I have issues with my Splunk integration
This page provides information on what to do if you are experiencing issues with your Splunk integration.
Problems with Scaleway Add-on for Splunk
General troubleshooting
For general guidance and support applicable across all add-ons, see Troubleshoot add-ons in the Splunk Add-ons documentation.
To analyze the complete log trace produced by the Scaleway Add-on, you can change the logging level to DEBUG.
- On your Splunk platform instance, go to the Splunk Web homepage, then select Scaleway Add-on in the navigation.
- Once in the Scaleway Add-on, go to Configuration tab > Logging tab.
- Change the log level to DEBUG.
- Click Save.
In your Search Head instance(s), you can run the following search to investigate errors:
index=\_internal source="/opt/splunk/var/log/splunk/ta-scaleway_*" log_level=ERRORAuthentication failures
If you experience authentication failures, verify the following:
- The API key is valid and has not expired.
- The Organization ID is correct.
- The API key has Audit Trail read permissions.
No data ingestion
If no data is being ingested, check the following:
- The Audit Trail permission is linked to the API key provided.
- The input configuration is complete and activated.
- Sufficient index quota in Splunk is available.
Slow performance
If you experience slow performance, try the following:
- Reduce polling frequency or narrow time ranges.
- Filter audit events by product.
Problems with Scaleway App for Splunk
Dashboards show no data
If dashboards display no data, verify the following:
- The Scaleway Add-On is collecting data successfully.
- The
sourcetypeis configured correctly. - Data is being indexed.
- The time range picker is set so it includes recent events (adjust the time range if necessary).
Missing visualizations
If visualizations are missing, check the following:
- All required fields are being extracted.
- CIM compatibility is configured.
- The Splunk version meets minimum requirements.
Slow dashboard loading
If dashboards load slowly, try the following:
- Reduce the default time range.
- Optimize search queries with
indexandsourcetypefilters. - Consider using summary indexing for large datasets.
Still need help?Create a support ticket