All Apps and Add-ons

dashboards not populating

Esky73
Builder

Playing around with meh-trics for the first time - i have configured a single host with collectd (CentOS7)

  • i can see the metrics in the collectd index
  • i can browse using metric explorer and metric navigator.

but all the other dashboards, Overview, cpu etc do not populate.

Looking at the troubleshooting section on splunkbase :

  • | mcatalog values(metric_name) provides no results.
  • | mstats min(_value) AS Min avg(_value) AS Avg max(_value) as "Max" WHERE metric_name=disk.disk_io_time.io_time index="*" by host - does tho
  • the host multiselect dropdown has the following search : | mcatalog values(host) AS host | mvexpand host which also doesn't provide any output.

Any ideas whats going on here ?

thanks.

0 Karma
1 Solution

lukeh
Contributor

lukeh
Contributor

Add the collectd index to "Indexes searched by default" :-
https://docs.splunk.com/Documentation/Splunk/latest/Search/Searchindexes#Control_index_access_using_...

Hope this helps 🙂

Esky73
Builder

Damn .. RTFM fail .. thankyou.

0 Karma

teknofile
New Member

I have a similar issue - I have added the indexes search by default already. I can see some data (memory, packet throughput, disk) but I do not see any CPU data populated in the graphs. Using the metrics navigator I can drill down though. Not sure where I should start in troubleshooting the dash board.

I tried to copy the query some of the graphs used in the Search & Reporting window, but it gave me a "Error in 'mstats' command: Unsupported aggregation type: $statsfunc$" so I dont think I can do it that way.

0 Karma

lukeh
Contributor

you're welcome 🙂

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

A Four-Part Event Series: Full Stack Observability For the AI Era

As AI reshapes applications, infrastructure, and the way teams operate, the traditional boundaries of ...

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Event Series: Level up your SOC: Advancing with Splunk Enterprise Security

AI has fundamentally raised the stakes for security operations, and this three-part series is your guide to ...