All Apps and Add-ons

SiteName key causing failed dashboard searches

Shayde_Nofziger
Engager

My team is working on trying to get the Citrix Template up and running on our dashboard. We've found that many of the performance queries that include "SiteName=%sitename%" cause 0 results to be returned. Upon omitting this field in the search, the visualizations populate as they should. What is this SiteName value, and where should it be coming in through our data?

0 Karma

michael_mcgrail
Engager

I know this question is quite old, but if others run into this....
We had this same issue. Upon investigation, we have VDAs returning lower-case host names to the xd_perfmon index but UPPERCASE hostnames in the SiteInfo lookup. If you're on Splunk 7+, navigate to Lookups > Lookup definitions > siteHosts > Advanced options > uncheck Case sensitive match.

0 Karma

allenbraginsky
New Member

I also have this problem. I ran the search and it generated no results. If i remove it from the search then the dashboards work. Do i have to manually build a lookup file? If so, what is the syntax i would follow.

Thank you.
-Allen

0 Karma

richgalloway
SplunkTrust
SplunkTrust

@allenbraginsky This thread is almost two years old. To better your chances of getting help, you should post a new question.

---
If this reply helps you, Karma would be appreciated.
0 Karma

jconger
Splunk Employee
Splunk Employee

The template was built to support multiple XenDesktop sites. The PowerShell scripts in the TA-XD7-Broker add-on populate the SiteName value. This allows you to look at all XenDesktop sites, or just a particular XenDesktop site.

What do you get if you run the following search:

`xd_index` | stats count by SiteName
0 Karma

hainesac
Loves-to-Learn

I have the same issue. When I run the GetXDSite7.ps1 script, I receive the following error message:

WARNING: Only first 250 records returned. Use -MaxRecordCount to retrieve more.

0 Karma

hainesac
Loves-to-Learn

Running xd_index | stats count by SiteName, I received "No results yet found"

0 Karma

pgreer_splunk
Splunk Employee
Splunk Employee

Which dashboard/visualization are you referring to?

0 Karma
Get Updates on the Splunk Community!

What's new in Splunk Cloud Platform 9.1.2312?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.1.2312! Analysts can ...

What’s New in Splunk Security Essentials 3.8.0?

Splunk Security Essentials (SSE) is an app that can amplify the power of your existing Splunk Cloud Platform, ...

Let’s Get You Certified – Vegas-Style at .conf24

Are you ready to level up your Splunk game? Then, let’s get you certified live at .conf24 – our annual user ...