Hi Splunkers,
Last Friday configured Splunk App for VMware, everything appears to work fine, but this morning I came back to work and the VMWare app is not working.
I am running Splunk Enterprise Version:7.2.3 and Splunk App for VMware 3.4.4. Indexers, Search Heads, Syslog Server/Forwarder, and DCN are all configured according to the Splunk documentation (this was actually configured by Splunk PS on Friday). Now the issue is that gauges/clocks graph in the dashboard are a showing 0%? And there's no entity info such like CPU or memory assigned to a VM or a Host. Splunkd is running just fine, my Syslog Server/Forwarder shows data being collected, permissions are fine, and when I perform a search on the Index I am seeing current, up-to-the-minute logs. Can anyone help figure out why the dashboard in the app is not being populated? Thanks
Rebuild the data models.
Michael thanks for your input. Can you provide your reasons for this?
Because the Data Models are what delivers the data to the app. It doesn't pull logs directly for most of the graphs etc. And if the DataModels are empty, or failed to finish, or got messed up, then the app won't display any data.
Of course this is assuming that PS set everything up correctly, and that the indexing is being done properly etc.