All Apps and Add-ons

dashboards not populating

Esky73
Builder

Playing around with meh-trics for the first time - i have configured a single host with collectd (CentOS7)

  • i can see the metrics in the collectd index
  • i can browse using metric explorer and metric navigator.

but all the other dashboards, Overview, cpu etc do not populate.

Looking at the troubleshooting section on splunkbase :

  • | mcatalog values(metric_name) provides no results.
  • | mstats min(_value) AS Min avg(_value) AS Avg max(_value) as "Max" WHERE metric_name=disk.disk_io_time.io_time index="*" by host - does tho
  • the host multiselect dropdown has the following search : | mcatalog values(host) AS host | mvexpand host which also doesn't provide any output.

Any ideas whats going on here ?

thanks.

0 Karma
1 Solution

lukeh
Contributor

lukeh
Contributor

Add the collectd index to "Indexes searched by default" :-
https://docs.splunk.com/Documentation/Splunk/latest/Search/Searchindexes#Control_index_access_using_...

Hope this helps 🙂

Esky73
Builder

Damn .. RTFM fail .. thankyou.

0 Karma

teknofile
New Member

I have a similar issue - I have added the indexes search by default already. I can see some data (memory, packet throughput, disk) but I do not see any CPU data populated in the graphs. Using the metrics navigator I can drill down though. Not sure where I should start in troubleshooting the dash board.

I tried to copy the query some of the graphs used in the Search & Reporting window, but it gave me a "Error in 'mstats' command: Unsupported aggregation type: $statsfunc$" so I dont think I can do it that way.

0 Karma

lukeh
Contributor

you're welcome 🙂

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...