All Apps and Add-ons

Input built via Splunk Add-on Builder not indexing data

anirbandasdeb
Path Finder

Hello Splunkers,

I am trying my hand at building modular inputs using the Splunk AoB, and following the walk-through examples provided for REST API at http://dev.splunk.com/view/addon-builder/SP-CAAAFCA . Followed the steps right down to each word to get a feel of the app..

I used the same set of API for NYTimes. The tests performed while building the input worked and provided output JSON.
The Interval is set for 30s.

I have created two inputs, indexing data to two separate indexes.
However, data is not indexed.

There is no activity logged by the two inputs in the _internal index as well.

I have restarted Splunk, but no result as well.

The AoB docs do not mention anything about indexing data via the created Add Ons

Can someone please help?

Note: I am running the created Add-On on the same instance as the AoB.. does taht make any difference?

0 Karma

chli_splunk
Splunk Employee
Splunk Employee

AoB test works but data input doesn't work? I guess sth wrong with your data input or environment, since there should be some logs in _internal at least, either from splunkd or addon.
Sorry I cannot triage it without more details, like the code, addon package, splunk diag, etc. You can try to contact a support, create a JIRA and upload your diag. Thanks.

RickbondPNT
Engager

Anirbandasdeb, what step did you miss. I also have the rest api getting data with Test, but nothing when i want to configure data or validate.

0 Karma

nkaplan_splunk
Splunk Employee
Splunk Employee

FYI, the updated location of the Splunk Add-on Builder documentation is https://docs.splunk.com/Documentation/AddonBuilder/3.0.1/UserGuide/UseTheApp

0 Karma

anirbandasdeb
Path Finder

It turns out that I did not follow everything right down to the word in the walkthrough. 😛

it is successfully indexing data now.

0 Karma

phepales
Loves-to-Learn Everything

Hello Splunkers,

I am trying my hand at building modular inputs using the Splunk AoB, and following the walk-through examples provided for REST API
The tests performed while building the input worked and provided output in XML.
The Interval is set for 300s.

I have created one inputs, indexing data to one index.
However, data is not indexed.

There is some activity logged by the input in the _internal index as well.

I have restarted Splunk, but no result as well.

I have set my props and transform conf for extraction.

The AoB docs do not mention anything about indexing data via the created Add Ons

Can someone please help?

Note: I am running the created Add-On on the same instance as the AoB.. does taht make any difference?

Thanks in Advance!!!

0 Karma
Get Updates on the Splunk Community!

New in Observability - Improvements to Custom Metrics SLOs, Log Observer Connect & ...

The latest enhancements to the Splunk observability portfolio deliver improved SLO management accuracy, better ...

Improve Data Pipelines Using Splunk Data Management

  Register Now   This Tech Talk will explore the pipeline management offerings Edge Processor and Ingest ...

3-2-1 Go! How Fast Can You Debug Microservices with Observability Cloud?

Register Join this Tech Talk to learn how unique features like Service Centric Views, Tag Spotlight, and ...