Getting Data In

Splunk app (forescout) could not read index

splunk-newbie
Loves-to-Learn

I am getting this error and needs help troubleshooting and resolving the issue: 
" App: [ForeScout App for Splunk] could not read index from : [ForeScout Technology Add-on for Splunk]"

 

Labels (2)
Tags (1)
0 Karma

splunk-newbie
Loves-to-Learn

Hi Soutamo,
Everything was working fine until a few days ago. The environment has been pretty steady, and I think something must have changed to cause that error. I just inherited the environment a couple of weeks ago and I need to get this issue resolved asap. Any help will be greatly appreciated.

0 Karma

isoutamo
SplunkTrust
SplunkTrust
Check from dashbords, macros, eventtypes which index it should use. Then check that this index exists and it has data and is readable. Look if there is any additional information on internal logs.
0 Karma

isoutamo
SplunkTrust
SplunkTrust
Hi
Have you done setup and create needed indexes described here https://www.forescout.com/company/resources/app-and-add-on-for-splunk-how-to-guide-2-9-1/ ?
0 Karma
Get Updates on the Splunk Community!

Splunk MCP & Agentic AI: Machine Data Without Limits

  Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization ...

Finding Based Detections General Availability

Overview  We’ve come a long way, folks, but here in Enterprise Security 8.4 I’m happy to announce Finding ...

Get Your Hands Dirty (and Your Shoes Comfy): The Splunk Experience

Hands-On Learning and Technical Seminars  Sometimes, you just need to see the code. For those looking for a ...