Dashboards & Visualizations

Why did Splunk dashboard stopped showing data?

Kartikeya
Observer

Up until a month ago, it was working perfectly, but for the past 2-3 weeks splunk dashboards are not showing any data and the mails we get as alerts are blank, they have no report in them.

What is the possible cause? How to resolve this?

Labels (1)
Tags (2)
0 Karma

Kartikeya
Observer

Hi @gcusello , yes there are other dashboards that are working fine.

The site/source from where we used to gather data updated a while back and some of the dashboards are now facing this problem, with a message saying "site reference is missing in the request"

0 Karma

PickleRick
SplunkTrust
SplunkTrust

Be a bit less secret about your problem 😉

What are those dasboards? Do they come from some Splunkbase-originating app or were they developed internally for you? Do you know what data they refer to and is this data present in your environment?

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @Kartikeya,

if other dashboards are sunning you haven't license violation problems so probably the problem is related to the Data Source.

at first check if the main search of your dashoard panels has results, probably not.

So check the data ingestion from that source.

I suppose that you have admin rights on your Splunk system so you haven't access problems.

Ciao.

Giuseppe

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @Kartikeya,

at first: are there other apps/dashboards that are correctly running on your Splunk environment?

then check if you're in license violation, you can see this by a message in the message area and anyway running a search on a non internal index.

then open in search the searches of the blank panels and see if there's something wrong.

You can debug a search removing, one by one, from the end each section starting with pipe, to arrive to the problem.

Does anything happen 3 weeks ago on your system? an update, an infrastructure change?

Ciao.

Giuseppe

0 Karma

Kartikeya
Observer

Hi @gcusello,

So we get data via Mulesoft, 3rd party, and a couple of months back Mulesoft did some updates on their part and we have had this problem since then.

So the dashboards that use Mulesoft for data have this issue.

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @Kartikeya,

this means that, as I supposed, you have to check the data ingestion, the issue isn't in the dashboard.

Tell us if we can help you more, otherwise, please, accept one answer for the other paople of Community.

Ciao.

Giuseppe

P.S.: Karma Points are appreciated by all the contributors 😉

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

A Four-Part Event Series: Full Stack Observability For the AI Era

As AI reshapes applications, infrastructure, and the way teams operate, the traditional boundaries of ...

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Event Series: Level up your SOC: Advancing with Splunk Enterprise Security

AI has fundamentally raised the stakes for security operations, and this three-part series is your guide to ...