All Apps and Add-ons

Splunk App for Dropbox for Business: 30,000 events were added to the dfb index, but why is no data shown in the main dashboard?

brightedge
Explorer

I just installed Dropbox app, and set up OAuth and integrated with Dropbox Business. I see that dfb index has been created for the Dropbox app, and more than 30,000 events were added to the dfb index. However, I still do not see anything from the Dropbox App main dashboard. What am I missing?

0 Karma
1 Solution

brightedge
Explorer

Here is the answer that came from Splunk support that fixed this problem for us:
"It turned out that the app was not designed for a clustered envirnment. We found that the eventtype was calling for a macro.conf that was not being pushed out to the indexers when the search was made. We then changed the eventtype to look at the index itself and it started to work. I have emailed the publisher to fix this in his app and hope to see a new one published soon." -Splunk Support

View solution in original post

brightedge
Explorer

Here is the answer that came from Splunk support that fixed this problem for us:
"It turned out that the app was not designed for a clustered envirnment. We found that the eventtype was calling for a macro.conf that was not being pushed out to the indexers when the search was made. We then changed the eventtype to look at the index itself and it started to work. I have emailed the publisher to fix this in his app and hope to see a new one published soon." -Splunk Support

jconger
Splunk Employee
Splunk Employee

A lot of the dashboards default to the last 7 days. It may take a while for the app to collect enough data to show up for that time frame as the app only collects about 1000 events every 60 seconds. This collection starts from the beginning of your Dropbox data. Try changing your time range to All Time to see if the dashboards populate.

0 Karma

ian0nline
New Member

I have installed the app without issue and as above had no data fro the last 7 days, upon finding this post I changed it to "All Time" and saw data being imported from the start of the year, which was when we started using DFB. Again it was importing approx. 1000 records every minute so I left it to run over the weekend and now have over 4.5 million records pulled in but still only have a few days in the time line. The data looks like it is being duplicated. Any idea's gratefully received?

0 Karma

brightedge
Explorer

Hi, I just tested with "All Time", but it is still not showing anything.

However, I just noticed one odd thing -- somehow the Source Type "dfb:activity" is not showing up in the "Source Types" list. So I tried to manually create one, but the system says that the source type already exists and thus it won't let me manually create one. I wonder why "dfb:activity" is not showing up in the Source Types list?

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...