Dashboards & Visualizations

user is unable to see the results in dashboard

pratapa
Explorer

User is complaining that he is unable to see the results in Dashboard. It is saying "No results found".

Following is the search query.

index=main sourcetype=wms_oracle_sessions | bucket span=5m _time | stats count AS sessions by _time,warehouse,machine,program | stats sum(sessions) AS wsessions by _time,warehouse | timechart avg(wsessions) by warehouse

Tags (1)
0 Karma

renjith_nair
SplunkTrust
SplunkTrust

@pratapa ,

Make sure the user has access to the main index and also look at the search filters

Have a look at https://docs.splunk.com/Documentation/Splunk/latest/Troubleshooting/Cantfinddata

Happy Splunking!
0 Karma

pratapa
Explorer

I checked source type under settings --> Source types

Source type "wms_oracle_sessions" does not exist.

How does this effect. If it does not exist, how to proceed further.

0 Karma

renjith_nair
SplunkTrust
SplunkTrust

@pratapa,
Have a look at this doc for a better understanding of sourcetype https://docs.splunk.com/Documentation/Splunk/8.0.1/Data/Whysourcetypesmatter

If the sourcetype does not exit indicates that either the data is not indexing or the source type extraction is not working and the events are indexed with another sourcetype. You might need to fix that.

Look for the events without specifying the sourcetype and adjust your search accordingly.

Happy Splunking!
0 Karma

pratapa
Explorer

I tried without specifying the sourcetype, but still showing "No results found"

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...