All Apps and Add-ons

Cisco Networks App for Splunk Enterprise: Why am I getting error "No Search Query Provided" on all dashboards in Splunk 6.1.1?

pksarkar
New Member

All the Cisco Networks App for Splunk Enterprise dashboards are blank with the error "No Search Query Provided". The data from the syslog is present in the index and shows the sourcetype as cisco:ios. I can run manual searches and that displays the data in the index files. If I copy the search string from the XML source file and edit the dashboards, it picks the data from the index. Please provide a solution since I don't want to manually copy the search string for all the dashboards. I have tried deleting the apps from the server and reinstalling it. Splunk version is 6.1.1 and running on Windows server.

0 Karma

mikaelbje
Motivator

You will need Splunk 6.2+ or higher I believe due to new features in the search. Otherwise you may try an older version of the Cisco Networks App which uses the old functions to call searches from dashboards.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...