Splunk ITSI

Report received from Splunk is incomplete and not generating

PONAS
Loves-to-Learn Lots

Hi Team,

Report received from Splunk is incomplete and not generating.

Where could we see date format on Splunk. Thanks,

 

Regards,
Sateesh

Labels (1)
0 Karma

PONAS
Loves-to-Learn Lots

Thanks for your response!

External server logs are being collected, but Splunk dashboards are not reflecting the data. Thanks,

 

0 Karma

PickleRick
SplunkTrust
SplunkTrust

There's so many things that can be wrong.

1. The data can be _not_ getting ingested properly.

2. The data can be not onboarded properly so that it's not properly understood by Splunk

3. Your dashboards or whatever means of searching your data can be not properly configured

4. The user can have no permissions to access the data

...

0 Karma

livehybrid
SplunkTrust
SplunkTrust

Hi @PONAS 

We will need a little more info on this please. You say its incomplete but also not generating, is it that sometimes it generates and sometimes not? Are there definitely events output when it isnt generated? 

Are you currently seeing date in a format you'd like to change? If so what is the desired format?

Please could you post the SPL of your search so that we can try and help you. 

🌟 Did this answer help you? If so, please consider:

  • Adding karma to show it was useful
  • Marking it as the solution if it resolved your issue
  • Commenting if you need any clarification

Your feedback encourages the volunteers in this community to continue contributing

0 Karma
Get Updates on the Splunk Community!

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

🔐 Trust at Every Hop: How mTLS in Splunk Enterprise 10.0 Makes Security Simpler

From Idea to Implementation: Why Splunk Built mTLS into Splunk Enterprise 10.0  mTLS wasn’t just a checkbox ...