All Apps and Add-ons

Splunk App for Microsoft Exchange: Why am I seeing these errors throughout various dashboards?

davidjohnbecket
Path Finder

Hi all,

After successfully installing a POC of the App: Splunk App for Microsoft Exchange in my test environment i went ahead and installed and configured this in production.

We run a search head cluster and index cluster, Splunk Version 6.5.2

I have run through the Guided Setup and all looks to be ok.

However, there are several errors i am seeing throughout the various dashboards.

Error 1: Exchange Service Analyzer - Error in 'map': Did not find value for required attribute 'time'.

alt text

Error 2: Host Overview - returns data however you see an ! triangle and notified that there are missing lookup tables

[IndexServer1] The lookup table 'hostInformation' does not exist. It is referenced by configuration 'source::...(service|process)...'.
[IndexServer1] The lookup table 'hostInformation' does not exist. It is referenced by configuration 'source::...Perfmon...'.
[IndexServer2] The lookup table 'hostInformation' does not exist. It is referenced by configuration 'source::...(service|process)...'.
[IndexServer2] The lookup table 'hostInformation' does not exist. It is referenced by configuration 'source::...Perfmon...'.

I have built the look ups again, and rebuilt the Data Models but none of this has helped.

Where should the lookup table 'hostInformation' be located? I can only see the 17 default lookups in the app:

alt text

Any ideas?

0 Karma

ansif
Motivator

Go through the documentation again. I came across this kind of issue and when I check the supported ad add on is missing,once I added everything was working.

In your case just go thru the documentation again.

0 Karma

adonio
Ultra Champion

did you configure the app first on the deployer and then pushed the configured Exchange app to the search heads?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Network to App: Observability Unlocked [May & June Series]

In today’s digital landscape, your environment is no longer confined to the data center. It spans complex ...

SPL2 Deep Dives, AppDynamics Integrations, SAML Made Simple and Much More on Splunk ...

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...