Splunk Enterprise

Database error while sending data to Dashboard

Ritu
Explorer

There are certain data labs created while the data stops indexing from some data labs, It should index data after every 15 minutes but that’s not happening. And those data gets reflected on the Splunk dashboard.

Can any one assist or suggest why the data for some datalabs are not indexing every 15 mins?

0 Karma

Ritu
Explorer

Can any one assist on it?

0 Karma

deepakc
Builder

What do you mean by data labs, can you please provide for the Splunk community a better posed question.

What is you set up, is datalabs a provider of some sort of data?

Is there a TA for for this or are you using the DB connect app if supported

Did this work before, what changed.

Have you developed a custom dashboard with panels that searches the data.

 

-------------------------------------------------------
NOTE:


Data is presented in the dashboards by the way of searches (SPL code) which is then set up inside of the dashboards.

Data is typically indexed into an index, Data model, index, summary index, or accelerated report and this comes from Splunk many different inputs methods. 

I would suggest start by looking at the dashboards SPL (Search code)  and troubleshoot from there. 

Look at the index (index=my_index) example and then workout where the inputs is coming from.

The TA's normally have some kind of inputs that perform collection every so often, if used you need to check the settings.

 

 

 

 

0 Karma

Ritu
Explorer

Hey,

Is there a TA for for this or are you using the DB connect app if supported---->

There is no TA, we are using the DB connect app  supported one in Splunk to generate data for the dashboard for some specific source types, and however we have set up specific data labs that should continously index data every 15 mins. Also, the database quires are efficiently running yet after all these configurations the data is not being sent as expected.

Did this work before, what changed.-- yes, this was working before when we created this.

Have you developed a custom dashboard with panels that searches the data.--- yes ,a custom dashboard with panels that searches the data.

0 Karma
Get Updates on the Splunk Community!

Now Available: Cisco Talos Threat Intelligence Integrations for Splunk Security Cloud ...

At .conf24, we shared that we were in the process of integrating Cisco Talos threat intelligence into Splunk ...

Preparing your Splunk Environment for OpenSSL3

The Splunk platform will transition to OpenSSL version 3 in a future release. Actions are required to prepare ...

Easily Improve Agent Saturation with the Splunk Add-on for OpenTelemetry Collector

Agent Saturation What and Whys In application performance monitoring, saturation is defined as the total load ...