Splunk IT Service Intelligence

Metrics selection in Splunk app for infrastructure (analysis tab) not working after moving index to S3

brunofernandez
Explorer

I am using the Splunk App for infrastructure to collect metrics.
One of my index is called prometheus_dock.
Using SmartStore I recently moved the buckets for that index to S3.
Everything is working fine. I can still query the metrics in search panel (mstats) for that particular index.
However, since the move, when I am trying to explore metrics for entities (tab Analysis, Metrics on the left hand side of the screen) I cannot select metrics as I am getting this error message:

Failed to localize fileTypeSet="{"file_types":["tsidx","deletes"]}" for bid=prometheus_dock~44~91006D1B-62E3-4512-8E14-7120EE9BA8B4

Splunkd.log does not say much either:

MetricStoreCatalogBaseHandler - Failed to localize fileTypeSet="{"file_types":["tsidx","deletes"]}" for bid=prometheus_dock~44~91006D1B-62E3-4512-8E14-7120EE9BA8B4

My guess is that (as oppose as Splunk core), the Splunk app for infrastructure can only get data from local storage and cannot connect to S3...

0 Karma

ntankersley_spl
Splunk Employee
Splunk Employee

The App for Infra team has been unable to reproduce this issue. Did the index name for the metrics change?

0 Karma
Get Updates on the Splunk Community!

Index This | I’m short for "configuration file.” What am I?

May 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with a Special ...

New Articles from Academic Learning Partners, Help Expand Lantern’s Use Case Library, ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Your Guide to SPL2 at .conf24!

So, you’re headed to .conf24? You’re in for a good time. Las Vegas weather is just *chef’s kiss* beautiful in ...