All Apps and Add-ons

Input built via Splunk Add-on Builder not indexing data

anirbandasdeb
Path Finder

Hello Splunkers,

I am trying my hand at building modular inputs using the Splunk AoB, and following the walk-through examples provided for REST API at http://dev.splunk.com/view/addon-builder/SP-CAAAFCA . Followed the steps right down to each word to get a feel of the app..

I used the same set of API for NYTimes. The tests performed while building the input worked and provided output JSON.
The Interval is set for 30s.

I have created two inputs, indexing data to two separate indexes.
However, data is not indexed.

There is no activity logged by the two inputs in the _internal index as well.

I have restarted Splunk, but no result as well.

The AoB docs do not mention anything about indexing data via the created Add Ons

Can someone please help?

Note: I am running the created Add-On on the same instance as the AoB.. does taht make any difference?

0 Karma

chli_splunk
Splunk Employee
Splunk Employee

AoB test works but data input doesn't work? I guess sth wrong with your data input or environment, since there should be some logs in _internal at least, either from splunkd or addon.
Sorry I cannot triage it without more details, like the code, addon package, splunk diag, etc. You can try to contact a support, create a JIRA and upload your diag. Thanks.

RickbondPNT
Engager

Anirbandasdeb, what step did you miss. I also have the rest api getting data with Test, but nothing when i want to configure data or validate.

0 Karma

nkaplan_splunk
Splunk Employee
Splunk Employee

FYI, the updated location of the Splunk Add-on Builder documentation is https://docs.splunk.com/Documentation/AddonBuilder/3.0.1/UserGuide/UseTheApp

0 Karma

anirbandasdeb
Path Finder

It turns out that I did not follow everything right down to the word in the walkthrough. 😛

it is successfully indexing data now.

0 Karma

phepales
Loves-to-Learn Everything

Hello Splunkers,

I am trying my hand at building modular inputs using the Splunk AoB, and following the walk-through examples provided for REST API
The tests performed while building the input worked and provided output in XML.
The Interval is set for 300s.

I have created one inputs, indexing data to one index.
However, data is not indexed.

There is some activity logged by the input in the _internal index as well.

I have restarted Splunk, but no result as well.

I have set my props and transform conf for extraction.

The AoB docs do not mention anything about indexing data via the created Add Ons

Can someone please help?

Note: I am running the created Add-On on the same instance as the AoB.. does taht make any difference?

Thanks in Advance!!!

0 Karma
Get Updates on the Splunk Community!

What's new in Splunk Cloud Platform 9.1.2312?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.1.2312! Analysts can ...

What’s New in Splunk Security Essentials 3.8.0?

Splunk Security Essentials (SSE) is an app that can amplify the power of your existing Splunk Cloud Platform, ...

Let’s Get You Certified – Vegas-Style at .conf24

Are you ready to level up your Splunk game? Then, let’s get you certified live at .conf24 – our annual user ...