Monitoring Splunk

DMC not displaying server metrics

tlmayes
Contributor

On our Monitoring Console on the "Overview", it does not display any metrics under "Resource Usage" for each of the categories "Indexers", "Search Heads", etc.  Not the browser, have tried from different computers, same problem.  No WARN or ERROR messages on the host, no errors in the "Setup" page, and CPU/RAM utilization is extremely low.

Anybody else experienced this?

Labels (1)
0 Karma
1 Solution

tlmayes
Contributor

Splunk says that it is an "as yet published" "known issue" since v9.1.0.  They will not classify it as a "bug" until they can verify.  How can it be classified as a known issue, and simultaneously not verified? 

View solution in original post

0 Karma

tlmayes
Contributor

Splunk says that it is an "as yet published" "known issue" since v9.1.0.  They will not classify it as a "bug" until they can verify.  How can it be classified as a known issue, and simultaneously not verified? 

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @tlmayes,

bug and known issues are synonyms.

doe Splunk Support give an indication about when the known issue will be solved?

Anyway, let me know if I can help you more.

Ciao.

Giuseppe

P.S.: Karma Points are appreciated 😉

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @tlmayes,

at first: did youconfigured yur DMC to take logs from the other servers?

To do this you have to connect the DMC to all the server to monitor on the 8089 port as a Search Head in Distributed Search.

Then, have you the message "N.A." or what else?

if you have "N.A.", are you using the last Splunk version (9.1.2)? because the previous version had a bug.

Ciao.

Giuseppe

0 Karma

tlmayes
Contributor

@gcusello , appreciate the response.  
Yes, this is a DMC that has been operational for ~ 3years, and suddenly started doing this.  All sources are connected without error.  I even removed a few and added back to see what happened.  No immediate change.  The interface works..... some of the time, about 20% but cannot figure out why it suddenly works, and without any change, refresh the screen and it is broken AGAIN.  

I did update as soon as 9.1.2 appeared hoping that would fix it (updated the entire architecture).  No luck, still broken

About to the point what I am simply going to delete it, and start over

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @tlmayes,

before restarting, open a case to Splunk Support, sending them a diag.

Ciao.

Giuseppe

0 Karma

tlmayes
Contributor

Splunk support responded that this was a known, as yet published, bug in the software.  Was hoping 9.2 release fixed this but sadly it did not

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...