Environment:
Splunk Enterprise version: 7.2.1
Two search heads (one is a master).
Six heavy forwarders.
Three indexers.
One deployment server.
I created a new index and deployed it out to the peers (indexers), installed the Mimecast for Splunk app on the search head, then worked with Mimecast to get data in to the app (which I can see since it's saying "parsed X amount of logs" in the troubleshooting section of the app), but the dashboards are not displaying anything. Where did I go wrong ya'll think? Thanks.
Hi!
I am having the same issue and havent been lucky solving it.
Were you able to see any data on the dashboards?
Thanks!!
Miriam
Hi There,
I am experiencing the same issue here, how did you resolve it?
Kind Regards
gift