All Apps and Add-ons

Cisco Networks App for Splunk Enterprise: Why am I getting error "No Search Query Provided" on all dashboards in Splunk 6.1.1?

pksarkar
New Member

All the Cisco Networks App for Splunk Enterprise dashboards are blank with the error "No Search Query Provided". The data from the syslog is present in the index and shows the sourcetype as cisco:ios. I can run manual searches and that displays the data in the index files. If I copy the search string from the XML source file and edit the dashboards, it picks the data from the index. Please provide a solution since I don't want to manually copy the search string for all the dashboards. I have tried deleting the apps from the server and reinstalling it. Splunk version is 6.1.1 and running on Windows server.

0 Karma

mikaelbje
Motivator

You will need Splunk 6.2+ or higher I believe due to new features in the search. Otherwise you may try an older version of the Cisco Networks App which uses the old functions to call searches from dashboards.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Index This | What travels the world but is also stuck in place?

April 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Discover New Use Cases: Unlock Greater Value from Your Existing Splunk Data

Realizing the full potential of your Splunk investment requires more than just understanding current usage; it ...

Continue Your Journey: Join Session 2 of the Data Management and Federation Bootcamp ...

As data volumes continue to grow and environments become more distributed, managing and optimizing data ...