Getting Data In

Cisco Networks App - no results found, open in search does show results

splunkuzleuven
Loves-to-Learn Lots

Hi,

I'm having an issue with some dashboard of the Cisco Network App.
Take for example the routing dashboard. There is a top neihbors panel. When I open the dashboard, it does the search and returns "No results found".
However when I do I job inspection, I see it does find results:

This search has completed and has
returned 2,520 results by scanning
3,930 events in 2.133 seconds

When opening the job in search, I also see all the data. The query seems to work, but not in the dashboard panel...

I've checked the roles and made sure all roles that can have access, have a default search on all internal indexes. This is needed because the search itself uses index*.

The search it executes:

eventtype=cisco_ios-routing index IN (*)
| eval routing_protocol = case(eventtype == "cisco_ios-routing-ospf", "OSPF", eventtype == "cisco_ios-routing-dual", "EIGRP", eventtype ==> "cisco_ios-routing-bgp", "BGP", eventtype == "cisco_ios-routing-ldp","LDP", eventtype =="cisco_ios-routing-isis", "ISIS", eventtype == "cisco_ios-routing-rsvp", "RSVP", eventtype =="cisco_ios-routing-pim", "PIM")
| search (routing_protocol="BGP" OR routing_protocol="OSPF")
| lookup dnslookup clientip as src_ip | top clienthost

I do get data back, so it seems all datamodels are correct.

I'm really at a loss why it would return "no results" when inspecting or running the search does return results :s

Setup: index and search cluster, everything running on version 8.0.0. App is the latest version.

0 Karma

splunkuzleuven
Loves-to-Learn Lots

Yes, I did make some changes, but besides that part, even before making the changes, it shows no results. I'm wondering if it's a kind of permission issue, but I wouldn't know where to start looking... Other dashboards are having the same issue.
The inspection does show it is giving me the results, but the panel is not showing it.
I guess I can try to delete the panel and replace it and see what it gives I guess.

It's a clean install of the app on the entire installation. So no Splunk nor app upgrades have been done so far. So I'm not entirely clear what you mean with client side in this case. The browser? Multiple users have this, even the local admin user.

0 Karma

mbjerkeland_spl
Splunk Employee
Splunk Employee

Hi,

I'm the author of the App. Not sure why you are having issues with the dashboards, but this part indicates you have made local customizations to the App: | lookup dnslookup clientip as src_ip | top clienthostas the original app does not have this query.

You may also try to clear any client side caches if you recently upgraded to Splunk 8.

0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...

What's new in Splunk Cloud Platform 9.1.2312?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.1.2312! Analysts can ...

What’s New in Splunk Security Essentials 3.8.0?

Splunk Security Essentials (SSE) is an app that can amplify the power of your existing Splunk Cloud Platform, ...