Splunk ITSI

Why is the Splunk Insights for Infrastructure not showing entity and data?

s2801871r
Explorer

We recently cloned a VM to a new one. Changed the references of the old host name to the new one in the following files:

/etc/collectd.conf - changed Hostname
/opt/splunkforwarder/etc/system/local/server.conf - changed Servername
/opt/splunkforwarder/etc/system/local/inputs.conf - changed host

Restarted both collectd and Splunk on the new server. Still, the entity did not show up in the Insights for Infrastructure portal. There are no errors in both /etc/collectd/collectd.log and /opt/splunkforwarder/var/log/splunkd.log files.

What else can be done to correct this issue?

0 Karma
1 Solution

dagarwal_splunk
Splunk Employee
Splunk Employee
  • Please verify token in collectd.conf for with SII "Add Data" page script.
  • Make sure "LoadPlugin cpu" or "Hostname" not commented out in collectd.conf. Also, check that collectd is actually running.
  • If still not solved, try restarting collectd again and post collectd.log here.

View solution in original post

0 Karma

s2801871r
Explorer

Yes. In addition to following the steps you outlined, I also had to restart the SII collector to see the list in the portal. Hope this helps somebody. Thanks for your help @dagarwal_splunk

0 Karma

dagarwal_splunk
Splunk Employee
Splunk Employee
  • Please verify token in collectd.conf for with SII "Add Data" page script.
  • Make sure "LoadPlugin cpu" or "Hostname" not commented out in collectd.conf. Also, check that collectd is actually running.
  • If still not solved, try restarting collectd again and post collectd.log here.
0 Karma

s2801871r
Explorer

In addition to following these steps, I also had to restart the Splunk collector. Then, I was able to see the entities and data in the portal. Thanks @dagarwal_splunk !

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...