All Apps and Add-ons

The lookup table 'monitored_indexes.csv' is invalid. in Fire Brigade v2 App

jbleich
Path Finder

I am a splunk newbie, so keep that in mind 🙂

I have copied the FB and FBTA both version 2 as I have splunk 6.1 into my etc/apps and restarted splunk. Some of the dashboards are working, but a lot are not and none of the dropdowns work either. I cant seem to find a "setup app" page within the app which tells me it should just work? Either way the one error that does come up is in the title. I cant find that in any of the folders, need some help here.

Tags (1)
1 Solution

sowings
Splunk Employee
Splunk Employee

Admittedly, the docs are a little thin an I should fix that.

In any event, the short answer is "wait 24h". The searches that populate data for Fire Brigade run once a day around midnight. The first piece is the "get me the list of indexes" (monitored_indexes.csv). A couple of minutes later, the "DB Inspection" search runs, looping over the named indexes. After that, the dashboards should work normally.

If you want to drive everything now, then I can provide some further instructions.

View solution in original post

ppablo
Community Manager
Community Manager

FYI, Fire Brigade version 2 will no longer be updated (latest version is 2.0.3). The newer versions 2.0.4 and higher will now be available with the original “Fire Brigade” app on Splunkbase which was just updated to support Splunk 6.3. This is noted on the page for Fire Brigade on Splunkbase:
https://splunkbase.splunk.com/app/1581/

If you have any questions, ping the developer of the app @sowings

Cheers!

0 Karma

sowings
Splunk Employee
Splunk Employee

Admittedly, the docs are a little thin an I should fix that.

In any event, the short answer is "wait 24h". The searches that populate data for Fire Brigade run once a day around midnight. The first piece is the "get me the list of indexes" (monitored_indexes.csv). A couple of minutes later, the "DB Inspection" search runs, looping over the named indexes. After that, the dashboards should work normally.

If you want to drive everything now, then I can provide some further instructions.

jbleich
Path Finder

Yeah I'm not sure what happened, it was working when we had our indexer on a windows box, but we reloaded our splunk onto a linux box and when i reloaded this app I'm now getting The lookup table 'monitored_indexes.csv' is invalid. so it's kind of a bummer....

0 Karma

sowings
Splunk Employee
Splunk Employee

Just remove the panel. It's going away in the next release.

0 Karma

vchepkov
Explorer

Unfortunately, this advice it doesn't work in clustered environment. I think this is because application creates lookup table in "system/lookups/monitored_indexes.csv", but cluster expects it to be somewhere under slave-apps/

sowings
Splunk Employee
Splunk Employee

I plan to take it out in the next release, probably before mid-month, Feb 2015.

Get Updates on the Splunk Community!

Security Highlights: September 2022 Newsletter

 September 2022 The Splunk App for Fraud Analytics (SFA) is now Splunk SupportedUse your existing Splunk ...

Platform Highlights | September 2022 Newsletter

 September 2022 What’s New in 9.0 and How to UpgradeGet a walk through of what is new Splunk Enterprise 9.0 ...

Observability Highlights | September 2022 Newsletter

 September 2022 Splunk Observability SuiteAccess to "Classic" SignalFx Interface Will be Removed on Sept 30, ...