All Apps and Add-ons

Status Indicator - Custom Visualization: Why do I have a broken dashboard and see strange tar behavior?

SierraX
Communicator

Hi,

Just downloaded the Status Indicator - Custom Visualization App ( https://splunkbase.splunk.com/app/3119/ ) (about small Karma splunkbase 3119)
and the panels looks ... I link a pic:
viz_test
This was on a fresh Mac OS X - Splunk 6.4 installation, installed with the webUI, but it looks the same on an installation via deployment server on a 6.4.0 Centos 7.1 Search Head.

The tar command to untar the .tgz to right folder shows some strange behavior:

tar: Ignoriere unbekanntes Schlüsselwort „LIBARCHIVE.creationtime“ für erweiterten Kopfteil
tar: Ignoriere unbekanntes Schlüsselwort „SCHILY.dev“ für erweiterten Kopfteil
tar: Ignoriere unbekanntes Schlüsselwort „SCHILY.ino“ für erweiterten Kopfteil
tar: Ignoriere unbekanntes Schlüsselwort „SCHILY.nlink“ für erweiterten Kopfteil

adds the last 3 lines of the list, in front of every line to extract.

For the non-German speakers:

tar: Ignore unknown keyword "*" for enhanced header.

Is there a fix scheduled?

0 Karma
1 Solution

magnew_splunk
Splunk Employee
Splunk Employee

Hi SierraX,

It looks like this is a test dashboard that was mistakenly shipped with the visualization. Do you see similar issues in the app's main 'gallery' dashboard? We'll make sure to remove the test dashboard in going forward.

View solution in original post

0 Karma

magnew_splunk
Splunk Employee
Splunk Employee

Hi SierraX,

It looks like this is a test dashboard that was mistakenly shipped with the visualization. Do you see similar issues in the app's main 'gallery' dashboard? We'll make sure to remove the test dashboard in going forward.

0 Karma

ziegfried
Influencer

Don't worry about the tar warning messages. This is just some additional metadata the tar on OSX included. It's shouldn't cause any problems.

SierraX
Communicator

But looks not nice and professional anyway.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Data Management Digest – August 2026

MichelleCorpora_1-1788182384472.png Welcome to the August 2026 edition of Data Management Digest! August was a ...

Your Feedback. Our Roadmap. Visit the PX Feedback Booth at .conf26

You use Splunk every day, come and help shape what's next.  Save Your Seat: Product-Focused Sessions at ...

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...