All Apps and Add-ons

Splunk App for Microsoft Exchange: Why am I seeing these errors throughout various dashboards?

davidjohnbecket
Path Finder

Hi all,

After successfully installing a POC of the App: Splunk App for Microsoft Exchange in my test environment i went ahead and installed and configured this in production.

We run a search head cluster and index cluster, Splunk Version 6.5.2

I have run through the Guided Setup and all looks to be ok.

However, there are several errors i am seeing throughout the various dashboards.

Error 1: Exchange Service Analyzer - Error in 'map': Did not find value for required attribute 'time'.

alt text

Error 2: Host Overview - returns data however you see an ! triangle and notified that there are missing lookup tables

[IndexServer1] The lookup table 'hostInformation' does not exist. It is referenced by configuration 'source::...(service|process)...'.
[IndexServer1] The lookup table 'hostInformation' does not exist. It is referenced by configuration 'source::...Perfmon...'.
[IndexServer2] The lookup table 'hostInformation' does not exist. It is referenced by configuration 'source::...(service|process)...'.
[IndexServer2] The lookup table 'hostInformation' does not exist. It is referenced by configuration 'source::...Perfmon...'.

I have built the look ups again, and rebuilt the Data Models but none of this has helped.

Where should the lookup table 'hostInformation' be located? I can only see the 17 default lookups in the app:

alt text

Any ideas?

0 Karma

ansif
Motivator

Go through the documentation again. I came across this kind of issue and when I check the supported ad add on is missing,once I added everything was working.

In your case just go thru the documentation again.

0 Karma

adonio
Ultra Champion

did you configure the app first on the deployer and then pushed the configured Exchange app to the search heads?

0 Karma
Get Updates on the Splunk Community!

What's new in Splunk Cloud Platform 9.1.2312?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.1.2312! Analysts can ...

What’s New in Splunk Security Essentials 3.8.0?

Splunk Security Essentials (SSE) is an app that can amplify the power of your existing Splunk Cloud Platform, ...

Let’s Get You Certified – Vegas-Style at .conf24

Are you ready to level up your Splunk game? Then, let’s get you certified live at .conf24 – our annual user ...