I have installed the Web Intelligence Beta app and I am unable to see any data within it. In fact I see "no results found" on every page and view.
I have completed the setup as instructed. I have my apache secureaccess.log and access.log files being monitored and sent to splunk. I can see both of these sources from within splunk. These are categorized in the accesscombined sourcetype. I even see the logs in the preview during the setup of this app. I have tried generating a lot of web traffic after the setup was complete and even backfilling the data but haven't spotted a single piece of data from within the app yet (unless I do a custom search).
I have now spent 5 days on this and about 10 hours trying multiple combinations of configurations and I'm now pretty frustrated with this. Can someone please help me identify where my problem lies? Thanks.
what is your version of splunk ? (I think that you need at last 4.2)
when you go to the search app, can you see logs when using sourcetype=access_combined in the default indexes ? (if they are in another index, make sure to add it to the default searchables index list in the account manager)
if nothing is loaded, please check the internal logs for errors( using index=_internal source=*splunkd.log )
The newest version of splunk 4.2.4.
Yes I see events when I search for sourcetype=accesscombined and they are in the main index as expected.
There are no issues in index=internal that I see.
I don't know what you mean about checking splunk indexing or the splunk spool folder.
The last question was about checking if the summary indexing is working.
to resume the process of summary indexing :
scheduled searches (with summary indexing option) -> write results in the folder $SPLUNKHOME/var/spool/splunk/...stashnew -> this folder is monitored and the results stored in the specified summary index then deleted from the spool folder -> the index is used in the dashboards of the app.
So please check that the monitor on the folder is not disabled (manager > data inputs > file inputs)
then check that the indexes wisummary* exists and contains results.
The stashnew monitor is on and enabled. There are no files in the $SPLUNKHOME/var/spool/splunk/ directory. Also from the bash shell in Ubuntu, "echo $SPLUNKHOME" doesn't show anything and I wonder if there's an environmental variable problem here. Another thing I found was that there is absolutely no data in any of the wisummary_* indexes. This is probably my problem but I don't know how to fix this. Any ideas on why they aren't populating? Thanks!
There has been no progress on this since. I am still looking for help on this and when I finally solve it I will post what I did to do it so there's at least some kind of documentation out there. I tried setting the environmental variables by hand by editing /etc/environment but this didn't result in anything. Any other ideas on how to solve this?
- the schedule searched are running, generating files in the spool folder, that are indexed (then deleted)
- but when you search in the summary indexes on the server they are empty.
2 things to check :
are you authorized to search on those indexes (check your role permissions, or try as admin) ?
what is your server :an indexer, a search-head, a forwarder ?
Please verify that it is not forwarding the events to another server (that is dropping the events because the indexes don't exits there, or is not a search-peer, therefore is not returning any results)
I have been using the admin account this whole time so it shouldn't be a permissions issue.
I originally started with a forwarder sending data to my indexer. The web intelligence app is installed on the indexer. During my troubleshooting I set up apache web server on the indexer itself and am monitoring a local apache log also. So both local monitoring and receiving logs from a remote forwarder are not seeing the summary indexes.
Still unable to get this app to work. Perhaps it cannot function on the free version of splunk? Anyways, is there another web statistics app out there? If not then I'll just have to build my own app and give up on any help here.
Hum, if you are using the free version (with an expired trial key), then the scheduled searched generating the summary data are not running. This is probably the cause.