All Apps and Add-ons

MSExchange APP: "No matching fields"

mikelanghorst
Motivator

I've installed the MSExchange app, and have data coming in. However when I view the summary page, and several other dashboard pages, I get a blue banner message saying "No matching fields exist." Many of the "activity" reports currently aren't working, but I don't know if those are related.

0 Karma

mikelanghorst
Motivator

As for the field extractions, searching for each of these sourcetypes it there are a number of fields extracted. But obviously, theres at least one missing.

0 Karma

mikelanghorst
Motivator

Sourcetypes, in the index=msexhange there are currently 9 sourcetypes seen:
WinEventLog:Security
WinEventLog:Application
MSExchange:2010:Topology
MSExchange:2010:PublicFolder-Stats
MSExchange:2010:MessageTracking
MSExchange:2010:Mailbox-Usage
MSExchange:2010:Folder-Usage
MSExchange:2010:Database-Stats
MSExchange:2010:AdminAudit

0 Karma

ahall_splunk
Splunk Employee
Splunk Employee

Unfortunately, there is not enough to go on here to even begin to answer this. Here are some things to check:

  1. What specific source types are coming in?
  2. Is the MSExchange Topology source type coming in?
  3. Are the field extractions working?
  4. Are they going into the right indices (see eventtypes.conf and macros.conf)

As always, more information is better.

0 Karma

ahall_splunk
Splunk Employee
Splunk Employee

Non-Reporting Servers is hopefully blank, unless you have non-reporting servers. The hosts is a little more troubling. Extract the search from the page (it's embedded clearly in the XML) and run it by hand.

0 Karma

jamlam
Explorer

I'm having the same issue, in my case the panels missing on the system overview page are Hosts and Non-Reporting Servers

0 Karma

ahall_splunk
Splunk Employee
Splunk Employee

Ok - next step - which particular panels on the summary overview have no data? This will narrow down which search is missing information from the field extractions.

0 Karma

mikelanghorst
Motivator

Thanks for replying. The confusing part for me is when there are many searches on the page, such as the summary not knowing which search is complaining. Yea, I'll have to dig deeper, but maybe someone saw this.

I'll add the additional info to the original question.

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...