Since 12 day's website monitoring does not show any graph.
History data is still available. Uninstall and install app does not fix the problem.
I use it for 4 sites. I also added a site that is in the same subnet as my Splunk - no data shown.
Every time I open the app I get "No results found."
Using Splunk 7.3.3 and website monitor 2.8 version.
After some research I found the problem. The website monitoring app version 2.8 does not function correctly on Splunk with free license.
On the free licensed Splunk (7.3.3) I removed /opt/splunk/etc/apps/website_monitoring
and /opt/splunk/etc/users/admin/website_monitoring
and restarted Splunk. After restart website monitoring app 2.7.6 installed and configured. The data is collected and shown now.
This is for me acceptable workaround.
This issue is not anymore present in version 2.9
@tobi2k this workaround is only for Splunk versions before 8.0.0.
I hope that @LukeMurphey will solve this bug it in the next release.
I cannot confirm that workaround! Adding new Websites to Website Monitor once the Splunk Installation runs in Free-Mode, will not work. Reinstalling of the Plugin does not solve the issue!
Splunk: 8.01
Website-Monitoring Plugin: v2.9
@tobi2k it will work only on Splunk releases before 8.0.0. I hope that @LukeMurphey will solve this bug quickly in next release.
After some research I found the problem. The website monitoring app version 2.8 does not function correctly on Splunk with free license.
On the free licensed Splunk (7.3.3) I removed /opt/splunk/etc/apps/website_monitoring
and /opt/splunk/etc/users/admin/website_monitoring
and restarted Splunk. After restart website monitoring app 2.7.6 installed and configured. The data is collected and shown now.
This is for me acceptable workaround.
I'm going to fix this so that the app will continue to work on the free license: https://lukemurphey.net/issues/2538
@LukeMurphey I get same behavior using any website monitoring app on Splunk 8
So history is available, but the checks are not performed anymore on free licensed deployment.
Tnx Luke and thank you for great app.
Hi @pa4rm,
to debug this problems you could start from two points of view:
you can check the first condition on you target.
For the second you could try something like this
index=_internal host=your_host
and if there are Splunk internal logs and from that server you usually receive other logs
index=wineventlog (or another index used for your logs) host=your_host
If you don't receive any log, check the connection (from the target host telnet IP_indexer 9997
) and the Universal Forwarder logs (at $SPLUNK_HOME/var/log/splunk/splunkd.log
)
If you continue to receive other logs but not the ones you want, you have to check if it's changed something in the parsing, e.g. the time format of timestamp.
Ciao.
Giuseppe
Hi Giuseppe,
Thank you for your comment. I receive internal and external logs and they are processed correctly. I've only issues with website monitoring which was working fine for few years till 2 weeks ago.
When the problem occur, I didn't make any change or upgrade of systems.
Thanks
Hi @pa4rm,
if you're receiving logs from the same host we have to debug the input of those logs.
Please, check the grants on those files and, if possible share some example, your inputs.conf from Forwarder (the one related to those logs) and props.conf from Indexer containing the sourcetype definition of those logs.
Ciao.
Giuseppe
Hi Giuseppe,
permissions are ok. I tried to solve it by removing this app and installing again - no luck.
My local/inputs.conf
[web_ping://RAD-IT]
interval = 5m
return_body = 0
title = RAD-IT
url = https://rad-it.nl
user_agent = Splunk Website Monitoring (+https://splunkbase.splunk.com/app/1493/
)
my default/inputs.conf
[web_ping]
user_agent=Splunk Website Monitoring (+https://splunkbase.splunk.com/app/1493/)
and my default/props.conf
[source::...web_availability_modular_input.log]
sourcetype=web_availability_modular_input
[source::...website_monitoring_rest_handler.log]
sourcetype=website_monitoring_rest_handler
Could you do some searching via the troubleshooting guide here: https://lukemurphey.net/projects/splunk-website-monitoring/wiki/Troubleshooting
I'll fix this ASAP if I can get some details that allow me to narrow down the problem.
Hi @LukeMurphey ,
On both search queries I get "No results found". Please view screenshots for proxy config (don't use it), python test and actual result page when I try to view monitoring results. Everiting was working fine till 2 weeks ago. I didn't make any change or upgrade at the time of starting problems.
Hi @LukeMurphy,
Just run again serach for modular input errors and got following:
2019-12-07 23:36:39,374 ERROR Execution failed
Traceback (most recent call last):
File "/opt/splunk/etc/apps/website_monitoring/bin/modular_input.zip/modular_input/modular_input_base_class.py", line 1092, in execute
self.do_run(in_stream, log_exception_and_continue=True)
File "/opt/splunk/etc/apps/website_monitoring/bin/modular_input.zip/modular_input/modular_input_base_class.py", line 961, in do_run
if ServerInfo.is_shc_captain(input_config.session_key) == False:
File "/opt/splunk/etc/apps/website_monitoring/bin/modular_input.zip/modular_input/shortcuts.py", line 31, in wrapper
return function(*args, **kwargs)
File "/opt/splunk/etc/apps/website_monitoring/bin/modular_input.zip/modular_input/server_info.py", line 154, in is_shc_captain
if not cls.is_on_shc(session_key):
File "/opt/splunk/etc/apps/website_monitoring/bin/modular_input.zip/modular_input/shortcuts.py", line 31, in wrapper
return function(*args, **kwargs)
File "/opt/splunk/etc/apps/website_monitoring/bin/modular_input.zip/modular_input/server_info.py", line 111, in is_on_shc
except splunk.ResourceNotFound:
NameError: global name 'splunk' is not defined