Getting Data In

Eventtypes have gone missing

kmower
Communicator

I have had Splunk Stream up and running for a while, but after upgrading to 7.3.1 some of my Eventtypes that drive the Stream dashboards seem to have gone AWOL. For example, I am mainly using Stream to monitor my sql database activity (tds). The Admin dashboard for databases used to work just fine, but now it is throwing the error: Eventtype 'stream_agg_databases' does not exist or is disabled.

I checked the Eventtypes after reading a post that said sometimes Eventtypes are disabled on upgrades, but this one is gone altogether. So I was wondering if anyone knows how to restore the Eventtypes for Stream? Thanks.

Tags (1)
0 Karma
1 Solution

kmower
Communicator

OK, I have answered this myself. The permissions for the Event Types for Splunk_TA_stream were restricted to 'The App' which is Splunk_TA_Stream, bit of course the Stream App is splunk_stream_app ... So the fix is to enable the Permissions for All apps so that splunk_stream_app can access the Event Types.

View solution in original post

0 Karma

kmower
Communicator

OK, I have answered this myself. The permissions for the Event Types for Splunk_TA_stream were restricted to 'The App' which is Splunk_TA_Stream, bit of course the Stream App is splunk_stream_app ... So the fix is to enable the Permissions for All apps so that splunk_stream_app can access the Event Types.

0 Karma
Get Updates on the Splunk Community!

User Groups | Upcoming Events!

If by chance you weren't already aware, the Splunk Community is host to numerous User Groups, organized ...

Splunk Lantern | Spotlight on Security: Adoption Motions, War Stories, and More

Splunk Lantern is a customer success center that provides advice from Splunk experts on valuable data ...

Splunk Cloud | Empowering Splunk Administrators with Admin Config Service (ACS)

Greetings, Splunk Cloud Admins and Splunk enthusiasts! The Admin Configuration Service (ACS) team is excited ...