Hello Splunkers,
We have a problem with our Splunk installation. Its a simple platform, Splunk 6.2 on one computer running Ubuntu Linux.
The problem we are experiencing is that its not possible to read out license usage report. Daily usage and percentage is working correctly. Even if we show the license report the today tab is working, but when we switch to the Previous 30 days tab its not generating anything.
I've looked up the _internal index, but it's empty.
Also I tried the following steps:
But still there is no data in all the indexes starting with an underscore.
Does anyone have a clue?
Splunk support figured this out, the admin role wasn't allowed to be viewed by the users.
By trying to search | dbinspect index=_internal
they found that the index was working correct.
Splunk support figured this out, the admin role wasn't allowed to be viewed by the users.
By trying to search | dbinspect index=_internal
they found that the index was working correct.