All Apps and Add-ons

Search Activity application Overall Metrics and Search acitvity dashboard not completely working

gjanders
SplunkTrust
SplunkTrust

I have the Search Activity application installed in Splunk 6.2.5 https://splunkbase.splunk.com/app/2632/
I initially had it on a search head cluster which after some period of testing did appear to be working, but it is not a recommended setup.

I have since moved it to the license master/deployment and deployer server which has no applications installed.

After a full 12 months of backfill, the search activity dashboard shows "Search produced no results" under the search head criteria. I had the same issue when running it on other search heads.

The "Top Apps and Views" appears to work just fine, and the overall metrics appear to show 0 results.

The troubleshooting TSIDX population shows all data is up to date and I have approx 10 months of data within the index and I cannot see any errors. Search history is marked as "Backfill Complete" and Events is makred as "0" seconds remaining.
The only item I notice is a lot of 404 errors on the URL /servicesNS/admin/search_activity/properties/macros/backfill_search_window/definition?count=0 by the splunk-system-user.

Is there something I have done wrong here?

0 Karma

David
Splunk Employee
Splunk Employee

Hi!

The 404 errors are likely a red herring -- the command to update the macro will try a few different permissions models, to account for some quirks around how the REST API functions.

I'll follow up with you via your support ticket -- let's schedule a webex to troubleshoot what's going on.

Thanks,
David

gjanders
SplunkTrust
SplunkTrust

David, I have been unable to get in contact with you since the email in September.

If there is anyone else who has an idea of how I can troubleshoot this further please let me know.

0 Karma

gjanders
SplunkTrust
SplunkTrust
0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...