All Apps and Add-ons

Website Monitoring: Why is data from my new index not displaying?

luisfernandez
Explorer

I installed the Website Monitoring application yesterday and it was working fine but for some reason, my dashboard only shows the data from the last 18hrs ago (index=main). But when I pull data from my new index is not working.

I queried the new index and it's collecting data but when I search sourcetype=web_ping it only shows data from the main index.

Please, can somebody give me a clue to what is wrong?

PS. I install the app twice but it didn't fix anything.

0 Karma
1 Solution

luisfernandez
Explorer

**

A member share this answer and it
works for me

**

Did you define your own index? if so, you will need to add the index to your account's list of indexes to search by default. You can add it by using the Splunk Manager:

1. Go to Users and authentication » Access controls » Roles
2. Select the role you want to change (user, admin, etc.)
3. Add the index to "Indexes searched by default"

To test if that works, run a search for logs with sourcetype of "web_ping" (without specifying the index):
1. sourcetype=web_ping

View solution in original post

0 Karma

luisfernandez
Explorer

**

A member share this answer and it
works for me

**

Did you define your own index? if so, you will need to add the index to your account's list of indexes to search by default. You can add it by using the Splunk Manager:

1. Go to Users and authentication » Access controls » Roles
2. Select the role you want to change (user, admin, etc.)
3. Add the index to "Indexes searched by default"

To test if that works, run a search for logs with sourcetype of "web_ping" (without specifying the index):
1. sourcetype=web_ping

0 Karma

riqbal47010
Path Finder

can we move this sourcetype to my web index

0 Karma

aaraneta_splunk
Splunk Employee
Splunk Employee

Hi @luisfernandez - Did your answer provide a working solution to your question? If yes, please don't forget to click "Accept" to close out your post, so that other users can easily find it. Thanks.

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...