All Apps and Add-ons

Input built via Splunk Add-on Builder not indexing data

anirbandasdeb
Path Finder

Hello Splunkers,

I am trying my hand at building modular inputs using the Splunk AoB, and following the walk-through examples provided for REST API at http://dev.splunk.com/view/addon-builder/SP-CAAAFCA . Followed the steps right down to each word to get a feel of the app..

I used the same set of API for NYTimes. The tests performed while building the input worked and provided output JSON.
The Interval is set for 30s.

I have created two inputs, indexing data to two separate indexes.
However, data is not indexed.

There is no activity logged by the two inputs in the _internal index as well.

I have restarted Splunk, but no result as well.

The AoB docs do not mention anything about indexing data via the created Add Ons

Can someone please help?

Note: I am running the created Add-On on the same instance as the AoB.. does taht make any difference?

0 Karma

chli_splunk
Splunk Employee
Splunk Employee

AoB test works but data input doesn't work? I guess sth wrong with your data input or environment, since there should be some logs in _internal at least, either from splunkd or addon.
Sorry I cannot triage it without more details, like the code, addon package, splunk diag, etc. You can try to contact a support, create a JIRA and upload your diag. Thanks.

RickbondPNT
Engager

Anirbandasdeb, what step did you miss. I also have the rest api getting data with Test, but nothing when i want to configure data or validate.

0 Karma

nkaplan_splunk
Splunk Employee
Splunk Employee

FYI, the updated location of the Splunk Add-on Builder documentation is https://docs.splunk.com/Documentation/AddonBuilder/3.0.1/UserGuide/UseTheApp

0 Karma

anirbandasdeb
Path Finder

It turns out that I did not follow everything right down to the word in the walkthrough. 😛

it is successfully indexing data now.

0 Karma

phepales
Loves-to-Learn Everything

Hello Splunkers,

I am trying my hand at building modular inputs using the Splunk AoB, and following the walk-through examples provided for REST API
The tests performed while building the input worked and provided output in XML.
The Interval is set for 300s.

I have created one inputs, indexing data to one index.
However, data is not indexed.

There is some activity logged by the input in the _internal index as well.

I have restarted Splunk, but no result as well.

I have set my props and transform conf for extraction.

The AoB docs do not mention anything about indexing data via the created Add Ons

Can someone please help?

Note: I am running the created Add-On on the same instance as the AoB.. does taht make any difference?

Thanks in Advance!!!

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Unlocking Unified Insights: New Gigamon Federated Search App for Splunk

In today’s data-heavy environment, organizations are caught in a data distribution dilemma. As data volumes ...

GA: New Data Management App in Splunk Platform

Streamlining Data Management: Introducing a unified experience in Splunk Managing data at scale shouldn’t feel ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...