All Apps and Add-ons

After upgrading the Splunk App for Windows Infrastructure from 1.0.3 to 1.1.3, why are some dashboards showing "Search produced no result"?

simontam
Explorer

I have just upgraded the Windows Infrastructure app from 1.0.3 to 1.1.3. Did many updates on different add-ons and related lookups. Everything seems good, but some dashboards are showing "search produced no result" on the top form input fields, which causes no results in the following tables and charts.

For example, the Active Directory > Domain Controllers > Domain Status, on the top right corner, the Domain drop down list is empty. I have tried to read all the related lookup "DomainSelector", "HostToDomain" and "SiteInfo". They all can return the correct information.

Any hints for me to troubleshoot the problem?

Thanks in advance.

0 Karma

hortonew
Builder

Start by clicking the magnifying glass (bottom left of dashboard panel) to see what search is being used for ones that aren't returning results. Sometimes the answer will be obvious just seeing what the app is searching for. Check a couple things:

Is it searching the correct indexes/sourcetypes for your environment? If no index/sourcetype is provided, try adding them (may not have these searched by default in your user's permissions).

Report back if still having issues.

0 Karma

simontam
Explorer

Thanks hortonew,

As in my example, the Domain Status page, which includes three components:
1: Domain drop down selector on the top right corner
2: Sites section on the left
3: Domain Controllers section on the right

Belows are the messages:
The domain drop down selector shows "Search produced no results".
Both the Sites and Domain Controllers shows "Search is waiting for input..."

I tried to click the magnify glass but nothing response.

Any hints? ToT

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...