Getting Data In

Splunk app (forescout) could not read index

splunk-newbie
Loves-to-Learn

I am getting this error and needs help troubleshooting and resolving the issue: 
" App: [ForeScout App for Splunk] could not read index from : [ForeScout Technology Add-on for Splunk]"

 

Labels (2)
Tags (1)
0 Karma

splunk-newbie
Loves-to-Learn

Hi Soutamo,
Everything was working fine until a few days ago. The environment has been pretty steady, and I think something must have changed to cause that error. I just inherited the environment a couple of weeks ago and I need to get this issue resolved asap. Any help will be greatly appreciated.

0 Karma

isoutamo
SplunkTrust
SplunkTrust
Check from dashbords, macros, eventtypes which index it should use. Then check that this index exists and it has data and is readable. Look if there is any additional information on internal logs.
0 Karma

isoutamo
SplunkTrust
SplunkTrust
Hi
Have you done setup and create needed indexes described here https://www.forescout.com/company/resources/app-and-add-on-for-splunk-how-to-guide-2-9-1/ ?
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Improve Delivery Assurance with S2S ACK for Edge Processor

Edge Processor helps Splunk customers process data closer to the source: filtering, transforming, masking, and ...

.conf26 Platform Sessions: Turn Machine Data into Agentic Action

As autonomous agents and multi-cloud architectures reshape modern IT, data platforms have to do far more than ...

Introducing the Launch of Edge Processor in Hybrid Mode!

Modernize Data Ingestion Without Starting Over  For years, organizations have relied on Splunk's proven ...