The initial installation goes through without a problem and the dashboard items appear, however none of the data being sent to the Splunk server(we confirmed the data is coming in) is being displayed on the Dashboard. A lot of the searches seem to reference a src_ip field, and I see where this transformation is supposed to happen, but when searching for src_ip, it returns nothing.
Is there a step missing to connect this missing src_ip field? I believe this is the cause of the dashboards being empty.
... View more