Content Pack for Cisco ThousandEyes

Content Pack for Cisco ThousandEyes

Data isn't populating in the default service analyzer

Problem

Data isn't populating in the default service analyzer.

Cause

This issue could be caused by any of the following reasons:

  • The content pack search macro definition doesn't point to the index used by the Cisco ThousandEyes App for Splunk. By default, the content pack macro definition is set to index="thousandeyes". If you used a different index when you configured the Cisco ThousandEyes App for Splunk, data will not populate in the service analyzer.
  • Data isn't being collected by the Cisco ThousandEyes App for Splunk index.
  • Services aren't enabled. By default, services are disabled when you install the content pack.

Solutions

Update the content pack search macro definition to point to the correct index

See Ensure the content pack uses the correct index.

Ensure that data is being collected by the Cisco ThousandEyes App for Splunk index

  1. From the IT Service Intelligence (ITSI) main menu, select Search.
  2. In the New Search field, enter search index="<thousandeyes-index>".
    1. Replace <thousandeyes-index> with the name of the index you created when you set up the Cisco ThousandEyes App for Splunk. To identify the name of this index, see Ensure the content pack uses the correct index.
  3. Use the results to confirm if data is being collected by the Cisco ThousandEyes App for Splunk. If no data is being collected, see Troubleshooting in the Cisco ThousandEyes documentation.

Enable services

  1. From the ITSI main menu, select Configuration, then Service Monitoring.
  2. Select Service and KPI Management.
  3. In the Filter field, enter Cisco ThousandEyes.
  4. Use the Status column to check if your services are enabled.
  5. To enable services, use one of the following methods:
    1. To enable individual services, select the toggle in the Status column to switch the status to Enabled.
    2. To bulk enable multiple services, check the boxes for the services you want to enable. Select Bulk Action, then Enable.
Last modified on 25 February, 2025
Use data links to navigate to Cisco ThousandEyes tests   Data isn't populating in the entity dashboards

This documentation applies to the following versions of Content Pack for Cisco ThousandEyes: 1.0.0


Please expect delayed responses to documentation feedback while the team migrates content to a new system. We value your input and thank you for your patience as we work to provide you with an improved content experience!

Was this topic useful?







You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters