Dashboards & Visualizations

index not working

Keerthi
Path Finder

Keerthi_0-1703070143786.png

Hi, i recently changes a SQL query in Splunk db connect to one of the dashboard. the query ran but i don't see the dashboard getting reflected to new data. as i was checking i see the index did not refresh after the new query is implemented. The last event of the index remians the day i changed the query. the new query had two new columns but i dont see it getting reflected. can anyone please help me with this. Its bit urgent !!!!!!!!!

Labels (1)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Try changing it back to how it was

0 Karma

Keerthi
Path Finder

you mean the SQL query?

 

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

If that's all you changed, then yes

0 Karma

Keerthi
Path Finder

ok but i have new columns to be added. if i do so the index stops working. so the data is not forwarding to the indexing.  is there nay option to run my index again?

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Please explain your full process as you haven't really provided sufficient information to determine what you are doing, what you changed, what your results were before the change, etc.

0 Karma

Keerthi
Path Finder

so initially my source is a SQL based query. i had modified my query by adding 2 new columns. so i ran my source. the dashboard has 2 reports which is linked to index and source (sql query).Their events are showing 0 from past 6 days. i ran this command
|index=<index name> it shows 0 event.

Keerthi_0-1703074763525.png

 

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Please provide more details about how the index is updated.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Event Series: Level up your SOC: Advancing with Splunk Enterprise Security

AI has fundamentally raised the stakes for security operations, and this three-part series is your guide to ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...