All Apps and Add-ons

Input built via Splunk Add-on Builder not indexing data

anirbandasdeb
Path Finder

Hello Splunkers,

I am trying my hand at building modular inputs using the Splunk AoB, and following the walk-through examples provided for REST API at http://dev.splunk.com/view/addon-builder/SP-CAAAFCA . Followed the steps right down to each word to get a feel of the app..

I used the same set of API for NYTimes. The tests performed while building the input worked and provided output JSON.
The Interval is set for 30s.

I have created two inputs, indexing data to two separate indexes.
However, data is not indexed.

There is no activity logged by the two inputs in the _internal index as well.

I have restarted Splunk, but no result as well.

The AoB docs do not mention anything about indexing data via the created Add Ons

Can someone please help?

Note: I am running the created Add-On on the same instance as the AoB.. does taht make any difference?

0 Karma

chli_splunk
Splunk Employee
Splunk Employee

AoB test works but data input doesn't work? I guess sth wrong with your data input or environment, since there should be some logs in _internal at least, either from splunkd or addon.
Sorry I cannot triage it without more details, like the code, addon package, splunk diag, etc. You can try to contact a support, create a JIRA and upload your diag. Thanks.

RickbondPNT
Engager

Anirbandasdeb, what step did you miss. I also have the rest api getting data with Test, but nothing when i want to configure data or validate.

0 Karma

nkaplan_splunk
Splunk Employee
Splunk Employee

FYI, the updated location of the Splunk Add-on Builder documentation is https://docs.splunk.com/Documentation/AddonBuilder/3.0.1/UserGuide/UseTheApp

0 Karma

anirbandasdeb
Path Finder

It turns out that I did not follow everything right down to the word in the walkthrough. 😛

it is successfully indexing data now.

0 Karma

phepales
Loves-to-Learn Everything

Hello Splunkers,

I am trying my hand at building modular inputs using the Splunk AoB, and following the walk-through examples provided for REST API
The tests performed while building the input worked and provided output in XML.
The Interval is set for 300s.

I have created one inputs, indexing data to one index.
However, data is not indexed.

There is some activity logged by the input in the _internal index as well.

I have restarted Splunk, but no result as well.

I have set my props and transform conf for extraction.

The AoB docs do not mention anything about indexing data via the created Add Ons

Can someone please help?

Note: I am running the created Add-On on the same instance as the AoB.. does taht make any difference?

Thanks in Advance!!!

0 Karma
Get Updates on the Splunk Community!

Monitoring Postgres with OpenTelemetry

Behind every business-critical application, you’ll find databases. These behind-the-scenes stores power ...

Mastering Synthetic Browser Testing: Pro Tips to Keep Your Web App Running Smoothly

To start, if you're new to synthetic monitoring, I recommend exploring this synthetic monitoring overview. In ...

Splunk Edge Processor | Popular Use Cases to Get Started with Edge Processor

Splunk Edge Processor offers more efficient, flexible data transformation – helping you reduce noise, control ...