All Apps and Add-ons

Active Directory App issue with dashboards

dchodur
Path Finder

I am seeing the following message on some of my AD App dashboards in different areas.
The job appears to have expired or has been canceled. Splunk could not retrieve data for this search.

One such place is the Security, User Logon Failures, all items to the right side. The charts on the left all work. In other dashboards parts work as well but others see this message.

I pieced out all the search strings from one of the dashboards (the security, user logon failures), macros, etc to verify all the data was there and such. It was and if I run this search string pieced together in a normal search filed it works. Makes me think there is something else going on that I am running into, like a compatibility issue or bug.

Anyone else seen or had this issue? Know of a fix.

Thanks

0 Karma
1 Solution

dchodur
Path Finder

I figured out my issue, I have this loaded on a Linux system are did not really want to load the TA for Windows on it. Yes- according to the directions and the popup you really do need this installed for the app to work correctly. Installed and and now those dashboards work fine.

View solution in original post

dchodur
Path Finder

I figured out my issue, I have this loaded on a Linux system are did not really want to load the TA for Windows on it. Yes- according to the directions and the popup you really do need this installed for the app to work correctly. Installed and and now those dashboards work fine.

Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...