Can you install the NewRelic App and Add on on a standalone instance of Splunk? I installed both the NewRelic app and NewRelic add on on a standalone instance of Splunk. I have events coming in but none of the dashboards in the App are showing any data.
In looking at the Splunk documentation on the app and add on- it says it needs to be installed on a heavy forwarder and does not support universal forwarder or light forwarder.
I don't have a heavy forwarder in my test environment and wanted to test the data before deploying it in production.
It should be supported in a standalone Splunk platform instance, yes. Those doc instructions only cover a distributed case because that requires special instructions, but all add-ons are supported on standalone instances unless stated otherwise.
As for why no data is showing in the dashboards, I'm not sure. Are the dashboards searching against the index that you sent the New Relic data to? Is the Role that your Splunk user is part of able to see the data in those indexes by default? You may need to add the index to the Selected Indexes list in Access Controls > Roles > .
Thank you for your answer. I discovered it was the API key I was using. But I am not seeing the Insights Data tab working in the App. I have raw events with the Insights data but the dashboards don't populate.
The raw event for insights data has the metadata section but that field is not extracted. Also when I click on search-Data summary and then go to sourcetype- none of the sourcetypes come up in the summary.