All Apps and Add-ons

Splunk App for Infrastructure

pietertruter1
Observer

I have installed V2.02 of the app and configured manual performance metrics inputs to Windows hosts with UF already installed. Problem is that the Overview dashboard panels are not working. | inputlookup em_entities is returning results for my hosts, but I notice that the metric_name fields are all small caps and the dashboard searches are looking for metric_names that is not all small caps: avg(Processor.%_Privileged_Time). If I change the metric names in the search to all small caps the searches run without issues.
If I read the metrics index documentation it states that you can only use small caps in the metric names.

Am I missing something when creating the manual inputs? Field alias also does not seem to be working either and I also cant find where to edit the dashboards to change the metric names.

Any suggestions welcome? Short from recreating all the dashboards to my own Im out of ideas.

Thanks
Pieter

0 Karma

pietertruter1
Observer

So we are on 7.3.3 on the Search head, but our indexers are still on 7.1.* which we are planning to upgrade soon.

Thanks for the quick answer. Will test again after our indexers are upgraded as well.

0 Karma

dagarwal_splunk
Splunk Employee
Splunk Employee

Yeah.. your indexers are the problem.. It needs to be 7.2 or higher.

0 Karma

dagarwal_splunk
Splunk Employee
Splunk Employee

Are you using Splunk version 7.1.* for your SAI? If yes, please upgrade version to 7.2 or higher..

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Mastering Threat Intelligence in ES 8.5, Splunk AI Assistant v2, and More from Splunk ...

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...

Break the Build: Inside the KubeDoom Lounge at .conf26

    You step up to the machine. The pixelated corridors of a certain 1993 FPS load in front of you, EMP Pulse ...

Splunk Auto Ingestion Parallel Pipeline Scaling

Why this feature matters Many Splunk environments experience ingestion pressure long before the host is fully ...