Dashboards & Visualizations

user is unable to see the results in dashboard

pratapa
Explorer

User is complaining that he is unable to see the results in Dashboard. It is saying "No results found".

Following is the search query.

index=main sourcetype=wms_oracle_sessions | bucket span=5m _time | stats count AS sessions by _time,warehouse,machine,program | stats sum(sessions) AS wsessions by _time,warehouse | timechart avg(wsessions) by warehouse

Tags (1)
0 Karma

renjith_nair
Legend

@pratapa ,

Make sure the user has access to the main index and also look at the search filters

Have a look at https://docs.splunk.com/Documentation/Splunk/latest/Troubleshooting/Cantfinddata

---
What goes around comes around. If it helps, hit it with Karma :slightly_smiling_face:
0 Karma

pratapa
Explorer

I checked source type under settings --> Source types

Source type "wms_oracle_sessions" does not exist.

How does this effect. If it does not exist, how to proceed further.

0 Karma

renjith_nair
Legend

@pratapa,
Have a look at this doc for a better understanding of sourcetype https://docs.splunk.com/Documentation/Splunk/8.0.1/Data/Whysourcetypesmatter

If the sourcetype does not exit indicates that either the data is not indexing or the source type extraction is not working and the events are indexed with another sourcetype. You might need to fix that.

Look for the events without specifying the sourcetype and adjust your search accordingly.

---
What goes around comes around. If it helps, hit it with Karma :slightly_smiling_face:
0 Karma

pratapa
Explorer

I tried without specifying the sourcetype, but still showing "No results found"

0 Karma
Get Updates on the Splunk Community!

See just what you’ve been missing | Observability tracks at Splunk University

Looking to sharpen your observability skills so you can better understand how to collect and analyze data from ...

Weezer at .conf25? Say it ain’t so!

Hello Splunkers, The countdown to .conf25 is on-and we've just turned up the volume! We're thrilled to ...

How SC4S Makes Suricata Logs Ingestion Simple

Network security monitoring has become increasingly critical for organizations of all sizes. Splunk has ...