I have a distributed environment which is running on version 6.6.2.
I have installed the Riverbed Steelhead Technology Add-on in it.
Currently I am unable to see the prebuilt panel in the app.
While checking for the logs for the steelhead logs I can see that in Splunk.
Could you please help me in guiding to set up this add-on to be working?
Thanks & Regards,
I would like to confirm that you are referring to the following Splunk Add-on/App:
If these are the Add-on/App that you are referring to being installed the issue that you are experiencing is the last Supported Version of Splunk the Add-on/Apps were validated against were Splunk 5.0 and as such are most likely not supported in Splunk 6.6.2.
There have been many changes to the Splunk Software since Splunk 5.0 and there are many Apps/Add-ons that were developed for Splunk 5.0 that the Original Developer of the App/Add-on did not update the code of the Tool to work with the most recent version of Splunk.
Unfortunately the Add-on/App is not viable for use with Splunk 6.x or Splunk 7.x.
I have this working in 6.6.3. The saved searches are looking for data with a sourcetype of riverbedsteelhead and indexes of main, riverbedinfo, and riverbed_notice. If this does not match the sourcetype or index for your steelhead logs, you can edit the saved searches. Try running them manually and changing things until you get them to work.