All Apps and Add-ons

Status Indicator - Custom Visualization: Why do I have a broken dashboard and see strange tar behavior?

SierraX
Communicator

Hi,

Just downloaded the Status Indicator - Custom Visualization App ( https://splunkbase.splunk.com/app/3119/ ) (about small Karma splunkbase 3119)
and the panels looks ... I link a pic:
viz_test
This was on a fresh Mac OS X - Splunk 6.4 installation, installed with the webUI, but it looks the same on an installation via deployment server on a 6.4.0 Centos 7.1 Search Head.

The tar command to untar the .tgz to right folder shows some strange behavior:

tar: Ignoriere unbekanntes Schlüsselwort „LIBARCHIVE.creationtime“ für erweiterten Kopfteil
tar: Ignoriere unbekanntes Schlüsselwort „SCHILY.dev“ für erweiterten Kopfteil
tar: Ignoriere unbekanntes Schlüsselwort „SCHILY.ino“ für erweiterten Kopfteil
tar: Ignoriere unbekanntes Schlüsselwort „SCHILY.nlink“ für erweiterten Kopfteil

adds the last 3 lines of the list, in front of every line to extract.

For the non-German speakers:

tar: Ignore unknown keyword "*" for enhanced header.

Is there a fix scheduled?

0 Karma
1 Solution

magnew_splunk
Splunk Employee
Splunk Employee

Hi SierraX,

It looks like this is a test dashboard that was mistakenly shipped with the visualization. Do you see similar issues in the app's main 'gallery' dashboard? We'll make sure to remove the test dashboard in going forward.

View solution in original post

0 Karma

magnew_splunk
Splunk Employee
Splunk Employee

Hi SierraX,

It looks like this is a test dashboard that was mistakenly shipped with the visualization. Do you see similar issues in the app's main 'gallery' dashboard? We'll make sure to remove the test dashboard in going forward.

View solution in original post

0 Karma

ziegfried
Influencer

Don't worry about the tar warning messages. This is just some additional metadata the tar on OSX included. It's shouldn't cause any problems.

SierraX
Communicator

But looks not nice and professional anyway.

0 Karma
.conf21 CFS Extended through 5/20!

Don't miss your chance
to share your Splunk
wisdom in-person or
virtually at .conf21!

Call for Speakers has
been extended through
Thursday, 5/20!