All Apps and Add-ons

Dashboards not working or have random gaps in information

mwarvi
Explorer

Since the upgrade to 6.0, including 6.0.1, the dashboards are more often not working than working for me.

In particular, the All Incidents dashboard seems to randomly stop being populated with data. For example, yesterday there's no information between 12pm and 6pm, and then today from 2am to 6am. I can confirm that there are incident type logs coming in the entire time, and that they are being parsed correctly. Data models are 100% and accelerated. During these gaps, the User Behavior dashboard also doesn't work.

As for other issues, the File Activity dashboard is always on "Waiting for data...", Endpoint and Firewall config is no results found, web activity is only loading Top Referrers and Methods over Time.

GlobalProtect, Firewall System and Real-Time seem to be working without an issue.

As stated before, the events are being tagged and parsed into the different event types fine. I'm just not sure where else to look.

0 Karma

darrenbisbey
New Member

i'm using 7.0 not 62

D.

0 Karma

nikita_p
Contributor

Hi @mwarvi,
Can you check below answer in splunk if it helps you?
https://answers.splunk.com/answers/186429/splunk-62-upgrade-issue-users-can-no-longer-create.html

0 Karma

DalJeanis
Legend

Okay, one possibility is that your underlying searches are not being run, either because they are not set up correctly, or because they are taking too long and the next one gets skipped. Try something like this to test that...

 index=_internal source=*metrics.log group=searchscheduler 
| timechart partial=false span=10m sum(dispatched) sum(skipped)   
0 Karma

darrenbisbey
New Member

GlobalProtect, Firewall System and Real-Time are working but as the above poster said. But all other dashboards not.

This was a fresh install.

Darren

0 Karma
Get Updates on the Splunk Community!

Introducing Splunk Enterprise 9.2

WATCH HERE! Watch this Tech Talk to learn about the latest features and enhancements shipped in the new Splunk ...

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...