Getting Data In

Cisco Networks App - no results found, open in search does show results

Loves-to-Learn Lots


I'm having an issue with some dashboard of the Cisco Network App.
Take for example the routing dashboard. There is a top neihbors panel. When I open the dashboard, it does the search and returns "No results found".
However when I do I job inspection, I see it does find results:

This search has completed and has
returned 2,520 results by scanning
3,930 events in 2.133 seconds

When opening the job in search, I also see all the data. The query seems to work, but not in the dashboard panel...

I've checked the roles and made sure all roles that can have access, have a default search on all internal indexes. This is needed because the search itself uses index*.

The search it executes:

eventtype=cisco_ios-routing index IN (*)
| eval routing_protocol = case(eventtype == "cisco_ios-routing-ospf", "OSPF", eventtype == "cisco_ios-routing-dual", "EIGRP", eventtype ==> "cisco_ios-routing-bgp", "BGP", eventtype == "cisco_ios-routing-ldp","LDP", eventtype =="cisco_ios-routing-isis", "ISIS", eventtype == "cisco_ios-routing-rsvp", "RSVP", eventtype =="cisco_ios-routing-pim", "PIM")
| search (routing_protocol="BGP" OR routing_protocol="OSPF")
| lookup dnslookup clientip as src_ip | top clienthost

I do get data back, so it seems all datamodels are correct.

I'm really at a loss why it would return "no results" when inspecting or running the search does return results :s

Setup: index and search cluster, everything running on version 8.0.0. App is the latest version.

0 Karma

Loves-to-Learn Lots

Yes, I did make some changes, but besides that part, even before making the changes, it shows no results. I'm wondering if it's a kind of permission issue, but I wouldn't know where to start looking... Other dashboards are having the same issue.
The inspection does show it is giving me the results, but the panel is not showing it.
I guess I can try to delete the panel and replace it and see what it gives I guess.

It's a clean install of the app on the entire installation. So no Splunk nor app upgrades have been done so far. So I'm not entirely clear what you mean with client side in this case. The browser? Multiple users have this, even the local admin user.

0 Karma

Splunk Employee
Splunk Employee


I'm the author of the App. Not sure why you are having issues with the dashboards, but this part indicates you have made local customizations to the App: | lookup dnslookup clientip as src_ip | top clienthostas the original app does not have this query.

You may also try to clear any client side caches if you recently upgraded to Splunk 8.

0 Karma
Get Updates on the Splunk Community!

.conf24 | Day 0

Hello Splunk Community! My name is Chris, and I'm based in Canberra, Australia's capital, and I travelled for ...

Enhance Security Visibility with Splunk Enterprise Security 7.1 through Threat ...

(view in My Videos)Struggling with alert fatigue, lack of context, and prioritization around security ...

Troubleshooting the OpenTelemetry Collector

  In this tech talk, you’ll learn how to troubleshoot the OpenTelemetry collector - from checking the ...