Dashboards & Visualizations

Splunk for OSSEC Dashboard : No results found.

nickbijmoer
Path Finder

Hello guys,

A few days ago the default dashboard of OSSEC in splunk worked fine, but I had to clean up some space so I deleted some data logs and now when I open the default dashboard it says: No results found.
So I dont know why, but I dont get data anymore and I tought I didnt change anything...
Can some1 help me? If you have questions please ask 🙂

0 Karma
1 Solution

DEAD_BEEF
Builder

I'm not sure if there's an option to set all fields to default again. I honestly think the easiest thing will be to just manually check each field. They are case-sensitive, so I'd be sure to check them very carefully! Sounds like a field prob. got renamed so the query isn't working. Let me know how this comes along.

View solution in original post

DEAD_BEEF
Builder

I'm not sure if there's an option to set all fields to default again. I honestly think the easiest thing will be to just manually check each field. They are case-sensitive, so I'd be sure to check them very carefully! Sounds like a field prob. got renamed so the query isn't working. Let me know how this comes along.

nickbijmoer
Path Finder

They were just gone apparently, I added them again and now its working 🙂

0 Karma

DEAD_BEEF
Builder

Some of the fields themselves were gone? As in, no logs contained data for such a named field? That is really odd. How did you add it again to fix it? Just so others know as well in the future 🙂

0 Karma

nickbijmoer
Path Finder

Yeah I just manually extracted the fields again 🙂

0 Karma

DEAD_BEEF
Builder

Have you checked the underlying query generating the dashboards to see if a field was renamed or now has no data/results?

0 Karma

nickbijmoer
Path Finder

Yeah I checked it, It gives no data if I search with that query, but the data that he used before is still in SPLUNK so I might have a field that renamed indeed or something like that... Is there an option to set all fields to default again or reset all fields?

0 Karma
Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer Certification at ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...