Quantcast
Channel: Questions in topic: "upgrade"
Viewing all articles
Browse latest Browse all 457

After upgrading the Cisco Networks App and Add-on for Splunk Enterprise to 2.3.0, why are panels showing "No results found" or lookup errors?

$
0
0
Hello; I've recently upgraded Cisco Networks App for Splunk Enterprise to cisco_ios 2.3.0, shortly followed by an upgrade to the TA on my Universal Forwarder and Indexers to TA-cisco_ios 2.3.0. My UF has its inputs.conf configured as: [monitor:///syslog-data/ios.log] sourcetype=syslog BTW, I've also tried setting this to "sourcetype=cisco:ios". Where before I was receiving data inside of the app, now I am seeing "**No results found.**" for each panel, except for "**Diagnostic messages**", where I am now seeing **'Error in '*lookup' command: The lookup table 'cisco_ios_severity' does not exist.***'. I've gone through the install setup for the add-on again, and am not able to determine why I am not seeing data. I've confirmed that my syslog file is from valid IOS devices. By the way, all of my devices are currently writing to the same file, and have always done so. Any suggestions? -mi

Viewing all articles
Browse latest Browse all 457

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>