I am working on a brand new Splunk cloud instance. I installed the App for web analytics app and then uploaded an IIS log file. I configured the App by defining the site name and host, source mappings. I then ran the lookups for the SEssions and Pages and then enabled the data model acceleration.
I was able to see data and was happy. I then added another IIS log file for a different site/server to the same index named "main". i went back to the Setup --> Websites page expecting to see the new site in the "Available host and source combinations" section and it was not there. Only the initial site I setup is listed there. Additionally, when I search for tag=web from within the App it only shows me the data from the first site. If I run the same search outside of the App it doesn't return anything.
I could sure use a little help here. 🙂
-Pete
... View more