All Apps and Add-ons

EMC VNX App for Splunk Enterprise: Why are some of the prebuilt panels not getting populated with data?

mtime24
Path Finder

Hello,

I've recently deployed the EMC VNX App for Splunk Enterprise on my Splunk instance and not all of the prebuilt panels are working. For instance, the storage processor response time, storage processor write time, top 10 block device writes, and top 10 block device reads are not working. All of the other prebuilt panels are working. Do I have to do anything on the array such as enabling statistics logging in order for these panels to work?

0 Karma
1 Solution

mtime24
Path Finder

apparently all i had to do was to enable performance logging on the array and just like that all the prebuilt charts started populating with information.

View solution in original post

mtime24
Path Finder

apparently all i had to do was to enable performance logging on the array and just like that all the prebuilt charts started populating with information.

mtime24
Path Finder

jkat54....thanks for the tip, I look at the apps settings which I normally never do and there are tons of predefined sourcetypes in there which i will have to explore....thanks!

0 Karma

jkat54
SplunkTrust
SplunkTrust

I converted this to the answer please mark it as such @mtime24

mtime24
Path Finder

thanks for the help

0 Karma

jkat54
SplunkTrust
SplunkTrust

No problem, you're welcome to upvote any comment that helped you 😉

0 Karma

jkat54
SplunkTrust
SplunkTrust

Sometimes you have to enable additional splunk inputs included in the app, sometimes you have to enable additional outputs from the device.

Best method to troubleshoot is to click on "open in search" in lower left corner of the panel, see what data it is looking for and then trace that backwards / reverse engineer to find why you're missing the data. It could be something as simple as specifying the index name in a search macro.

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...