Dashboards & Visualizations

site value not populating correctley

Ram2
Explorer

We have a query where we are  getting the count by site.

index=test-index |stats count by host site.

When we run this query in search head cluster we are getting output as 

site                       host

undefined         appdtz

undefined        appstd

undefined        apprtg

undefined        appthf

 

When we run the same query in deployer we are getting output correctly with site.

site                       host

sitea         appdtz

sitea       appstd

siteb        apprtg

siteb        appthf

 how to fix this issue in SH cluster.

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @Ram2 ,

probaby you runned the search on SHC outside the app where the site fied is extracted.

have you in the events the site field?

Ciao.

Giuseppe

0 Karma

Ram2
Explorer

Hi @gcusello ,

probaby you runned the search on SHC outside the app where the site fied is extracted. --No i am running the same query under search and reporting app  in SHC and Deployer

have you in the events the site field? --No these are default values for a host coming from universal forwarder,  what they set from application side.

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @Ram2 ,

what's the Mode you're using? you must use Verbose.

if the site field isn't extracted, you cannoy use it, did you extracted the site field?

Ciao.

Giuseppe

0 Karma

Ram2
Explorer

@gcusello ,

what's the Mode you're using? you must use Verbose. --running in verbose mode.

if the site field isn't extracted, you cannoy use it, did you extracted the site field? -- The site field is a default field like host sourcetype. 

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @Ram2 ,

host e sourcetype are indextime fields that you associate to your data surce, site should be an extracted field.

Have you this field running only the search without stats?

if not (as probable) you have to extract it.

Ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...