All Apps and Add-ons

Is there any set up steps for the Splunk Add-on for Box on Search Head servers?

lyanta
Explorer

I installed the Splunk Add-on for Box on my heavy forwarder and search head servers. Per the documentation, I configured the app on my heavy forwarder to retrieve events from Box.

While viewing the objects for the Splunk Add-on for Box using the search head server Splunk web app, I noticed there are several panels. How do I make the app visible on the search head servers to obtain access to these panels without needing to perform the setup that retrieves events from Box?

0 Karma
1 Solution

lyanta
Explorer

I figured out my problem. I needed to update the permissions for the app to be available for all applications. After doing this, the panels were available in the dashboard editor to be added to a custom dashboard.

View solution in original post

0 Karma

lyanta
Explorer

I figured out my problem. I needed to update the permissions for the app to be available for all applications. After doing this, the panels were available in the dashboard editor to be added to a custom dashboard.

0 Karma

jkat54
SplunkTrust
SplunkTrust

The documentation says you just install the addon on the heavy forwarder and the search head.

My hunch is your dashboards need the correct index name in their searches. You might have to edit a macro being used by the app to specify the correct index(es). From what I can tell you specify the index when you configure the inputs. So somewhere you've got to align those prebuilt dashboard searches with the index name you used. Maybe you specified one name and then changed it after setup, etc... check your macros in the app and the underlying searches to be sure they're configured for the correct index(es).

http://docs.splunk.com/Documentation/AddOns/latest/Box/Install

Install the Splunk Add-on for Box
Specific installation notes for this add-on
**In a distributed deployment, install the Splunk Add-on for Box to your search heads and heavy forwarders.**

If that doesnt fix it, please open a "broken" dashboard panel in search and look at the job inspector for search.log etc. and update this post any errors and warnings you see.

0 Karma
Get Updates on the Splunk Community!

Enter the Splunk Community Dashboard Challenge for Your Chance to Win!

The Splunk Community Dashboard Challenge is underway! This is your chance to showcase your skills in creating ...

.conf24 | Session Scheduler is Live!!

.conf24 is happening June 11 - 14 in Las Vegas, and we are thrilled to announce that the conference catalog ...

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...