Dashboards & Visualizations

user is unable to see the results in dashboard

pratapa
Explorer

User is complaining that he is unable to see the results in Dashboard. It is saying "No results found".

Following is the search query.

index=main sourcetype=wms_oracle_sessions | bucket span=5m _time | stats count AS sessions by _time,warehouse,machine,program | stats sum(sessions) AS wsessions by _time,warehouse | timechart avg(wsessions) by warehouse

Tags (1)
0 Karma

renjith_nair
Legend

@pratapa ,

Make sure the user has access to the main index and also look at the search filters

Have a look at https://docs.splunk.com/Documentation/Splunk/latest/Troubleshooting/Cantfinddata

---
What goes around comes around. If it helps, hit it with Karma 🙂
0 Karma

pratapa
Explorer

I checked source type under settings --> Source types

Source type "wms_oracle_sessions" does not exist.

How does this effect. If it does not exist, how to proceed further.

0 Karma

renjith_nair
Legend

@pratapa,
Have a look at this doc for a better understanding of sourcetype https://docs.splunk.com/Documentation/Splunk/8.0.1/Data/Whysourcetypesmatter

If the sourcetype does not exit indicates that either the data is not indexing or the source type extraction is not working and the events are indexed with another sourcetype. You might need to fix that.

Look for the events without specifying the sourcetype and adjust your search accordingly.

---
What goes around comes around. If it helps, hit it with Karma 🙂
0 Karma

pratapa
Explorer

I tried without specifying the sourcetype, but still showing "No results found"

0 Karma
Get Updates on the Splunk Community!

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

🔐 Trust at Every Hop: How mTLS in Splunk Enterprise 10.0 Makes Security Simpler

From Idea to Implementation: Why Splunk Built mTLS into Splunk Enterprise 10.0  mTLS wasn’t just a checkbox ...