All Apps and Add-ons

Cisco Networks App for Splunk Enterprise: Why am I getting error "No Search Query Provided" on all dashboards in Splunk 6.1.1?

pksarkar
New Member

All the Cisco Networks App for Splunk Enterprise dashboards are blank with the error "No Search Query Provided". The data from the syslog is present in the index and shows the sourcetype as cisco:ios. I can run manual searches and that displays the data in the index files. If I copy the search string from the XML source file and edit the dashboards, it picks the data from the index. Please provide a solution since I don't want to manually copy the search string for all the dashboards. I have tried deleting the apps from the server and reinstalling it. Splunk version is 6.1.1 and running on Windows server.

0 Karma

mikaelbje
Motivator

You will need Splunk 6.2+ or higher I believe due to new features in the search. Otherwise you may try an older version of the Cisco Networks App which uses the old functions to call searches from dashboards.

0 Karma
Get Updates on the Splunk Community!

More Ways To Control Your Costs With Archived Metrics | Register for Tech Talk

Tuesday, May 14, 2024  |  11AM PT / 2PM ET Register to Attend Join us for this Tech Talk and learn how to ...

.conf24 | Personalize your .conf experience with Learning Paths!

Personalize your .conf24 Experience Learning paths allow you to level up your skill sets and dive deeper ...

Threat Hunting Unlocked: How to Uplevel Your Threat Hunting With the PEAK Framework ...

WATCH NOWAs AI starts tackling low level alerts, it's more critical than ever to uplevel your threat hunting ...