Dashboards & Visualizations

Splunk App for Cisco UCS: Why is the home dashboard showing 0 Managers, Chassis, Servers?

muebel
SplunkTrust
SplunkTrust

I've configured the UCS app for my distributed environment. When I run the search:

index="cisco_ucs*" | stats count by sourcetype

I see ciscoucs:ucsm:inventory, ciscoucs.ucsm:perf, cisco:ucs:syslog (I've changed this last sourcetype to ciscoucs:syslog since writing)

However, the homepage doesn't list anything for the single digit boxes at the top, and non of the panels are populated.

What could be going on here?

0 Karma

friea
Splunk Employee
Splunk Employee

Quick heads up that Spunk has released a new and fully supported Add-on for Cisco UCS which which available at https://splunkbase.splunk.com/app/2731/. Cisco's Bill Williams posted a nice write-up on the new integration at http://blogs.cisco.com/datacenter/splunk-integration-for-ucs.

(I know ... doesn't address your question in the least. But thought it would be useful for you & the folks following this post to know that a more current integration is available.)

0 Karma

mhunter
New Member

Is there a walk through on how to get a dashboard like that setup from scratch?

0 Karma

halr9000
Motivator

When you run that command and drilldown into *inventory, what does the data look like? You should see 1-line events with pipe-separated values, and there should be >100 extracted fields. For example, "classId", as well as all of the fields which would correspond to the things you see in UCS Manager, like model, numOfCpu, etc Look at these screenshots:

alt text

alt text

If not, then I'm wondering if field extraction is borked.

0 Karma

muebel
SplunkTrust
SplunkTrust

when I examine the events related to the inventory sourcetype, I can see all the fields as you describe. Seems like the extractions are working.

When I run this search over the last hour:

`landing-page-search` | chart count by class

I don't see a topSystem class. I see equipmentChassis class, and computeBlade, but topSystem is missing.

So the UCS Manager panels are blank on the home screen. The rest of the views seem to be working.

I do see a field in the inventory "ucs" that has the name of both of our manager VIPs.

0 Karma

dominiquevocat
SplunkTrust
SplunkTrust

if it is of any comfort, i do have the same or a very similar issue. The searches themselfs as they are run in the home dashboard deliver results but when i use the dashboard there are no resluts for "managers" the other items seem to be ok but comment they have too many resluts and truncate the results. We are not that big a company though lol.

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In September, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...

New in Observability - Improvements to Custom Metrics SLOs, Log Observer Connect & ...

The latest enhancements to the Splunk observability portfolio deliver improved SLO management accuracy, better ...

Improve Data Pipelines Using Splunk Data Management

  Register Now   This Tech Talk will explore the pipeline management offerings Edge Processor and Ingest ...