All Apps and Add-ons

Splunk app for infrastructure is not showing entities and im receving events, i did all te troubleshooting task!! Help!!

carlosmacario
New Member

I have Installed Splunk App For Infrastructure and Splunk add-on for infrastructure.
I have configured the HEC 8088 and the Receiving Port 9997.
I have installed a Linux Client with the script.
I made troubleshooting.
In Splunk Enterprise im looking metrics arriving from that customers

I Dont See New Entities Connected!!

😞

Tags (2)
0 Karma

woodcock
Esteemed Legend

You need to specify ALL of the details and the configuration files and the contents of them. This is a complex pipeline and you've hardly told us anything.

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi carlosmacario,
check if in the eventtypes there are indexes: usually in these apps there isn't the flter for indexes.
you can check this opening in search one panel and adding the filter index=your_index

To solve this problem, you could choose between two solutions:

  • put the indexes in the default search path [ Settings -- Access Controls -- Roles -- -- Indexes];
  • create an eventtype with index=your_index and put this eventtype in each eventtype or macro of your App.

I prefer the second though it requests more work, because it's more clear and more performant.

Ciao.
Giuseppe

0 Karma
Get Updates on the Splunk Community!

Index This | Why did the turkey cross the road?

November 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...