Dashboards & Visualizations

Cisco IOS Default Dashboard Not Working

hw023280
Explorer

After installing the Cisco IOS app, when I navigate to the app's default home dashboard, the top 8 panels display the following error:

Error in 'PivotProcessor': Unable to fetch datamodelreport REST endpoint '/servicesNS/admin/cisco_ios/datamodel/pivot/Cisco_IOS_Event' from 'https://127.0.0.1:8089'

Starting with the Port Flapping panel does any data display. Any assistance would be greatly appreciated!

mikaelbje
Motivator

I just released the following:

  • Cisco IOS App version 1.3.2
  • Cisco IOS TA version 1.2.2

The Cisco IOS App includes a dashboard with workarounds for the Data Model issue. The dashboard is called overview_postprocesssearches__no_pivot

I haven't done anything about the pivots/data models in the other dashboards as I want to take advantage of the Data Model performance benefits, but you should hopefully have a working overview dashboard now. Please note that it's very slow! Splunk will hopefully have a look at the defect soon.

+++ 1.3.2 (2014-04-23)

Added a new overview page (overview_postprocess_searches_no_pivot)
as a workaround for users having problems with Data Model powered
searches not displaying (Splunk defect SPL-83310) - THIS IS SLOW!

Release notes:

Bug fixes:

  • Removed some unneccessary files.
  • Moved Performance panels into a common performance_dashboard

Features:

  • Preliminary support for IP SLA events (Performance dashboard)
  • Optical transceiver attenuation monitoring (Switching -> Dashboard)
0 Karma

hrottenberg_spl
Splunk Employee
Splunk Employee

The bug report is assigned to an engineer and has been marked as "to fix".

0 Karma

halr9000
Motivator

I'll ask for a follow up.

0 Karma

mikaelbje
Motivator

Haven't heard anything so far

0 Karma

hw023280
Explorer

Have you heard anything regarding the splunk defect SPL-83310? I hope Splunk is working on it as the workaround is nice, but like you said, very very slow.

0 Karma

mikaelbje
Motivator

Did you replace "overview" in the address bar of your browser with "overview_postprocess_searches_no_pivot"?

This new dashboard isn't the standard one, so you need to do that to display it 🙂

0 Karma

hw023280
Explorer

Am I doing something wrong? I updated both through "Manage Apps," than restarted splunk successfully, but the error still shows up! I don't mean to come off abrasive, because that's not my intention, but is there anyway at all this workaround might not work still? This app is going to impress... just hope it works for me sooner than later.

0 Karma

mikaelbje
Motivator

I've seen this and so far I think it's a permission issue. Could you navigate to Settings - Data Models - Expand the "Cisco IOS Event" model, click permissions. Make it readable by everyone and export it to All Apps/Global (this should be the default). Let me know if that doesn't work and I'll investigate further and get a fixed version uploaded.

What Splunk version are you running? I just installed the app on a clean server with Splunk 6.0.3 and all the dashboards work. Is your server extremely busy? Have you tried stopping and starting the Splunk search head?

If none of the above work you can download the latest development version from https://github.com/inspired/cisco_ios/

Let me know how this works out for you.

0 Karma

rdowd
Path Finder

Sure thing! Thanks for the prompt response 🙂

0 Karma

mikaelbje
Motivator

Hi,

I'll upload a version that doesn't use Data Models for the overview page by tomorrow hopefully if you can wait 🙂

rdowd
Path Finder

Same issue as soon as I upgraded to 1.3.1. This is a week old now so I'm hoping I can go back to the older version.

0 Karma

halr9000
Motivator

They triage bugs once a week. But the process thereafter can take some time. May want to think about workarounds for now.

0 Karma

mikaelbje
Motivator

I'm happy to hear that. If there was anything I could do I would, but it looks like this is an internal Splunk bug. Why it works on some installs is beyond my understanding though.

0 Karma

hw023280
Explorer

Ok, thank you! For your reference (assuming you knew this already), but I just copied over the most recent revision to your app and the same error occurred. Very anxious to get this amazing app working smoothly!!!

0 Karma

mikaelbje
Motivator

hw023280: No, you'll just have to wait on this one. halr9000 is a Splunk employee and has opened a defect, so I expect that the case will receive some attention 🙂

0 Karma

hw023280
Explorer

mikaelbje - shall I still get with a Splunk Engineer to discuss the splunkd.log errors you mentioned above?

0 Karma

halr9000
Motivator

I just opened a defect. Will update here once it has been triaged.

0 Karma

halr9000
Motivator

I'm trying to see if this is a Splunk bug, which is what I suspect. There are some others who have hit the same error message, e.g. http://answers.splunk.com/answers/113095/error-in-pivotprocessor-unable-to-fetch-datamodelreport-res...

0 Karma

mikaelbje
Motivator

I checked back on one of my installs and on the initial loading of the overview page I got the same error as you. I checked splunkd.log and saw this:

04-19-2014 15:48:45.701 +0200 WARN NetUtils - select_for timeout hit waiting for read
04-19-2014 15:48:45.701 +0200 WARN NetUtils - Bad select_for_loop rv = -2
04-19-2014 15:48:45.702 +0200 ERROR HTTPClient - Should have gotten at least 3 tokens in status line, while getting response code. Only got 0.

Please ask the engineer to get your diagnostic logs and check with Splunk internally.

0 Karma

mikaelbje
Motivator

I'm on Easter Holidays, so please excuse me for my late reply.

Could you please download the latest development version again? I've included a new dashboard called overview_postprocess_searches which you can try out. The difference is:

overview_postprocess_searches uses post process searches (should speed things up a bit)

If my app causes Splunk to crash I'd say that is a Splunk issue and I would kindly ask that you and the Splunk engineer spend some more time to gather and analyze Splunk diagnostic logs to find the root cause. I'm eager to find out myself and solve any bugs.

0 Karma
Get Updates on the Splunk Community!

Take Your Breath Away with Splunk Risk-Based Alerting (RBA)

WATCH NOW!The Splunk Guide to Risk-Based Alerting is here to empower your SOC like never before. Join Haylee ...

SignalFlow: What? Why? How?

What is SignalFlow? Splunk Observability Cloud’s analytics engine, SignalFlow, opens up a world of in-depth ...

Federated Search for Amazon S3 | Key Use Cases to Streamline Compliance Workflows

Modern business operations are supported by data compliance. As regulations evolve, organizations must ...