Splunk ITSI

ITSI - Exchange - Dashboard - Inbound Messages - Microsoft Exchange - Inbound Message Volume - Built-in macro bug?

corti77
Contributor

Hi,

after the installation of ITE Works 4.9.2 and the exchange content pack. I checked all the dashboards to be sure the data was correctly processed and I realized that some panels were blank.

One of them, Inbound Messages - Microsoft Exchange, the panel related to the inbound message volume is empty. looking into the search, 

 

`msgtrack-inbound-messages`|eval total_kb=total_bytes/1024|timechart fixedrange=t bins=120 per_second(total_kb) as "Bandwidth"

 


I realized that the first macro does not return a column total_bytes so the eval cannot create the new field total_kb so the timechart can not visualize anything.

is there some configuration missing on my side or is it a known bug of the content pack?

corti77_0-1629108703022.png

Cheers

 

Labels (2)
0 Karma

eduncan
Splunk Employee
Splunk Employee

Hey I will load this on my env and take a look and if it is a bug I will let the developer know.

0 Karma
Get Updates on the Splunk Community!

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...

[Live Demo] Watch SOC transformation in action with the reimagined Splunk Enterprise ...

Overwhelmed SOC? Splunk ES Has Your Back Tool sprawl, alert fatigue, and endless context switching are making ...

What’s New & Next in Splunk SOAR

Security teams today are dealing with more alerts, more tools, and more pressure than ever.  Join us on ...