All Apps and Add-ons

Dashboards not working or have random gaps in information

mwarvi
Explorer

Since the upgrade to 6.0, including 6.0.1, the dashboards are more often not working than working for me.

In particular, the All Incidents dashboard seems to randomly stop being populated with data. For example, yesterday there's no information between 12pm and 6pm, and then today from 2am to 6am. I can confirm that there are incident type logs coming in the entire time, and that they are being parsed correctly. Data models are 100% and accelerated. During these gaps, the User Behavior dashboard also doesn't work.

As for other issues, the File Activity dashboard is always on "Waiting for data...", Endpoint and Firewall config is no results found, web activity is only loading Top Referrers and Methods over Time.

GlobalProtect, Firewall System and Real-Time seem to be working without an issue.

As stated before, the events are being tagged and parsed into the different event types fine. I'm just not sure where else to look.

0 Karma

darrenbisbey
New Member

i'm using 7.0 not 62

D.

0 Karma

nikita_p
Contributor

Hi @mwarvi,
Can you check below answer in splunk if it helps you?
https://answers.splunk.com/answers/186429/splunk-62-upgrade-issue-users-can-no-longer-create.html

0 Karma

DalJeanis
Legend

Okay, one possibility is that your underlying searches are not being run, either because they are not set up correctly, or because they are taking too long and the next one gets skipped. Try something like this to test that...

 index=_internal source=*metrics.log group=searchscheduler 
| timechart partial=false span=10m sum(dispatched) sum(skipped)   
0 Karma

darrenbisbey
New Member

GlobalProtect, Firewall System and Real-Time are working but as the above poster said. But all other dashboards not.

This was a fresh install.

Darren

0 Karma
Get Updates on the Splunk Community!

Threat Hunting Unlocked: How to Uplevel Your Threat Hunting With the PEAK Framework ...

WATCH NOWAs AI starts tackling low level alerts, it's more critical than ever to uplevel your threat hunting ...

Splunk APM: New Product Features + Community Office Hours Recap!

Howdy Splunk Community! Over the past few months, we’ve had a lot going on in the world of Splunk Application ...

Index This | Forward, I’m heavy; backward, I’m not. What am I?

April 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...