I installed the Splunk App for MS SP and it looks like I am unable to generate the lookup tables. I run the Lookup Table Rebuilder and it seems like it works but the following show up with zero bytes:
SPApplicationPool.csv, SPContentDatabase.csv, SPList.csv, SPSite.csv, SPUser.csv, SPWebApplication.csv, SPWeb.csv, and SPWebTemplate.csv.
Because of this, the searches in the various dashboards come up empty.
Have you tried installing the PowerShell Modular input on the search head and indexer(s)? (http://apps.splunk.com/app/1477/) Once you install that, then you want to make sure that the Powershell scripts are executing. Let me know if you have any issue with this, I was able to install it and get data.
having the same troubles - i'm unable to generate lookups.
the powershell modular input is deployed. i think the powershell scripts are not running.
is there a logfile for the powershell operatoins?