I have the Search Activity application installed in Splunk 6.2.5 https://splunkbase.splunk.com/app/2632/
I initially had it on a search head cluster which after some period of testing did appear to be working, but it is not a recommended setup.
I have since moved it to the license master/deployment and deployer server which has no applications installed.
After a full 12 months of backfill, the search activity dashboard shows "Search produced no results" under the search head criteria. I had the same issue when running it on other search heads.
The "Top Apps and Views" appears to work just fine, and the overall metrics appear to show 0 results.
The troubleshooting TSIDX population shows all data is up to date and I have approx 10 months of data within the index and I cannot see any errors. Search history is marked as "Backfill Complete" and Events is makred as "0" seconds remaining.
The only item I notice is a lot of 404 errors on the URL /servicesNS/admin/search_activity/properties/macros/backfill_search_window/definition?count=0 by the splunk-system-user.
Is there something I have done wrong here?
Hi!
The 404 errors are likely a red herring -- the command to update the macro will try a few different permissions models, to account for some quirks around how the REST API functions.
I'll follow up with you via your support ticket -- let's schedule a webex to troubleshoot what's going on.
Thanks,
David
David, I have been unable to get in contact with you since the email in September.
If there is anyone else who has an idea of how I can troubleshoot this further please let me know.
Search activity application version 2.2.3