This is a very strange issue. I currently have a small Splunk infra living in an EC2 instance as a POC. Everything is going well minus some SSL hiccups along the way, but one of hte most valuable pieces that the teams are looking for is the CW metrics that are coming into the Splunk App for Infra.
Setup was easy and things were going well, when yesterday I noticed that all of the entities disappeared.
The interesting thing is that the metrics are all still coming in (able to see data coming into the metric index).
Is there any way to rebuild the asset table?
Just to build on what @abrown_splunk mentioned. Right now looks like the issue is that SAI doesn't support Splunk_aws_TA 4.6. It looks like with Splunk_AWS_TA, metrics still do come in, however they have an extra dimension to them. For example, CPUUtiliziation is a metric with 4.5, however that metric changes to CPUUtilization.average with 4.6.
I would hold off on upgrading to 4.6 if you rely on the dashboards from SAI.
Closing the loop, there is a difference in the way AWS information is displayed when upgrading from 4.5.0 to 4.6.0 versions of that TA. In the 4.5.0 version, certain metrics are displayed as an average, where in 4.6.0, the information is presented more granularly - there is a tree to see min/max/average. No change is needed when making this upgrade, but information will be presented in a different, more granular, way.