I am running the following versions of Splunk and supporting apps for Windows infrastructure on Linux RHEL 6.8:
Splunk Enterprise 7.2.1
Splunk App for Windows Infrastructure 1.5.0
Windows Add-on 5.0.1
Client side Is Windows 2008R2 SP1 installed with UF, and Windows Add-on 5.0.1 was deployed from deployment server.
If I go to Splunk App for Windows Infrastructure do the search I can see data is getting in, like index="wineventlog", I can see a lot events.
But if I select Windows > Windows Overview, I only can see "0 Hosts", I also can see the list of sources, sourceTypes and hosts, how can I see the Overview?