All Apps and Add-ons

After upgrading the Splunk App for Windows Infrastructure from 1.0.3 to 1.1.3, why are some dashboards showing "Search produced no result"?

simontam
Explorer

I have just upgraded the Windows Infrastructure app from 1.0.3 to 1.1.3. Did many updates on different add-ons and related lookups. Everything seems good, but some dashboards are showing "search produced no result" on the top form input fields, which causes no results in the following tables and charts.

For example, the Active Directory > Domain Controllers > Domain Status, on the top right corner, the Domain drop down list is empty. I have tried to read all the related lookup "DomainSelector", "HostToDomain" and "SiteInfo". They all can return the correct information.

Any hints for me to troubleshoot the problem?

Thanks in advance.

0 Karma

hortonew
Builder

Start by clicking the magnifying glass (bottom left of dashboard panel) to see what search is being used for ones that aren't returning results. Sometimes the answer will be obvious just seeing what the app is searching for. Check a couple things:

Is it searching the correct indexes/sourcetypes for your environment? If no index/sourcetype is provided, try adding them (may not have these searched by default in your user's permissions).

Report back if still having issues.

0 Karma

simontam
Explorer

Thanks hortonew,

As in my example, the Domain Status page, which includes three components:
1: Domain drop down selector on the top right corner
2: Sites section on the left
3: Domain Controllers section on the right

Belows are the messages:
The domain drop down selector shows "Search produced no results".
Both the Sites and Domain Controllers shows "Search is waiting for input..."

I tried to click the magnify glass but nothing response.

Any hints? ToT

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Unlock What’s Next: The Splunk Cloud Platform at .conf25

In just a few days, Boston will be buzzing as the Splunk team and thousands of community members come together ...