All Apps and Add-ons

Splunk App for Microsoft Exchange: Why am I seeing these errors throughout various dashboards?

davidjohnbecket
Path Finder

Hi all,

After successfully installing a POC of the App: Splunk App for Microsoft Exchange in my test environment i went ahead and installed and configured this in production.

We run a search head cluster and index cluster, Splunk Version 6.5.2

I have run through the Guided Setup and all looks to be ok.

However, there are several errors i am seeing throughout the various dashboards.

Error 1: Exchange Service Analyzer - Error in 'map': Did not find value for required attribute 'time'.

alt text

Error 2: Host Overview - returns data however you see an ! triangle and notified that there are missing lookup tables

[IndexServer1] The lookup table 'hostInformation' does not exist. It is referenced by configuration 'source::...(service|process)...'.
[IndexServer1] The lookup table 'hostInformation' does not exist. It is referenced by configuration 'source::...Perfmon...'.
[IndexServer2] The lookup table 'hostInformation' does not exist. It is referenced by configuration 'source::...(service|process)...'.
[IndexServer2] The lookup table 'hostInformation' does not exist. It is referenced by configuration 'source::...Perfmon...'.

I have built the look ups again, and rebuilt the Data Models but none of this has helped.

Where should the lookup table 'hostInformation' be located? I can only see the 17 default lookups in the app:

alt text

Any ideas?

0 Karma

ansif
Motivator

Go through the documentation again. I came across this kind of issue and when I check the supported ad add on is missing,once I added everything was working.

In your case just go thru the documentation again.

0 Karma

adonio
Ultra Champion

did you configure the app first on the deployer and then pushed the configured Exchange app to the search heads?

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...