Splunk Enterprise Security

Cannot read properties of undefined (reading 'map')

Anit_Mathew
Engager

i having some issues to populate the traffic center dashboard in splunk ES. It's showing as "Cannot read properties of undefined (reading 'map')".

anyone have any solutions?

Screenshot 2025-02-13 124637.png

Labels (2)
0 Karma

livehybrid
SplunkTrust
SplunkTrust

Hi @Anit_Mathew 

Did you get to the bottom of this? 

This looks like the "Traffic Over Time By Protocol" panel which is broken? Which version of ES are you on?

In ES 7.3.2 the search it runs is something like this:

| `tstats` count from datamodel=Network_Traffic.All_Traffic where * by _time,All_Traffic.transport span=10m | timechart minspan=10m useother=`useother` count by All_Traffic.transport | `drop_dm_object_name("All_Traffic")`

Which doesnt look like it has a map command anywhere, unless you have altered any macros?

Please can you confirm the ES and CIM app versions you are using and if any changes have been made to the macros?

Please let me know how you get on and consider accepting this answer or adding karma this answer if it has helped.
Regards

Will

VatsalJagani
SplunkTrust
SplunkTrust

@Anit_Mathew- If it is Splunk ES default dashboard without any change in it and if it is still giving you error you can raise Splunk support ticket for it.

 

First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

September Community Champions: A Shoutout to Our Contributors!

As we close the books on another fantastic month, we want to take a moment to celebrate the people who are the ...

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...

What’s New in Splunk Observability – September 2025

What's NewWe are excited to announce the latest enhancements to Splunk Observability, designed to help ITOps ...