Splunk IT Service Intelligence

Why is the Splunk Insights for Infrastructure not showing entity and data?

Explorer

We recently cloned a VM to a new one. Changed the references of the old host name to the new one in the following files:

/etc/collectd.conf - changed Hostname
/opt/splunkforwarder/etc/system/local/server.conf - changed Servername
/opt/splunkforwarder/etc/system/local/inputs.conf - changed host

Restarted both collectd and Splunk on the new server. Still, the entity did not show up in the Insights for Infrastructure portal. There are no errors in both /etc/collectd/collectd.log and /opt/splunkforwarder/var/log/splunkd.log files.

What else can be done to correct this issue?

0 Karma
1 Solution

Splunk Employee
Splunk Employee
  • Please verify token in collectd.conf for with SII "Add Data" page script.
  • Make sure "LoadPlugin cpu" or "Hostname" not commented out in collectd.conf. Also, check that collectd is actually running.
  • If still not solved, try restarting collectd again and post collectd.log here.

View solution in original post

0 Karma

Explorer

Yes. In addition to following the steps you outlined, I also had to restart the SII collector to see the list in the portal. Hope this helps somebody. Thanks for your help @dagarwal_splunk

0 Karma

Splunk Employee
Splunk Employee
  • Please verify token in collectd.conf for with SII "Add Data" page script.
  • Make sure "LoadPlugin cpu" or "Hostname" not commented out in collectd.conf. Also, check that collectd is actually running.
  • If still not solved, try restarting collectd again and post collectd.log here.

View solution in original post

0 Karma

Explorer

In addition to following these steps, I also had to restart the Splunk collector. Then, I was able to see the entities and data in the portal. Thanks @dagarwal_splunk !

0 Karma