All Apps and Add-ons

Is there any set up steps for the Splunk Add-on for Box on Search Head servers?

lyanta
Explorer

I installed the Splunk Add-on for Box on my heavy forwarder and search head servers. Per the documentation, I configured the app on my heavy forwarder to retrieve events from Box.

While viewing the objects for the Splunk Add-on for Box using the search head server Splunk web app, I noticed there are several panels. How do I make the app visible on the search head servers to obtain access to these panels without needing to perform the setup that retrieves events from Box?

0 Karma
1 Solution

lyanta
Explorer

I figured out my problem. I needed to update the permissions for the app to be available for all applications. After doing this, the panels were available in the dashboard editor to be added to a custom dashboard.

View solution in original post

0 Karma

lyanta
Explorer

I figured out my problem. I needed to update the permissions for the app to be available for all applications. After doing this, the panels were available in the dashboard editor to be added to a custom dashboard.

0 Karma

jkat54
SplunkTrust
SplunkTrust

The documentation says you just install the addon on the heavy forwarder and the search head.

My hunch is your dashboards need the correct index name in their searches. You might have to edit a macro being used by the app to specify the correct index(es). From what I can tell you specify the index when you configure the inputs. So somewhere you've got to align those prebuilt dashboard searches with the index name you used. Maybe you specified one name and then changed it after setup, etc... check your macros in the app and the underlying searches to be sure they're configured for the correct index(es).

http://docs.splunk.com/Documentation/AddOns/latest/Box/Install

Install the Splunk Add-on for Box
Specific installation notes for this add-on
**In a distributed deployment, install the Splunk Add-on for Box to your search heads and heavy forwarders.**

If that doesnt fix it, please open a "broken" dashboard panel in search and look at the job inspector for search.log etc. and update this post any errors and warnings you see.

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...