All Apps and Add-ons

50 - 50 output in web intelligence app | [Traffic pattern/status, Report Top page view/Top Client Ips are working , remaining not working ]

mnaina
Explorer

Following tabs are working in web intelligence app

-Traffic Pattern

-Traffic status

-Advanced Charting: Report - Top Pageview

-Advanced Charting Report - Top Client Ips

Rest of the tabs are not working like (real time dashboard, page views, visitor trends, organic searches ..etc. [error: No results found]

I'm using IIS logs, Installed the universal forwarder in the web server and added the following stanza in the inputs.conf file


[monitor://C:\inetpub\logs\LogFiles]

disabled = false

followTail = 0

sourcetype=iis


Backfilling done for 10 days

What do I need to do to configure to get rest of the things will work...

Thanks in advance

0 Karma

rcavallo
New Member

I have a simliar problem, but it appears that it is because eventtype=pageview does not exist in my system anywhere. Am I supposed to create that eventtype manually?

0 Karma

mnaina
Explorer

Thanks gfuente for your answer

I checked the W3C log format in Web server IIS manager, client ip is enabled but referrer not, now referrer is enabled.

Report Bus and Report Ops are not working in web intelligence app , but Realtime Bus and realtime Ops reports are working.
I also did backfilling for 10 days.

What is missing?

0 Karma

gfuente
Motivator

Hello

You should check your IIS login format configuration, maybe you are not login client-ip or referrer

Regards

mnaina
Explorer

Thanks gfuente for your answer

I checked the W3C log format in Web server IIS manager, client ip is enabled but referrer not, now referrer is enabled.

Report Bus and Report Ops are not working in web intelligence app , but Realtime Bus and realtime Ops reports are working.
I also did backfilling for 10 days.

What is missing?

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to July Tech Talks, Office Hours, and Webinars!

What are Community Office Hours?Community Office Hours is an interactive 60-minute Zoom series where ...

Updated Data Type Articles, Anniversary Celebrations, and More on Splunk Lantern

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

A Prelude to .conf25: Your Guide to Splunk University

Heading to Boston this September for .conf25? Get a jumpstart by arriving a few days early for Splunk ...