We need a lot more information. Which app and which TA did you install? Where did you install them? How did you install them? What does your Splunk architecture look like? How are the inputs defined? Are you looking in the right place(s) for the data? Have you looked at the logs? Are you sure there's data to be found?
--- If this reply helps you, an upvote would be appreciated.
of course, keep in mind I'm not all that familiar with splunk config. This splunk infrastructure was passed down to me.
I installed PureStorage app and the TA. They were installed on a indexer and heavy forwarder, our infrastructure consists of 6 indexers, 6 search heads, 1 cluster master, 1 deployment server, and 2 heavy forwarders. To answer your inputs question, how do I look that up? is it under the installed app (inputs.conf). Where do I look for issues in the logs? is it the ones in splunkhome/var
And, yes...I can see the data on the appliances and splunk would just feed off of that I suppose
The app should be installed on all search heads. Install the TA on both heavy forwarders.
Inputs will be defined in the TA under $SPLUNK_HOME/etc/apps/<app-name>/default/inputs.conf and $SPLUNK_HOME/etc/apps/<app-name>/local/inputs.conf. You may also find it in the HF's UI under Settings->Data inputs.
The best way to look at the logs is by using Splunk. Search for