Troubleshoot the Splunk Add-on for Microsoft Hyper-V
General troubleshooting
For troubleshooting tips that you can apply to all add-ons, see Troubleshoot add-ons in Splunk Add-ons. For additional resources, see Support and resource links for add-ons in Splunk Add-ons.
Cannot launch add-on
This add-on does not have views and is not intended to be visible in Splunk Web. If you are trying to launch or load views for this add-on and you are experiencing results you do not expect, turn off visibility for the add-on.
For more details about add-on visibility and instructions for turning visibility off, see Check if the add-on is intended to be visible or not in the Splunk Add-ons Troubleshooting topic.
Data loss after Hyper-V server restart
When a Microsoft Hyper-V server fails or is restarted, you may encounter data loss if your forwarder collecting data from that machine is not restarted manually after the Hyper-V failure/restart. When your Microsoft Hyper-V server restarts, your forwarder automatically restarts with the Microsoft Hyper-V server. However, you may need to restart the forwarder manually again to prevent data loss.
<![CDATA[]]> embedded in extracted fields for Splunk 7.x
If you are seeing events whose fields are embedded with "CDATA" such as:
os="<![CDATA[]]>" description="<![CDATA[CentOS01]]>" mem="<![CDATA[2048]]>" ip="<![CDATA[]]>" cpu_count="<![CDATA[8]]>" ...
Upgrade the Splunk Add-on for Microsoft Hyper-V to version 3.1.0 and install on any Splunk 7.x deployments that you are using to run this add-on.
Configure inputs for the Splunk Add-on for Microsoft Hyper-V | Source types for the Splunk Add-on for Microsoft Hyper-V |
This documentation applies to the following versions of Splunk® Supported Add-ons: released
Feedback submitted, thanks!