I have successfully installed the Git Version Control for Splunk app on my local environment. However, when I set it up in our prod environment I'm getting the following error: "No results found".
Can someone help me resolve the error?
Hi @dshatto
If you have followed all the instructions but the dashboard is empty, it is probably because you changed the index where the logs are stored. The dashboard expects the logs to be in the _internal index. If you used something else, edit the dashboard and change the searche/s to use that index instead.
Hope this helps,
Chris
I have the app working in a local test environment and now trying to get it working in production. Have installed and it is configured for _internal for index but no results are found. Have done a search for index=_internal and there is nothing. I created a report and saved it to see if it would pick that up but nothing.
I am sorry but I have no thoughts about why you would not be receiving any data at all. It sounds like the script is not being started correctly by Splunk itself. As soon as the script starts it will at the very least print the system time. I would check that the input is enabled, but it sounds like you have probably already done this.