All Apps and Add-ons

Splunk App for Infrastructure

pietertruter1
Observer

I have installed V2.02 of the app and configured manual performance metrics inputs to Windows hosts with UF already installed. Problem is that the Overview dashboard panels are not working. | inputlookup em_entities is returning results for my hosts, but I notice that the metric_name fields are all small caps and the dashboard searches are looking for metric_names that is not all small caps: avg(Processor.%_Privileged_Time). If I change the metric names in the search to all small caps the searches run without issues.
If I read the metrics index documentation it states that you can only use small caps in the metric names.

Am I missing something when creating the manual inputs? Field alias also does not seem to be working either and I also cant find where to edit the dashboards to change the metric names.

Any suggestions welcome? Short from recreating all the dashboards to my own Im out of ideas.

Thanks
Pieter

0 Karma

pietertruter1
Observer

So we are on 7.3.3 on the Search head, but our indexers are still on 7.1.* which we are planning to upgrade soon.

Thanks for the quick answer. Will test again after our indexers are upgraded as well.

0 Karma

dagarwal_splunk
Splunk Employee
Splunk Employee

Yeah.. your indexers are the problem.. It needs to be 7.2 or higher.

0 Karma

dagarwal_splunk
Splunk Employee
Splunk Employee

Are you using Splunk version 7.1.* for your SAI? If yes, please upgrade version to 7.2 or higher..

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...