I installed the Splunk Add-on for Box on my heavy forwarder and search head servers. Per the documentation, I configured the app on my heavy forwarder to retrieve events from Box.
While viewing the objects for the Splunk Add-on for Box using the search head server Splunk web app, I noticed there are several panels. How do I make the app visible on the search head servers to obtain access to these panels without needing to perform the setup that retrieves events from Box?
I figured out my problem. I needed to update the permissions for the app to be available for all applications. After doing this, the panels were available in the dashboard editor to be added to a custom dashboard.
I figured out my problem. I needed to update the permissions for the app to be available for all applications. After doing this, the panels were available in the dashboard editor to be added to a custom dashboard.
The documentation says you just install the addon on the heavy forwarder and the search head.
My hunch is your dashboards need the correct index name in their searches. You might have to edit a macro being used by the app to specify the correct index(es). From what I can tell you specify the index when you configure the inputs. So somewhere you've got to align those prebuilt dashboard searches with the index name you used. Maybe you specified one name and then changed it after setup, etc... check your macros in the app and the underlying searches to be sure they're configured for the correct index(es).
http://docs.splunk.com/Documentation/AddOns/latest/Box/Install
Install the Splunk Add-on for Box
Specific installation notes for this add-on
**In a distributed deployment, install the Splunk Add-on for Box to your search heads and heavy forwarders.**
If that doesnt fix it, please open a "broken" dashboard panel in search and look at the job inspector for search.log etc. and update this post any errors and warnings you see.