Hi everyone, I'm sure this is a question that's been answered before, but my google-fu is failing me. I am running Splunk Cloud 8.2 (Victoria), Salesforce App for Splunk version 4.11, and Splunk Add-on for Salesforce version 4.4.0-1651043262. I have the Salesforce app configured and data inputs set and I have data in my index from all the sources:
What I don't have, however, is literally any data populating any of my dashboards:
I'm wondering if it has anything to do with the lookup tables being broken:
I have enabled the saved search and run it, successfully (per the Add-on docs); however, the App docs have saved Lookup searches that, when I run, don't return data:
So the lookups aren't populated. Also there are only 3 lookups, not 4 like in the docs. I'm sure I'm missing something *very* simple; but anyone have any ideas?
That index may need to be set to default searchable to be picked up by the populating search. Or edit the search to specify the index.
Yes, my data is fully populated in the index, and I have run the searches; however as I indicated, they return nothing and thus do not populate the LOOKUP files
That index may need to be set to default searchable to be picked up by the populating search. Or edit the search to specify the index.
Ok, so progress! Adding the index fixed the Account_Id to Account_Name Lookup; thanks, I should have thought of that 😞
https://splunkbase.splunk.com/app/1931/#/details
Try that?
As far as I can tell, this app does not function.
I base this on extensive troubleshooting with Splunk tech support.
There is no support. It doesn't work.
Personally I believe it should be removed from Splunkbase.