Dashboards & Visualizations

how to debug applications

robgreen
Path Finder

I am having a heck of a time trying to debug advanced xml so i am wondering if maybe i am just missing something. Basically i have a view with advanced xml in it, i have to do this

  1. modify the xml
  2. bin/splunk restart (not just restart splunkweb)
  3. reload ui and re login
  4. browse to my app and load the view
  5. if it doesn't work goto step 1

is there an easier way for modifying the xml is the first question, and the second question are there logs i can look at that tells me why my view isn't working? usually my panel is blank with no reason as to why. even things like search query being bad doesn't display in the messages panel. I am using an xml editor so the xml is well-formed.

rob

Tags (1)
0 Karma

Drainy
Champion

Welcome!
I assume you are editing the XML outside of Splunk? This can be problematic and Splunk can do the validation for you but if you are using an editor you should be ok.

Just because there are no errors being displayed doesn't mean that there are no problems however, it could be that Splunk has merely interpreted your xml in a way that results in.. nothing.
The quickest way to troubleshoot would be if you could paste an example on here so we can check it out.

Also to save time, when you save your externally modified XML just run the following URL to reload the internal cache on the fly;
http://SPLUNKSERVER:PORT/en-US/debug/refresh?entity=/admin/views

This will force splunk to do a reload, no restart required!

Get Updates on the Splunk Community!

Avoid Certificate Expiry Issues in Splunk Enterprise with Certificate Assist

This blog post is part 2 of 4 of a series on Splunk Assist. Click the links below to see the other ...

Using Machine Learning for Hunting Security Threats

REGISTER NOW Seeing the exponential hike in global cyber threat spectrum, organizations are now striving more ...

Security Highlights | November 2022 Newsletter

 November 2022 2022 Gartner Magic Quadrant for SIEM: Splunk Named a Leader for the 9th Year in a RowSplunk is ...