All Apps and Add-ons

Splunk app for infrastructure is not showing entities and im receving events, i did all te troubleshooting task!! Help!!

carlosmacario
New Member

I have Installed Splunk App For Infrastructure and Splunk add-on for infrastructure.
I have configured the HEC 8088 and the Receiving Port 9997.
I have installed a Linux Client with the script.
I made troubleshooting.
In Splunk Enterprise im looking metrics arriving from that customers

I Dont See New Entities Connected!!

😞

Tags (2)
0 Karma

woodcock
Esteemed Legend

You need to specify ALL of the details and the configuration files and the contents of them. This is a complex pipeline and you've hardly told us anything.

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi carlosmacario,
check if in the eventtypes there are indexes: usually in these apps there isn't the flter for indexes.
you can check this opening in search one panel and adding the filter index=your_index

To solve this problem, you could choose between two solutions:

  • put the indexes in the default search path [ Settings -- Access Controls -- Roles -- -- Indexes];
  • create an eventtype with index=your_index and put this eventtype in each eventtype or macro of your App.

I prefer the second though it requests more work, because it's more clear and more performant.

Ciao.
Giuseppe

0 Karma
Get Updates on the Splunk Community!

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...

Data Management Digest – November 2025

  Welcome to the inaugural edition of Data Management Digest! As your trusted partner in data innovation, the ...