<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk for OSSEC Dashboard : No results found. in Dashboards &amp; Visualizations</title>
    <link>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-for-OSSEC-Dashboard-No-results-found/m-p/243289#M15111</link>
    <description>&lt;P&gt;They were just gone apparently, I added them again and now its working &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 14 Oct 2016 11:49:08 GMT</pubDate>
    <dc:creator>nickbijmoer</dc:creator>
    <dc:date>2016-10-14T11:49:08Z</dc:date>
    <item>
      <title>Splunk for OSSEC Dashboard : No results found.</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-for-OSSEC-Dashboard-No-results-found/m-p/243285#M15107</link>
      <description>&lt;P&gt;Hello guys,&lt;/P&gt;

&lt;P&gt;A few days ago the default dashboard of OSSEC in splunk worked fine, but I had to clean up some space so I deleted some data logs and now when I open the default dashboard it says: No results found. &lt;BR /&gt;
So I dont know why, but I dont get data anymore and I tought I didnt change anything...&lt;BR /&gt;
Can some1 help me? If you have questions please ask &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 12 Oct 2016 11:05:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-for-OSSEC-Dashboard-No-results-found/m-p/243285#M15107</guid>
      <dc:creator>nickbijmoer</dc:creator>
      <dc:date>2016-10-12T11:05:24Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk for OSSEC Dashboard : No results found.</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-for-OSSEC-Dashboard-No-results-found/m-p/243286#M15108</link>
      <description>&lt;P&gt;Have you checked the underlying query generating the dashboards to see if a field was renamed or now has no data/results?&lt;/P&gt;</description>
      <pubDate>Wed, 12 Oct 2016 14:52:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-for-OSSEC-Dashboard-No-results-found/m-p/243286#M15108</guid>
      <dc:creator>DEAD_BEEF</dc:creator>
      <dc:date>2016-10-12T14:52:16Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk for OSSEC Dashboard : No results found.</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-for-OSSEC-Dashboard-No-results-found/m-p/243287#M15109</link>
      <description>&lt;P&gt;Yeah I checked it, It gives no data if I search with that query, but the data that he used before is still in SPLUNK so I might have a field that renamed indeed or something like that... Is there an option to set all fields to default again or reset all fields?&lt;/P&gt;</description>
      <pubDate>Thu, 13 Oct 2016 07:26:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-for-OSSEC-Dashboard-No-results-found/m-p/243287#M15109</guid>
      <dc:creator>nickbijmoer</dc:creator>
      <dc:date>2016-10-13T07:26:14Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk for OSSEC Dashboard : No results found.</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-for-OSSEC-Dashboard-No-results-found/m-p/243288#M15110</link>
      <description>&lt;P&gt;I'm not sure if there's an option to set all fields to default again.  I honestly think the easiest thing will be to just manually check each field.  They are case-sensitive, so I'd be sure to check them very carefully!  Sounds like a field prob. got renamed so the query isn't working.  Let me know how this comes along.&lt;/P&gt;</description>
      <pubDate>Thu, 13 Oct 2016 15:21:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-for-OSSEC-Dashboard-No-results-found/m-p/243288#M15110</guid>
      <dc:creator>DEAD_BEEF</dc:creator>
      <dc:date>2016-10-13T15:21:21Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk for OSSEC Dashboard : No results found.</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-for-OSSEC-Dashboard-No-results-found/m-p/243289#M15111</link>
      <description>&lt;P&gt;They were just gone apparently, I added them again and now its working &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 14 Oct 2016 11:49:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-for-OSSEC-Dashboard-No-results-found/m-p/243289#M15111</guid>
      <dc:creator>nickbijmoer</dc:creator>
      <dc:date>2016-10-14T11:49:08Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk for OSSEC Dashboard : No results found.</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-for-OSSEC-Dashboard-No-results-found/m-p/243290#M15112</link>
      <description>&lt;P&gt;Some of the fields themselves were gone?  As in, no logs contained data for such a named field?  That is really odd.  How did you add it again to fix it?  Just so others know as well in the future &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 14 Oct 2016 14:42:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-for-OSSEC-Dashboard-No-results-found/m-p/243290#M15112</guid>
      <dc:creator>DEAD_BEEF</dc:creator>
      <dc:date>2016-10-14T14:42:25Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk for OSSEC Dashboard : No results found.</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-for-OSSEC-Dashboard-No-results-found/m-p/243291#M15113</link>
      <description>&lt;P&gt;Yeah I just manually extracted the fields again &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 17 Oct 2016 06:58:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-for-OSSEC-Dashboard-No-results-found/m-p/243291#M15113</guid>
      <dc:creator>nickbijmoer</dc:creator>
      <dc:date>2016-10-17T06:58:13Z</dc:date>
    </item>
  </channel>
</rss>

