All Apps and Add-ons

Initial setup,Not seeing any data

rohithashok
Engager

I've gotten my FIOS router setup and forwarding and I think I've gotten the data input setup correctly. I can search the data. However the dashboard is not showing any data. Is there any configuration I'm missing between the data input and the dashboard? thanks!,I've setup the FIOS router and I've got the data input. I can see the data input and search it, however the dashboard isn't finding anything. I also can not change the source type if that's significant. It remains grayed out. Am I missing something obvious? thanks!

Tags (1)

amiracle
Splunk Employee
Splunk Employee

Have you checked out the latest version of the app (4.1.1)? Did that help with the issue you saw with your initial setup?

Thanks,
Kam

0 Karma

amiracle
Splunk Employee
Splunk Employee

Which dashboards are not populating? Typically it's because the fields have been changed, either due to an update by Verizon, or because the hostname might be coming in different than expected. Do me a favor and paste one of your events into this comment section and I'll see what can be the problem with your data. You can obfuscate your hostname and IP's, but leave the 'structure' in tact.

rohithashok
Engager

Here is a sample event, I changed some random digits in the IP. I'm not seeing anything on the Traffic Flow, Duration or the main dashboard. I do see the IP. I'm not convinced I'm getting enough events to support all the data, although I did double check the system logging and security logging is enabled.

thanks

Mar 27 15:23:09 192.168.1.1 Mar 27 15:23:07 2015 FIOS_Router OUT: ACCEPT [57] Connection closed ( : UDP 192.168.1.35:5353 <-->174.26.225.26:5353 [224.0.0.251:5353] eth1 NAPT Outgoing FP-CAP )

amiracle
Splunk Employee
Splunk Employee

Sorry for the delay, but I've modified the app (3.2.1), check it out and see if that helps you with your problem.

Thanks,
Kam

Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...