Monitoring Splunk

Why is DMC showing servers "unknown" on overview page?

AzmathShaik
Path Finder

Screenshot 2023-08-11 at 3.46.52 PM.pngHello Splunkers

we recently upgraded our splunk distributed deployment from 8.2.9 to 9.0.5.1. After upgrade our splunk servers are started show under unknown category. 

it's pretty much impacting all the dashboards in monitoring console. below is the error 

"Streamed search execute failed because: Error in 'prerest' command: You do not have a role with the rest_access_server_endpoints capability that is required to run the 'rest' command with the endpoint=/services/server/status/limits/search-concurrency?count=0. Contact your Splunk administrator to request that this capability be added to your role.."

please let me know what can i do to bring the views back to normal. 

 

Thanks in advance

Labels (3)
0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

based on that error message you are needing a role which have rest_access_server_endpoints capability. Ask that your splunk admins add role which contains this capability or ad this to your current role.

r. Ismo

0 Karma

AzmathShaik
Path Finder

@isoutamo i have verified the capabilities. i assume this is a capabilities that need to be added to admin role. or do i need to create new role. 

0 Karma

isoutamo
SplunkTrust
SplunkTrust

As admin user should see those dashboards, you could add that capability to admin role.

0 Karma
Get Updates on the Splunk Community!

More Ways To Control Your Costs With Archived Metrics | Register for Tech Talk

Tuesday, May 14, 2024  |  11AM PT / 2PM ET Register to Attend Join us for this Tech Talk and learn how to ...

.conf24 | Personalize your .conf experience with Learning Paths!

Personalize your .conf24 Experience Learning paths allow you to level up your skill sets and dive deeper ...

Threat Hunting Unlocked: How to Uplevel Your Threat Hunting With the PEAK Framework ...

WATCH NOWAs AI starts tackling low level alerts, it's more critical than ever to uplevel your threat hunting ...