All Apps and Add-ons

SiteName key causing failed dashboard searches

Shayde_Nofziger
Engager

My team is working on trying to get the Citrix Template up and running on our dashboard. We've found that many of the performance queries that include "SiteName=%sitename%" cause 0 results to be returned. Upon omitting this field in the search, the visualizations populate as they should. What is this SiteName value, and where should it be coming in through our data?

0 Karma

michael_mcgrail
Engager

I know this question is quite old, but if others run into this....
We had this same issue. Upon investigation, we have VDAs returning lower-case host names to the xd_perfmon index but UPPERCASE hostnames in the SiteInfo lookup. If you're on Splunk 7+, navigate to Lookups > Lookup definitions > siteHosts > Advanced options > uncheck Case sensitive match.

0 Karma

allenbraginsky
New Member

I also have this problem. I ran the search and it generated no results. If i remove it from the search then the dashboards work. Do i have to manually build a lookup file? If so, what is the syntax i would follow.

Thank you.
-Allen

0 Karma

richgalloway
SplunkTrust
SplunkTrust

@allenbraginsky This thread is almost two years old. To better your chances of getting help, you should post a new question.

---
If this reply helps you, Karma would be appreciated.
0 Karma

jconger
Splunk Employee
Splunk Employee

The template was built to support multiple XenDesktop sites. The PowerShell scripts in the TA-XD7-Broker add-on populate the SiteName value. This allows you to look at all XenDesktop sites, or just a particular XenDesktop site.

What do you get if you run the following search:

`xd_index` | stats count by SiteName
0 Karma

hainesac
Loves-to-Learn

I have the same issue. When I run the GetXDSite7.ps1 script, I receive the following error message:

WARNING: Only first 250 records returned. Use -MaxRecordCount to retrieve more.

0 Karma

hainesac
Loves-to-Learn

Running xd_index | stats count by SiteName, I received "No results yet found"

0 Karma

pgreer_splunk
Splunk Employee
Splunk Employee

Which dashboard/visualization are you referring to?

0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...