Splunk ITSI

Metrics selection in Splunk app for infrastructure (analysis tab) not working after moving index to S3

brunofernandez
Explorer

I am using the Splunk App for infrastructure to collect metrics.
One of my index is called prometheus_dock.
Using SmartStore I recently moved the buckets for that index to S3.
Everything is working fine. I can still query the metrics in search panel (mstats) for that particular index.
However, since the move, when I am trying to explore metrics for entities (tab Analysis, Metrics on the left hand side of the screen) I cannot select metrics as I am getting this error message:

Failed to localize fileTypeSet="{"file_types":["tsidx","deletes"]}" for bid=prometheus_dock~44~91006D1B-62E3-4512-8E14-7120EE9BA8B4

Splunkd.log does not say much either:

MetricStoreCatalogBaseHandler - Failed to localize fileTypeSet="{"file_types":["tsidx","deletes"]}" for bid=prometheus_dock~44~91006D1B-62E3-4512-8E14-7120EE9BA8B4

My guess is that (as oppose as Splunk core), the Splunk app for infrastructure can only get data from local storage and cannot connect to S3...

0 Karma

ntankersley_spl
Splunk Employee
Splunk Employee

The App for Infra team has been unable to reproduce this issue. Did the index name for the metrics change?

0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...