The status of an entity is not updating
When an entity stops sending data, the status of the entity changes to Inactive
. If the entity starts sending data after an extended period of time of not sending data, the status may not automatically change to Active
.
To force an update of the status for an entity, delete the entity from the Splunk App for Infrastructure (SAI). After you delete the entity, it reappears in SAI as long as the data collection agents on the host machine are sending data to SAI. If deleting the entity does not update its status when SAI rediscovers it, restart the Splunk Enterprise instance that is running SAI. When you restart the instance, the app refreshes the status of every entity.
Delete the host from SAI
Delete the host from SAI so the app rediscovers the host machine that is sending data to SAI.
Prerequisites
- Permission to delete an entity from SAI. For more information, see Admin and user roles in Splunk App for Infrastructure.
Steps
Follow these steps to manually delete an entity from SAI.
- Log in to Splunk Web.
- Go to SAI.
- Select the Investigate tab.
- Select each entity that is displaying an inaccurate Status.
- In the Actions column, select Delete. If you selected multiple entities, click the Bulk actions drop-down menu and select Delete Selected Entities.
Restart Splunk Enterprise
Restart the Splunk Enterprise instance that is running SAI. This forces an update for every entity that is sending data to SAI.
Prerequisites
- Administrator access to the system that is running SAI.
Steps
Follow these steps to restart the Splunk Enterprise instance that is running SAI. For more information about stopping, starting, and restarting Splunk software, including restarting an instance in Splunk Web, see Start and stop Splunk Enterprise in the Splunk Enterprise Admin Manual.
- On the system that is running SAI, open a command line terminal.
- Go to the
$SPLUNK_HOME/bin
directory. - Restart the Splunk Enterprise instance:
$ ./splunk restart
Collectd DF Plugin not generating output on Linux with XFS file system | SAI version 1.3.x is not compatible with the Splunk Add-on for Windows |
This documentation applies to the following versions of Splunk® App for Infrastructure (Legacy): 1.3.1, 1.4.0, 1.4.1, 2.0.0, 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.1.0, 2.1.1 Cloud only, 2.2.0 Cloud only, 2.2.1, 2.2.3 Cloud only, 2.2.4, 2.2.5
Feedback submitted, thanks!