Splunk ITSI

Why is the Splunk Insights for Infrastructure not showing entity and data?

s2801871r
Explorer

We recently cloned a VM to a new one. Changed the references of the old host name to the new one in the following files:

/etc/collectd.conf - changed Hostname
/opt/splunkforwarder/etc/system/local/server.conf - changed Servername
/opt/splunkforwarder/etc/system/local/inputs.conf - changed host

Restarted both collectd and Splunk on the new server. Still, the entity did not show up in the Insights for Infrastructure portal. There are no errors in both /etc/collectd/collectd.log and /opt/splunkforwarder/var/log/splunkd.log files.

What else can be done to correct this issue?

0 Karma
1 Solution

dagarwal_splunk
Splunk Employee
Splunk Employee
  • Please verify token in collectd.conf for with SII "Add Data" page script.
  • Make sure "LoadPlugin cpu" or "Hostname" not commented out in collectd.conf. Also, check that collectd is actually running.
  • If still not solved, try restarting collectd again and post collectd.log here.

View solution in original post

0 Karma

s2801871r
Explorer

Yes. In addition to following the steps you outlined, I also had to restart the SII collector to see the list in the portal. Hope this helps somebody. Thanks for your help @dagarwal_splunk

0 Karma

dagarwal_splunk
Splunk Employee
Splunk Employee
  • Please verify token in collectd.conf for with SII "Add Data" page script.
  • Make sure "LoadPlugin cpu" or "Hostname" not commented out in collectd.conf. Also, check that collectd is actually running.
  • If still not solved, try restarting collectd again and post collectd.log here.
0 Karma

s2801871r
Explorer

In addition to following these steps, I also had to restart the Splunk collector. Then, I was able to see the entities and data in the portal. Thanks @dagarwal_splunk !

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...