All Apps and Add-ons

Why aren't the Splunk Add-on and App for New Relic showing data in my dashboards on a Splunk standalone instance?

Kibibi4640
New Member

Can you install the NewRelic App and Add on on a standalone instance of Splunk? I installed both the NewRelic app and NewRelic add on on a standalone instance of Splunk. I have events coming in but none of the dashboards in the App are showing any data.

In looking at the Splunk documentation on the app and add on- it says it needs to be installed on a heavy forwarder and does not support universal forwarder or light forwarder.

I don't have a heavy forwarder in my test environment and wanted to test the data before deploying it in production.

0 Karma

rpille_splunk
Splunk Employee
Splunk Employee

It should be supported in a standalone Splunk platform instance, yes. Those doc instructions only cover a distributed case because that requires special instructions, but all add-ons are supported on standalone instances unless stated otherwise.

As for why no data is showing in the dashboards, I'm not sure. Are the dashboards searching against the index that you sent the New Relic data to? Is the Role that your Splunk user is part of able to see the data in those indexes by default? You may need to add the index to the Selected Indexes list in Access Controls > Roles > .

0 Karma

Kibibi4640
New Member

Thank you for your answer. I discovered it was the API key I was using. But I am not seeing the Insights Data tab working in the App. I have raw events with the Insights data but the dashboards don't populate.

The raw event for insights data has the metadata section but that field is not extracted. Also when I click on search-Data summary and then go to sourcetype- none of the sourcetypes come up in the summary.

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...