Splunk Enterprise Security

Cannot read properties of undefined (reading 'map')

Anit_Mathew
New Member

i having some issues to populate the traffic center dashboard in splunk ES. It's showing as "Cannot read properties of undefined (reading 'map')".

anyone have any solutions?

Screenshot 2025-02-13 124637.png

Labels (2)
0 Karma

livehybrid
Super Champion

Hi @Anit_Mathew 

Did you get to the bottom of this? 

This looks like the "Traffic Over Time By Protocol" panel which is broken? Which version of ES are you on?

In ES 7.3.2 the search it runs is something like this:

| `tstats` count from datamodel=Network_Traffic.All_Traffic where * by _time,All_Traffic.transport span=10m | timechart minspan=10m useother=`useother` count by All_Traffic.transport | `drop_dm_object_name("All_Traffic")`

Which doesnt look like it has a map command anywhere, unless you have altered any macros?

Please can you confirm the ES and CIM app versions you are using and if any changes have been made to the macros?

Please let me know how you get on and consider accepting this answer or adding karma this answer if it has helped.
Regards

Will

0 Karma

VatsalJagani
SplunkTrust
SplunkTrust

@Anit_Mathew- If it is Splunk ES default dashboard without any change in it and if it is still giving you error you can raise Splunk support ticket for it.

 

0 Karma
Get Updates on the Splunk Community!

The All New Performance Insights for Splunk

Splunk gives you amazing tools to analyze system data and make business-critical decisions, react to issues, ...

Good Sourcetype Naming

When it comes to getting data in, one of the earliest decisions made is what to use as a sourcetype. Often, ...

See your relevant APM services, dashboards, and alerts in one place with the updated ...

As a Splunk Observability user, you have a lot of data you have to manage, prioritize, and troubleshoot on a ...