All Apps and Add-ons

Dynatrace Application Performance Management: Why is are no events getting into the Splunk Dynatrace index?

srisahitya_v
Communicator

Hi Team,

We set up Dynatrace and Splunk Configuration, but no event data is coming to the Index. We have followed all steps as per Splunk & DT site.

index = _internal is showing some path details with dynatrace, but NO data.

Thanks

0 Karma

Dynatrace
Path Finder

@srisahitya_v:

Typically issues with the Dynatrace plugin are related to one of four items:

  1. Lack of Java on the Splunk host. The Dynatrace Splunk plugin currently requires the presence of Java on the Splunk host so that the Flume process that listens for data can run.
  2. Firewall preventing connectivity to Flume. Please ensure that connectivity exists between your Dynatrace server and Splunk server.
  3. Configuring the Dynatrace Business Transactions Feed to connect to the Splunk port rather than the Flume port. Remember that Dynatrace needs to connect to Flume, not Splunk. It will utilize port 4321 by default.
  4. Not configuring a Dynatrace Business Transaction for export. No data will be exported unless a Business Transaction is configured within Dynatrace to export data. This is done by right clicking on the business transaction within the Dynatrace client and ensuring the checkbox for "Export results via HTTP" is enabled. This configuration change is not retroactive and will only take place for new transactions coming into the environment monitored by Dynatrace.

Please don't hesitate to contact me directly via email at michael.villiger at dynatrace.com if none of the above solutions are applicable!

thanks!

0 Karma

srisahitya_v
Communicator

I checked the above points and all are fine, As per the Splunkd log it was showing that data is coming from dynatrace server but it is not landing into the "dynatrace" Index.

Here in Splunkd log I am getting the below error.

  1. HotDBManager - closing hot mgr for idx=dynatrace
  2. HotDBManager - idx=dynatrace Setting hot mgr params: maxHotSpanSecs=7776000 snapBucketTimespans=false maxHotBuckets=3 maxDataSizeBytes=786432000 quarantinePastSecs=77760000 quarantineFutureSecs=2592000

Could you please suggest or give the solution for this problem!!

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...