Dashboards & Visualizations

Glasstable --few of the tiles is showing N/A instead of showing the search result

KumaKa
Engager

Glass table was showing tiles with search result number.depends on the color which has been set.it was showing properly.,All of a sudden from today the red colored ones is showing as grey with N/A inside it.

 

It was working showing the values till yesterday even if the color changes from green to red .

 

Could someone help me to fix this issue?

 

 

NA.jpg

Labels (1)
Tags (1)
0 Karma

KumaKa
Engager

@richgallowayThank you so much for your reply.

Below is the search query 

| metadata type=sourcetypes index=websense-dlp_sec | eval diff=(now()-lastTime)/60 | table diff

it used to give some information and which will be displayed in the glass table tile.From yesterday its not happening.

There is an underlaying issue which we where debugging related to log drop from a tool since 2 days back.as the logs are not coming in it should show in red colour with the minutes since the last log came. Previously  it use to show the correct value with red colour.Can anyone help me to sort this issue.

Same is there for another tile too which was in red colour now showing N/A.Dont know whether this related to the above issue or not.

search Query for this is 

| metadata type=hosts index=fort*| eval diff=(now()-lastTime)/60| search host="FGT-MGMT"| table diff

 
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Both of the searches will return no results and display "N/A" if there is no data in their respective indexes or no data from host "FGT-MGMT" in the second search.

Yes, this certainly could be related to the log drop.  If the searches rely on data from a particular tool and that tool stops sending data then the searches likely will fail.

There may be ways to detect this condition so the tile is always red, but I think it's useful to display "N/A" to indicate when there's a data problem.

---
If this reply helps you, Karma would be appreciated.
0 Karma

KumaKa
Engager

Thanks for your reply.

what makes me confused is couple of weeks back also we detected log drop ,then the tile was in red and showed values like 5k ,6k and all.that means even after 2 days of log drop tile was showing the value since the last log was onboarded and in red.

Now the case is just after a day since the last log came into splunk it started showing N/A and in grey.

 

this strange behavior is making me things hard to understand.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

The problem lies with the search that populates that metric.  Debug the search to determine why it is not returning a number.  Or post the search here for someone to look at.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...