All Apps and Add-ons

Cisco Networks App for Splunk Enterprise: Why am I getting error "No Search Query Provided" on all dashboards in Splunk 6.1.1?

pksarkar
New Member

All the Cisco Networks App for Splunk Enterprise dashboards are blank with the error "No Search Query Provided". The data from the syslog is present in the index and shows the sourcetype as cisco:ios. I can run manual searches and that displays the data in the index files. If I copy the search string from the XML source file and edit the dashboards, it picks the data from the index. Please provide a solution since I don't want to manually copy the search string for all the dashboards. I have tried deleting the apps from the server and reinstalling it. Splunk version is 6.1.1 and running on Windows server.

0 Karma

mikaelbje
Motivator

You will need Splunk 6.2+ or higher I believe due to new features in the search. Otherwise you may try an older version of the Cisco Networks App which uses the old functions to call searches from dashboards.

0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...