Getting Data In

Splunk app (forescout) could not read index

splunk-newbie
Loves-to-Learn

I am getting this error and needs help troubleshooting and resolving the issue: 
" App: [ForeScout App for Splunk] could not read index from : [ForeScout Technology Add-on for Splunk]"

 

Labels (2)
Tags (1)
0 Karma

splunk-newbie
Loves-to-Learn

Hi Soutamo,
Everything was working fine until a few days ago. The environment has been pretty steady, and I think something must have changed to cause that error. I just inherited the environment a couple of weeks ago and I need to get this issue resolved asap. Any help will be greatly appreciated.

0 Karma

isoutamo
SplunkTrust
SplunkTrust
Check from dashbords, macros, eventtypes which index it should use. Then check that this index exists and it has data and is readable. Look if there is any additional information on internal logs.
0 Karma

isoutamo
SplunkTrust
SplunkTrust
Hi
Have you done setup and create needed indexes described here https://www.forescout.com/company/resources/app-and-add-on-for-splunk-how-to-guide-2-9-1/ ?
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...