All Apps and Add-ons

SiteName key causing failed dashboard searches

Shayde_Nofziger
Engager

My team is working on trying to get the Citrix Template up and running on our dashboard. We've found that many of the performance queries that include "SiteName=%sitename%" cause 0 results to be returned. Upon omitting this field in the search, the visualizations populate as they should. What is this SiteName value, and where should it be coming in through our data?

0 Karma

michael_mcgrail
Engager

I know this question is quite old, but if others run into this....
We had this same issue. Upon investigation, we have VDAs returning lower-case host names to the xd_perfmon index but UPPERCASE hostnames in the SiteInfo lookup. If you're on Splunk 7+, navigate to Lookups > Lookup definitions > siteHosts > Advanced options > uncheck Case sensitive match.

0 Karma

allenbraginsky
New Member

I also have this problem. I ran the search and it generated no results. If i remove it from the search then the dashboards work. Do i have to manually build a lookup file? If so, what is the syntax i would follow.

Thank you.
-Allen

0 Karma

richgalloway
SplunkTrust
SplunkTrust

@allenbraginsky This thread is almost two years old. To better your chances of getting help, you should post a new question.

---
If this reply helps you, Karma would be appreciated.
0 Karma

jconger
Splunk Employee
Splunk Employee

The template was built to support multiple XenDesktop sites. The PowerShell scripts in the TA-XD7-Broker add-on populate the SiteName value. This allows you to look at all XenDesktop sites, or just a particular XenDesktop site.

What do you get if you run the following search:

`xd_index` | stats count by SiteName
0 Karma

hainesac
Loves-to-Learn

I have the same issue. When I run the GetXDSite7.ps1 script, I receive the following error message:

WARNING: Only first 250 records returned. Use -MaxRecordCount to retrieve more.

0 Karma

hainesac
Loves-to-Learn

Running xd_index | stats count by SiteName, I received "No results yet found"

0 Karma

pgreer_splunk
Splunk Employee
Splunk Employee

Which dashboard/visualization are you referring to?

0 Karma
Get Updates on the Splunk Community!

Splunk is Nurturing Tomorrow’s Cybersecurity Leaders Today

Meet Carol Wright. She leads the Splunk Academic Alliance program at Splunk. The Splunk Academic Alliance ...

Part 2: A Guide to Maximizing Splunk IT Service Intelligence

Welcome to the second segment of our guide. In Part 1, we covered the essentials of getting started with ITSI ...

Part 1: A Guide to Maximizing Splunk IT Service Intelligence

As modern IT environments continue to grow in complexity and speed, the ability to efficiently manage and ...