Having a bit of an issue getting the Splunk App for Web Analytics setup completed. Here's some details:
Installed Splunk App for Web Analytics v1.31 on Search Head (v6.2)
The 'Available host and source combinations' panel appears to be working properly. I.E. I see the host(s) and sources I care about listed.
The 'Setup new website' panel appears to be working properly. I.E. After adding a site it is listed in the 'Configured websites' panel and is added to the WA_settings.csv file. Here's an example of the wildcards I'm using:
key,value,source,host
site,"mysite.mydomain.com","H:\inetpub\logs\LogFiles\my-site\W3SVC**","mynode-01"
I have verified the Role being used to set up the app (Admin) has the proper index listed for both 'indexes searched by default' and 'indexes'. In fact I've simply added 'All non-internal indexes' to both.
The following manual searches all return results:
tag="web"
sourcetype="iis"
source="H:\inetpub\logs\LogFiles\my-site\W3SVC*\"
| tstats prestats=t count where index= by host,source | stats count AS events by host, source | search host=""* OR source=""*
It seems like everything is in place, but when I go to build the lookups nothing is returned. Any help to narrow down my configuration oversight would be much appreciated.
... View more