Splunk Search

Splunk for Exchange 2.0 - Blank charts with 4.3.4

letienne
Path Finder

Hello,

I just upgraded from 4.3.3 to 4.3.4 and Splunk for Exchange to 2.0, and now it seems that all the charts are blank or empty. The data is here when I run the search manually, but the dashboard just stays blank. By blank I mean that I see a blank empty rectangle; it does NOT say "no results found":

alt text

I can make some of the charts appear by resizing the chart panel, but not all. Not sure if this is a Splunk or Splunk for Exchange issue. I have chart in other apps that work just fine.

Have any of you seen this issue?

Thanks !

Kind regards,

0 Karma
1 Solution

letienne
Path Finder

I found a workaround to this issue:

Replacing "module name="JSChart" by "module name="FlashChart"" in the views.xml allow the charts to render properly.

Is there anything I can do to help you find out what's wrong with JSChart?

Regards,

View solution in original post

0 Karma

letienne
Path Finder

I found a workaround to this issue:

Replacing "module name="JSChart" by "module name="FlashChart"" in the views.xml allow the charts to render properly.

Is there anything I can do to help you find out what's wrong with JSChart?

Regards,

0 Karma

ahall_splunk
Splunk Employee
Splunk Employee

If you have a paid version, open up a support case. I think you have given me enough to work on, though. Since it happens in all browsers, it should be easy enough to track down.

0 Karma

ahall_splunk
Splunk Employee
Splunk Employee

Given that the chart appears when you re-size it, I'm going to go out on a limb and say "Splunk issue" - what browser and version are you using?

0 Karma

letienne
Path Finder

Running the search defined in sizing_messages.xml by hand gives me data:

http://imgh.us/Untitled_149.png
http://img15.hostingpics.net/pics/459330Untitled.png

It really looks like a rendering issue. Is there any way to force flash rendering from the xml to see if this changes anything?

0 Karma

ahall_splunk
Splunk Employee
Splunk Employee

Check the underlying data - this chart is produced via a summarization in saved_searches.conf, so the data may not be there yet. Ensure the saved search is running and producing the correct summarization.

0 Karma

letienne
Path Finder

Win7x64SP1, with IE9, Firefox 4, or Chrome 19.

I am unable to make the charts above appear by resizing them. It works, however, with the "Message Rate" from the "dashboard_live".

Any idea on how I could fix this?

Can anyone with 4.3.4 and Splunk for Exchange 2.0 display this properly?

Thanks !

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...