All Apps and Add-ons

Active Directory App issue with dashboards

dchodur
Path Finder

I am seeing the following message on some of my AD App dashboards in different areas.
The job appears to have expired or has been canceled. Splunk could not retrieve data for this search.

One such place is the Security, User Logon Failures, all items to the right side. The charts on the left all work. In other dashboards parts work as well but others see this message.

I pieced out all the search strings from one of the dashboards (the security, user logon failures), macros, etc to verify all the data was there and such. It was and if I run this search string pieced together in a normal search filed it works. Makes me think there is something else going on that I am running into, like a compatibility issue or bug.

Anyone else seen or had this issue? Know of a fix.

Thanks

0 Karma
1 Solution

dchodur
Path Finder

I figured out my issue, I have this loaded on a Linux system are did not really want to load the TA for Windows on it. Yes- according to the directions and the popup you really do need this installed for the app to work correctly. Installed and and now those dashboards work fine.

View solution in original post

dchodur
Path Finder

I figured out my issue, I have this loaded on a Linux system are did not really want to load the TA for Windows on it. Yes- according to the directions and the popup you really do need this installed for the app to work correctly. Installed and and now those dashboards work fine.

Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Unlock What’s Next: The Splunk Cloud Platform at .conf25

In just a few days, Boston will be buzzing as the Splunk team and thousands of community members come together ...