The "Splunk Add-on for NetApp Data ONTAP" is only fetching performance information for the first 50 volumes on a cluster. Changing the "perf_chunk_size_cluster_mode" value in ta_ontap_collection.conf will vary the number -- if I set it to 53, I'll get performance data for the first 53 alphabetic volumes on the cluster. You can't set this arbitrarily large, if I put it to 10000, I get a failure on the data collection.
The chunking mechanism is part of OntapPerf.py, and normally would iterate over multiple queries until it collected data for all volumes. This worked for years, but has been broken for several months now. May or may not align with our upgrade to Splunk Enterprise 8.2.2 and Python 3.
Add-on is latest version (3.0.2). Filers are running ONTAP 9.7. I went back through the install manual and verified all the steps and add-on data. Inventory/capacity information works without issue, it is just performance metrics that are a problem.
OntapPerf.py throws log warnings "No instances found for object type volume"... from line 461 in the script.
It seems like the "next_tag" mechanism in the script is failing, but I can't work out how to run OntapPerf.py from command line, I don't know how to troubleshoot any further.
Splunk_TA_ontap shows as "unsupported" and developed by "Splunk Works". Last release was June 2021. I could really use some pointers on how to resolve this, or how I could move forward troubleshooting it myself.