Have been trying to troubleshoot using Splunk for the first time but not getting anywhere really, can anyone give me some tips please?
In Cisco ASA Monitor, looking at Top Bandwidth Consumers, No Results Found. When I click 'Inspect', this is what I get:
This search has completed, but did not match any events. The terms specified in the highlighted portion of the search:
search index=flowintegrator sourcetype=flowintegrator nfc_id=20018 | eval bytes = bytes/1048576 | strcat src_ip "/" user ip_user | timechart limit=10 sum(bytes) by ip_user | fields - OTHER
over the time range:
08/11/2013 16:06:00.000 – 08/11/2013 17:06:34.000
did not return any data.
Similar 'no results found' in all other apps I have installed, 'Application & Network Monitor' & 'NetFlow for Splunk'. Any advice much appreciated.
All previously existing versions of NetFlow Logic Splunk apps have been merged into one NetFlow for Splunk by NetFlow Logic App. See this link http://apps.splunk.com/app/489/