Dashboards & Visualizations

Issue with service availibilty at overview dashboard

nawneel
Communicator

I am facing issue while using Exchange app for Splunk . I am not getting data rendered in widget of my dashboard

In overview -> Service Availability .. it displays NO RESULTS FOUND . when I inspect query

eventtype=msexchange-topology | dedup Name | eval Service=split(ServicesNotRunning,",") | eval ServiceCount=if(ServicesNotRunning!="",mvcount(Service),0) | table Name,Service,ServiceCount | addcoltotals fieldname=Service labelfield=Name label="# Problem Services" | eval Service=if(Name="# Problem Services",ServiceCount,Service) | search Name="# Problem Services" OR ServiceCount>0 | table Name,Service
and hit it in search I get result as

                  Name                   Services
               1.# Problem Services              0

Now practically this value should be rendered in dashboard.
Please look into this . Thanks in advance !

0 Karma
1 Solution

nawneel
Communicator

We resolved the problem by correcting system time on SPLUNK Indexer server.

View solution in original post

0 Karma

nawneel
Communicator

We resolved the problem by correcting system time on SPLUNK Indexer server.

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...