Hi i have installed the Cacti Mirage Add-On for Splunk on my lab instance which is Search Head and indexer in one.
Cacti is installed in /var/www/html/cacti-1.0.1/
I have installed the Universal Forwarder on cacti and am seeing data for the following sourcetypes coming in to my index called cacti:
cacti:mirage cacti:system cacti:lookup:mirage
However some of the reports are missing data - i think because my lookup table is not being populated.
Looking at the search for Cacti Polling & Lookups Status the search is driven by:
eventtype=cacti:mirage | timechart span=5m count by host
In the eventtypes.conf i have:
[cacti:mirage] search = `cacti_index` sourcetype=cacti:mirage
and if i run
then that works fine but then if i run:
i see no results
Any idea why?
Sorry for the inconvenience! I believe the issue is the use of the macro in the eventtype, which broke somewhere along the upgrade path since we released the app in 6.3
I will make sure to update the app on Splunkbase, in the meantime, try updating the eventtype to :
[splunker@n00bserver local]$ cat eventtypes.conf [cacti:mirage] search = index=cacti sourcetype=cacti:mirage [cacti:lookup:mirage] search = index=cacti sourcetype=cacti:lookup:mirage [splunker@n00bserver local]$
The macro was only thrown in to let users set their own index, but at this point we will just take it out and ensure the users either use index=cacti or configure the eventtype accordingly.
Let me know if that solves it for you
Thanks for that - there were a few other broken searches - but you got me on the right track and all's looking good. Thanks a lot.