All Apps and Add-ons

Splunk App for Infrastructure

pietertruter1
Observer

I have installed V2.02 of the app and configured manual performance metrics inputs to Windows hosts with UF already installed. Problem is that the Overview dashboard panels are not working. | inputlookup em_entities is returning results for my hosts, but I notice that the metric_name fields are all small caps and the dashboard searches are looking for metric_names that is not all small caps: avg(Processor.%_Privileged_Time). If I change the metric names in the search to all small caps the searches run without issues.
If I read the metrics index documentation it states that you can only use small caps in the metric names.

Am I missing something when creating the manual inputs? Field alias also does not seem to be working either and I also cant find where to edit the dashboards to change the metric names.

Any suggestions welcome? Short from recreating all the dashboards to my own Im out of ideas.

Thanks
Pieter

0 Karma

pietertruter1
Observer

So we are on 7.3.3 on the Search head, but our indexers are still on 7.1.* which we are planning to upgrade soon.

Thanks for the quick answer. Will test again after our indexers are upgraded as well.

0 Karma

dagarwal_splunk
Splunk Employee
Splunk Employee

Yeah.. your indexers are the problem.. It needs to be 7.2 or higher.

0 Karma

dagarwal_splunk
Splunk Employee
Splunk Employee

Are you using Splunk version 7.1.* for your SAI? If yes, please upgrade version to 7.2 or higher..

0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...