All Apps and Add-ons
Highlighted

Re: Jenkins data indexing into Splunk, dashboards all blank

Builder

You have mentioned that you have deployed the app via Search head cluster deployer which is fine, but you need to copy indexes.conf and props.conf from default folder on the app to indexers and in case of indexer cluster to this directory $SPLUNKHOME/etc/master-apps/cluster/local/ on cluster master, then run "splunk apply cluster-bundle".

This is because indexed extractions need to be applied during indexing time.

as per props.conf doc (http://docs.splunk.com/Documentation/Splunk/6.6.0/Admin/Propsconf)

 Structured Data Header Extraction and configuration

 * This feature and all of its settings apply at input time, when data is
   first read by Splunk.  The setting is used on a Splunk system that has
   configured inputs acquiring the data.

Regards

0 Karma
Highlighted

Re: Jenkins data indexing into Splunk, dashboards all blank

New Member

We had the same issue, and in the end it was because we had the HEC Jenkins was pushing data to on a heavy forwarder, so the props.conf needs installing on there as well.

Regards
Andy

0 Karma