In SOS the "Instance to query" pulldown is empty.
In "_internal" i see the following error as soon as i click the pulldown:
- Splunk 6.1.1 build 207789 on Suse Linux - Standalone
- Sideview Utils 1.3.5
- Splunk on Splunk version 3.2 - build 207364
It's a fresh Splunk installation, only installed to test SOS. pssos.sh and lsofsos.sh are activated, index sos has values. Lookup splunkserverscache.csv lookes fine (only one entry with "stand-alone indexer" because nothing else connected).
Uncaught SyntaxError: Unexpected token o
Just did a local installation (Windows 7 notebook): No problem:
Splunk.Module.ResultsValueSetter - Although we're still loading the page we have to let modules cache contexts.
success - context dispatched for search= | inputlookup splunkinstancesinfo | search sos_server="***"
Can't replicate that here, so no chance of debugging... just in case you could try cleaning your browser cache in case something broken stuck, and try different version combinations such as the free internal use version of Sideview Utils from http://sideviewapps.com/apps/sideview-utils/ ... that's just fishing in murky waters though.
It does look like the issue is with Sideview Utils' Pulldown module parsing the search results created from the splunkserverscache.csv lookup file. Perhaps our dear @sideview will have some thoughts on this matter.
I found the solution:
The parameter "overrideJSONMIMEtypewithtextplain = True" in "web.conf"causes this problem. Setting it to "False" - this is also the default - solves the problem. SoS works as expected then.
Please don't ask me, why this parameter was set to "True". According to the documentation "this keeps it compatible with previous versions of Splunk". So lessons learned for me: Don't touch parameters you don't really need and understand.
Thanks for your help!