All Apps and Add-ons

Status Indicator - Custom Visualization: Why do I have a broken dashboard and see strange tar behavior?

SierraX
Communicator

Hi,

Just downloaded the Status Indicator - Custom Visualization App ( https://splunkbase.splunk.com/app/3119/ ) (about small Karma splunkbase 3119)
and the panels looks ... I link a pic:
viz_test
This was on a fresh Mac OS X - Splunk 6.4 installation, installed with the webUI, but it looks the same on an installation via deployment server on a 6.4.0 Centos 7.1 Search Head.

The tar command to untar the .tgz to right folder shows some strange behavior:

tar: Ignoriere unbekanntes Schlüsselwort „LIBARCHIVE.creationtime“ für erweiterten Kopfteil
tar: Ignoriere unbekanntes Schlüsselwort „SCHILY.dev“ für erweiterten Kopfteil
tar: Ignoriere unbekanntes Schlüsselwort „SCHILY.ino“ für erweiterten Kopfteil
tar: Ignoriere unbekanntes Schlüsselwort „SCHILY.nlink“ für erweiterten Kopfteil

adds the last 3 lines of the list, in front of every line to extract.

For the non-German speakers:

tar: Ignore unknown keyword "*" for enhanced header.

Is there a fix scheduled?

0 Karma
1 Solution

magnew_splunk
Splunk Employee
Splunk Employee

Hi SierraX,

It looks like this is a test dashboard that was mistakenly shipped with the visualization. Do you see similar issues in the app's main 'gallery' dashboard? We'll make sure to remove the test dashboard in going forward.

View solution in original post

0 Karma

magnew_splunk
Splunk Employee
Splunk Employee

Hi SierraX,

It looks like this is a test dashboard that was mistakenly shipped with the visualization. Do you see similar issues in the app's main 'gallery' dashboard? We'll make sure to remove the test dashboard in going forward.

0 Karma

ziegfried
Influencer

Don't worry about the tar warning messages. This is just some additional metadata the tar on OSX included. It's shouldn't cause any problems.

SierraX
Communicator

But looks not nice and professional anyway.

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...