All Apps and Add-ons

Splunk for Palo Alto Networks 4.2.2 and Splunk 6.3.0 : I am receiving and can search logs, but why is the dashboard not populating?

phamel
New Member

Hi,

Splunk for Palo Alto Networks 4.2.2 and Splunk 6.3.0, dashboard not populating. I'm receiving logs and can search on them, but dashboards are empty.

Thanks,
Patrick

0 Karma

Richfez
SplunkTrust
SplunkTrust

I'd guess:

The app assumes your data is in a "searched by default" index, and maybe it isn't any more.
The app uses an 'index=blah' or a macro that loads a line like that and the index it points to is wrong.
The app uses tags, events or both, and those are no longer being applied correctly.

I know of no magic bullet at this time, you just have to start digging into the searches to see what they are running, then start digging and fiddling to find out why they aren't running.

0 Karma
Get Updates on the Splunk Community!

New This Month - Splunk Observability updates and improvements for faster ...

What’s New? This month, we’re delivering several enhancements across Splunk Observability Cloud for faster and ...

What's New in Splunk Cloud Platform 9.3.2411?

Hey Splunky People! We are excited to share the latest updates in Splunk Cloud Platform 9.3.2411. This release ...

Buttercup Games: Further Dashboarding Techniques (Part 6)

This series of blogs assumes you have already completed the Splunk Enterprise Search Tutorial as it uses the ...