All Apps and Add-ons

Jenkens Splunk app is blank (but events are indexed)

ninja_ops
New Member

I followed the jenkens config steps recommended here:
https://wiki.jenkins.io/display/JENKINS/Splunk+Plugin+for+Jenkins

Events show up If I search
index=jenkens*

But jenkens app in splunk shows "No results found"

Splunk version: 7.1
Jenkens App version: 1.0.7

0 Karma

doriandaumiller
New Member

The Splunk App for Jenkins uses 3 default indexes called jenkins_statistics, jenkins_slaves and jenkins_console IIRC.
You should see them in your list of indexes.
Make sure your collector has permissions to push there (or find out how to tell the Splunk App from which indexes to read)

0 Karma

mstjohn_splunk
Splunk Employee
Splunk Employee

hi @ninja_ops,

Did the answer below solve your problem? If so, please resolve this post by approving it!

If your problem is still not solved, keep us updated so that someone else can help ya.

Thanks for posting!

0 Karma

adonio
Ultra Champion

in many cases, apps with visualizations relay only on sourcetypes as filters.
try to open one of the panels in search by clicking the magnifying glass icon on the bottom right corner.
inspect the search and see if it indicates an index.
if it does, maybe its not the location where the data resides. if it doesnt, it probably means you role does not search the jenkens index by default.
you can fix it by setting it under your role.
click settings (top right corner) -> Access Controls -> Roles -> pick your role -> scroll down all the way (one before last item) -> observe the "indexes searched by default" settings -> add the relevant index name by clicking it -> click save -> click dashboard and see if its populate.

hope it helps

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...