All Apps and Add-ons

App for Infrastructure AWS Entities Disappeared

paimonsoror
Builder

This is a very strange issue. I currently have a small Splunk infra living in an EC2 instance as a POC. Everything is going well minus some SSL hiccups along the way, but one of hte most valuable pieces that the teams are looking for is the CW metrics that are coming into the Splunk App for Infra.

Setup was easy and things were going well, when yesterday I noticed that all of the entities disappeared.

The interesting thing is that the metrics are all still coming in (able to see data coming into the metric index).

Is there any way to rebuild the asset table?

0 Karma

paimonsoror
Builder

Just to build on what @abrown_splunk mentioned. Right now looks like the issue is that SAI doesn't support Splunk_aws_TA 4.6. It looks like with Splunk_AWS_TA, metrics still do come in, however they have an extra dimension to them. For example, CPUUtiliziation is a metric with 4.5, however that metric changes to CPUUtilization.average with 4.6.

I would hold off on upgrading to 4.6 if you rely on the dashboards from SAI.

abrown_splunk
Splunk Employee
Splunk Employee

Closing the loop, there is a difference in the way AWS information is displayed when upgrading from 4.5.0 to 4.6.0 versions of that TA. In the 4.5.0 version, certain metrics are displayed as an average, where in 4.6.0, the information is presented more granularly - there is a tree to see min/max/average. No change is needed when making this upgrade, but information will be presented in a different, more granular, way.

dagarwal_splunk
Splunk Employee
Splunk Employee

What version of Splunk App for Infra are you using? Did you recently upgrade SAI?

0 Karma

paimonsoror
Builder

I am actually using 1.2.0. Haven't upgraded it, actually started with 1.2.0

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...