All Apps and Add-ons

dashboards not populating

Esky73
Builder

Playing around with meh-trics for the first time - i have configured a single host with collectd (CentOS7)

  • i can see the metrics in the collectd index
  • i can browse using metric explorer and metric navigator.

but all the other dashboards, Overview, cpu etc do not populate.

Looking at the troubleshooting section on splunkbase :

  • | mcatalog values(metric_name) provides no results.
  • | mstats min(_value) AS Min avg(_value) AS Avg max(_value) as "Max" WHERE metric_name=disk.disk_io_time.io_time index="*" by host - does tho
  • the host multiselect dropdown has the following search : | mcatalog values(host) AS host | mvexpand host which also doesn't provide any output.

Any ideas whats going on here ?

thanks.

0 Karma
1 Solution

lukeh
Contributor

lukeh
Contributor

Add the collectd index to "Indexes searched by default" :-
https://docs.splunk.com/Documentation/Splunk/latest/Search/Searchindexes#Control_index_access_using_...

Hope this helps 🙂

Esky73
Builder

Damn .. RTFM fail .. thankyou.

0 Karma

teknofile
New Member

I have a similar issue - I have added the indexes search by default already. I can see some data (memory, packet throughput, disk) but I do not see any CPU data populated in the graphs. Using the metrics navigator I can drill down though. Not sure where I should start in troubleshooting the dash board.

I tried to copy the query some of the graphs used in the Search & Reporting window, but it gave me a "Error in 'mstats' command: Unsupported aggregation type: $statsfunc$" so I dont think I can do it that way.

0 Karma

lukeh
Contributor

you're welcome 🙂

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...