All Apps and Add-ons

After upgrading the Splunk App for Windows Infrastructure from 1.0.3 to 1.1.3, why are some dashboards showing "Search produced no result"?

simontam
Explorer

I have just upgraded the Windows Infrastructure app from 1.0.3 to 1.1.3. Did many updates on different add-ons and related lookups. Everything seems good, but some dashboards are showing "search produced no result" on the top form input fields, which causes no results in the following tables and charts.

For example, the Active Directory > Domain Controllers > Domain Status, on the top right corner, the Domain drop down list is empty. I have tried to read all the related lookup "DomainSelector", "HostToDomain" and "SiteInfo". They all can return the correct information.

Any hints for me to troubleshoot the problem?

Thanks in advance.

0 Karma

hortonew
Builder

Start by clicking the magnifying glass (bottom left of dashboard panel) to see what search is being used for ones that aren't returning results. Sometimes the answer will be obvious just seeing what the app is searching for. Check a couple things:

Is it searching the correct indexes/sourcetypes for your environment? If no index/sourcetype is provided, try adding them (may not have these searched by default in your user's permissions).

Report back if still having issues.

0 Karma

simontam
Explorer

Thanks hortonew,

As in my example, the Domain Status page, which includes three components:
1: Domain drop down selector on the top right corner
2: Sites section on the left
3: Domain Controllers section on the right

Belows are the messages:
The domain drop down selector shows "Search produced no results".
Both the Sites and Domain Controllers shows "Search is waiting for input..."

I tried to click the magnify glass but nothing response.

Any hints? ToT

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...