Getting Data In

Issue with getting data to Splunk App for Hyperledger Fabric

ginsp
Observer

I am very new to splunk, We are trying to monitor our hyperledger fabric network with the Splunk App for fabric in the splunk enterprise. We have a hyperledger fabric network with version 2.2.2. I installed the app and followed the instructions specified in https://splunkbase.splunk.com/app/4605/#/details . I also setup the fabric-logger and i could see the fabric-logger is running and it is able to fetch the blocks and event details from the peer from which it is connected to. In the splunk enterprise UI, I got below message. "Search peer indexer-0 has the following message: Received event for unconfigured/disabled/deleted index=hyperledger_logs with source="source::fabriclogger" host="host::fabric-logger-6b79d77b99-bncwj" sourcetype="sourcetype::fabric_logger:endorser_transaction". So far received events from 1 missing index(es).". I have the HEC enabled and i also have the index hyperledger_logs. I don´t see any errors in the logs of fabric-logger or in the indexer. But I am not seeing any data also in the splunk. Please find the screenshot below

 

ginsp_0-1619084712411.png

 

Labels (1)
0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...