Getting Data In

Jira Issue Input: Why is Add-on data not indexing?

sweetie
Explorer

hello, I have installed the add-on (Jira issue input add-on: https://splunkbase.splunk.com/app/6168) for collecting jira data in our splunk enterprise.  We have configured the account and required input. However cant see any data getting ingested in splunk. Internal jira log (ta_jira_issue_input_jira_issue.log) says below- 

2023-07-13 07:00:31,772 INFO pid=23702 tid=MainThread file=base_modinput.py:log_info:295 | The input xyz_jira_input ran successfully! There were no (new) Jira issues indexed during this interval.

Any idea why the data is not getting ingested? Happy to share more details as needed.

 

Thanks

Labels (2)
Tags (4)
0 Karma

VatsalJagani
SplunkTrust
SplunkTrust

@sweetie 

  1. It creates a new event when you create a new Jira ticket.
    1.  
  2. Also, please check your Splunk Add-on input, the field for JQL is covering the tickets that you want to ingest.
    1. VatsalJagani_0-1689317270677.png

       

    2. You could test it on the Jira side.
    3.  
  3. Last thing, ensure that you are running the search in all-time in the right ingest to see there is no timing related issues causing this.

 

I hope this helps!!! If it does kindly consider upvoting/accepting the answer!!

0 Karma

sweetie
Explorer

Thanks @VatsalJagani , the query I used in JQL is below- and this helped in ingesting the data.

project IN (SD)

 

However, There is a limitation to this Jira issue input add-on which we found. It ingests only 500 tickets and leaves the rest. On next poll , since previous job was not completed it tries pulling the data again but brings the same 500 ticket entries again. This not only results in duplicates in every poll but also missing data (if you gave >500 tickets). Are you aware of this limitation and any fix?

 

Thanks

0 Karma

VatsalJagani
SplunkTrust
SplunkTrust

@sweetie - Ensure configure the Add-on properly.

 

Otherwise, try to contact the Add-on developers if support is provided (you can check that on Splunkbase page for the Add-on)

 

0 Karma

sweetie
Explorer

hi @VatsalJagani - I have tried testing the inputs multiple times and it does bring me the data but nothing more than 500 records from jira tickets. 
The app is developer supported: 
 https://splunkbase.splunk.com/app/6168

 

Thanks

0 Karma

VatsalJagani
SplunkTrust
SplunkTrust

@sweetie - I would suggest contacting the developer or creating an issue on the Github repo - https://splunkbase.splunk.com/app/6168  

0 Karma

sweetie
Explorer

hi, As a workaround for now- I have further split my data into labels such that the JQL is like
project IN (xyx) AND labels IN (abc)

Though had to create multiple inputs but this has narrowed down my results hence pulling the required data.

 

Thanks

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In September, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...

New in Observability - Improvements to Custom Metrics SLOs, Log Observer Connect & ...

The latest enhancements to the Splunk observability portfolio deliver improved SLO management accuracy, better ...

Improve Data Pipelines Using Splunk Data Management

  Register Now   This Tech Talk will explore the pipeline management offerings Edge Processor and Ingest ...