Splunk® Metrics Workspace

Using the Splunk Metrics Workspace

Download manual as PDF

This documentation does not apply to the most recent version of SMW. Click here for the latest version.
Download topic as PDF

Troubleshoot the Splunk Metrics Workspace

You might encounter the following issues while using the Splunk Metrics Workspace.

Error message on app setup page

After downloading and installing the Splunk Metrics Workspace, you cannot open the application. You see a message prompting you to upgrade Splunk Enterprise.


You are running an unsupported version of Splunk Enterprise. The Splunk Metrics Workspace requires Splunk Enterprise version 7.1 or later.


Upgrade to a supported version of Splunk Enterprise. For more information, see How to upgrade Splunk Enterprise in the Installation Manual.

Metrics do not appear in the Data panel

No metrics data sources appear in the Data panel.


The following issues can cause metrics to not appear in the Data panel:

  • No metrics with timestamps in the past 24 hours are available.
  • The technical add-ons and agents you use to send and ingest metrics malfunctioned.


  1. Verify that Splunk Web ingested no metrics with timestamps in the past 24 hours.
  2. (Optional) Expand the time range for ingested metrics by modifying the earliest parameter in the metadata stanza located in the app's workspace.conf file. Expanding the time range for ingested metrics might have a negative impact on performance.
  3. Run the following search in the Search & Reporting app to verify that Splunk software is properly fetching metrics data:

    | mcatalog values(metric_name) as metrics WHERE NOT ("_dims"="rollup_aggregate" OR "_dims"="rollup_span" OR "_dims"="rollup_source_index") AND ("index"="*" OR "index"="_*" ) earliest=-1d BY index | mvexpand metrics limit=20000

    The search results match the list of metric names in the Metrics Workspace Data panel.
  4. Investigate whether the technical add-ons and agents you use to ingest metrics are functioning properly.

Data panel does not contain datasets

No datasets are listed in the Data panel.


Datasets are not accelerated.


  1. Verify that the dataset is shared with you.
  2. Click the Datasets tab on the Splunk Enterprise Search & Reporting navigation bar.
  3. Check whether the dataset is accelerated. Accelerated datasets are designated by the lightning bolt (This screen image shows the accelerated dataset icon.) icon.

For more information, see Accelerate data models in the Knowledge Manager Manual.

Chart does not contain data

You are able to select a data source, but no data appears on the chart.


The following conditions are possible causes of this issue:

  • There is no data within your selected time range.
  • There is no data using your selected filters.
  • You do not have access to the underlying index for the data.


  1. Expand the time range to view a wider range of data.
  2. In the Analysis Panel of the Metrics Workspace, adjust the filters to include a wider range of values.
  3. Contact your administrator to verify your permissions.

For more information about Metrics Workspace permissions and capabilities, see Hardware and software requirements for the Splunk Metrics Workspace.

Hardware and software requirements for the Splunk Metrics Workspace
Share data in the Splunk Metrics Workspace

This documentation applies to the following versions of Splunk® Metrics Workspace: 1.1.6, 1.1.7

Was this documentation topic helpful?

Enter your email address, and someone from the documentation team will respond to you:

Please provide your comments here. Ask a question or make a suggestion.

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters