I am facing issue while using Exchange app for Splunk . I am not getting data rendered in widget of my dashboard
In overview -> Service Availability .. it displays NO RESULTS FOUND . when I inspect query
eventtype=msexchange-topology | dedup Name | eval Service=split(ServicesNotRunning,",") | eval ServiceCount=if(ServicesNotRunning!="",mvcount(Service),0) | table Name,Service,ServiceCount | addcoltotals fieldname=Service labelfield=Name label="# Problem Services" | eval Service=if(Name="# Problem Services",ServiceCount,Service) | search Name="# Problem Services" OR ServiceCount>0 | table Name,Service
and hit it in search I get result as
Name Services
1.# Problem Services 0
Now practically this value should be rendered in dashboard.
Please look into this . Thanks in advance !
We resolved the problem by correcting system time on SPLUNK Indexer server.
We resolved the problem by correcting system time on SPLUNK Indexer server.