i've one splunk server reside on linux i've finished installed splunk for symantec app
i work with syslog i saw all events in splunk when i do searching but dashboard is empty
someone have any suggest about this issue
Did you found the problem ?
I got the same and dont know how to solve it.
It's appear that the sub sourcetype are not applied then, the dashboards return no result.
But I dont Know exactly how to make it working.
What is the sourcetype that the symantec events are coming in as? If it's not "sep", try setting the sourcetype to sep in inputs.conf.