All Apps and Add-ons

Splunk App for Web Analytics: How to resolve missing data?

jgauthier
Contributor

I've read several threads on this already, as well as have been over the documentation. I'm not sure what I've done incorrectly.

Quick summary:

Apache data is going into Splunk. Source type is apache:access. I added this to the [web-traffic] section in eventtypes.conf:

[OR sourcetype="apache:access"]

The logs are going to the 'main' index, which my user has access to.
The lookups under "setup" do not return any data, nor does eventtype=web-traffic
However, tag=web does work in the app context.

"Data model audit" also does not return data. (and acceleration says 0)

What am I missing with this?

Thanks!

0 Karma

jbjerke_splunk
Splunk Employee
Splunk Employee

Hi jgauthier

The apache:access sourcetype does not extract all the fields you require for this app out of the box. Make sure that all field extractions that are currently mapped to sourcetype access_combined are also mapped to apache:access. You can do this by making a copy of props.conf in the "default" folder into the "local" folder and edit the section with field extractions linked to "access"combined"/

Let me know how you get along.

johan

0 Karma

woodcock
Esteemed Legend

What "lookups under setup"? It will really help if you provide a more complete context and fuller framing of your problem including sample events and searches.

0 Karma

jgauthier
Contributor

Are you familiar with the application?

From the instructions:
Once the data has been imported run the two lookups "Generate user sessions" and "Generate pages".

They are the only two lookups under 'Setup' in the context of the application.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...