All Apps and Add-ons

Dashboard showing Zeroes

MageSlayer
New Member

The initial installation goes through without a problem and the dashboard items appear, however none of the data being sent to the Splunk server(we confirmed the data is coming in) is being displayed on the Dashboard. A lot of the searches seem to reference a src_ip field, and I see where this transformation is supposed to happen, but when searching for src_ip, it returns nothing.

Is there a step missing to connect this missing src_ip field? I believe this is the cause of the dashboards being empty.

Tags (1)
0 Karma

MageSlayer
New Member

It seems a reboot of the FireEye box suddenly made it start working.

0 Karma

MageSlayer
New Member

It's for the FireEye app(sorry I thought that was noticed with the tag there)

0 Karma

rsennett_splunk
Splunk Employee
Splunk Employee

Can you specify what Dashboard you're talking about? Is it from an app you downloaded or something you built?

If src_ip is referenced in the searches it might be a field created in props.conf

can you post that here?

If you like, post the props.conf, the trasnforms.conf and one of the searches.

With Splunk... the answer is always "YES!". It just might require more regex than you're prepared for!
0 Karma
Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...