SPAN&gt;wineventlog&amp;nbsp;OR&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;index&lt;/SPAN&gt;&lt;SPAN&gt;=&lt;/SPAN&gt;&lt;SPAN&gt;main&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;Do you have any idea why this is happening?&amp;nbsp; &lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;When you are writing "definition is correct and shared properly" what exactly do you mean?&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;Thanks in advance&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Thu, 01 Aug 2024 09:17:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Content-Pack-for-Windows-Dashboards-and-Reports-data-not-showing/m-p/694959#M80920</guid>
      <dc:creator>karampatsis</dc:creator>
      <dc:date>2024-08-01T09:17:56Z</dc:date>
    </item>
    <item>
      <title>Re: Content Pack for Windows Dashboards and Reports data not showing</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Content-Pack-for-Windows-Dashboards-and-Reports-data-not-showing/m-p/695632#M80941</link>
      <description>&lt;P&gt;Does anyone know why eventtype&lt;/P&gt;&lt;P&gt;[wineventlog_index_windows]&lt;BR /&gt;definition= index=wineventlog OR index=main&lt;/P&gt;&lt;P&gt;doesn't return something?&lt;/P&gt;&lt;P&gt;Am I doing something wrong in the eventtypes.conf file or should I declare it somewhere else as well?&lt;/P&gt;&lt;P&gt;Thank you very much&lt;/P&gt;</description>
      <pubDate>Thu, 08 Aug 2024 03:52:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Content-Pack-for-Windows-Dashboards-and-Reports-data-not-showing/m-p/695632#M80941</guid>
      <dc:creator>karampatsis</dc:creator>
      <dc:date>2024-08-08T03:52:32Z</dc:date>
    </item>
    <item>
      <title>Re: Content Pack for Windows Dashboards and Reports data not showing</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Content-Pack-for-Windows-Dashboards-and-Reports-data-not-showing/m-p/695668#M80942</link>
      <description>&lt;P&gt;I think I can see the issue here:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[wineventlog_index_windows]
definition= index=wineventlog OR index=main&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This should be:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[wineventlog_index_windows]
search = index=wineventlog OR index=main&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Note the "search" directive instead of "definition". Definition is used in macros.conf. Let me know how you get on &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 08 Aug 2024 09:41:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Content-Pack-for-Windows-Dashboards-and-Reports-data-not-showing/m-p/695668#M80942</guid>
      <dc:creator>Tom_Lundie</dc:creator>
      <dc:date>2024-08-08T09:41:22Z</dc:date>
    </item>
    <item>
      <title>Re: Content Pack for Windows Dashboards and Reports data not showing</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Content-Pack-for-Windows-Dashboards-and-Reports-data-not-showing/m-p/695905#M80955</link>
      <description>&lt;P&gt;Tom everything seems to be working fine.&lt;BR /&gt;Your help was crucial in finding the problem.&lt;BR /&gt;Thank you very much&lt;/P&gt;</description>
      <pubDate>Sun, 11 Aug 2024 03:40:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Content-Pack-for-Windows-Dashboards-and-Reports-data-not-showing/m-p/695905#M80955</guid>
      <dc:creator>karampatsis</dc:creator>
      <dc:date>2024-08-11T03:40:54Z</dc:date>
    </item>
  </channel>
</rss>

