Dashboards & Visualizations

index not working

Keerthi
Path Finder

Keerthi_0-1703070143786.pngKeerthi_0-1703070143786.png

Hi, i recently changes a SQL query in Splunk db connect to one of the dashboard. the query ran but i don't see the dashboard getting reflected to new data. as i was checking i see the index did not refresh after the new query is implemented. The last event of the index remians the day i changed the query. the new query had two new columns but i dont see it getting reflected. can anyone please help me with this. Its bit urgent !!!!!!!!!

Labels (1)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Try changing it back to how it was

0 Karma

Keerthi
Path Finder

you mean the SQL query?

 

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

If that's all you changed, then yes

0 Karma

Keerthi
Path Finder

ok but i have new columns to be added. if i do so the index stops working. so the data is not forwarding to the indexing.  is there nay option to run my index again?

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Please explain your full process as you haven't really provided sufficient information to determine what you are doing, what you changed, what your results were before the change, etc.

0 Karma

Keerthi
Path Finder

so initially my source is a SQL based query. i had modified my query by adding 2 new columns. so i ran my source. the dashboard has 2 reports which is linked to index and source (sql query).Their events are showing 0 from past 6 days. i ran this command
|index=<index name> it shows 0 event.

Keerthi_0-1703074763525.pngKeerthi_0-1703074763525.png

 

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Please provide more details about how the index is updated.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Event Series: The Agentic SOC: Trust Before Autonomy

AI is fundamentally changing security operations, but true progress requires more than just automation—it ...

Free Professional Services for .conf26 Attendees

This year at .conf26, we are doing something a little different. We are bringing the best minds from ...

Defend at Machine Speed: Your Guide to Security Sessions at .conf26

Splunk .conf26   With threats moving at machine speed and attack surfaces expanding across hybrid ...