Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Dashboards are empty but data is being ingested into Splunk #62

Open
brodgers-df opened this issue Apr 5, 2023 · 0 comments
Open

Dashboards are empty but data is being ingested into Splunk #62

brodgers-df opened this issue Apr 5, 2023 · 0 comments

Comments

@brodgers-df
Copy link

Similar to issue #56 and #58

I'm getting a very similar issue as previous reported. I have configured the GitHub Add-on For Splunk to ingest audit and user events as well as configured webhooks to capture events to the github index in Splunk. I can manually search the data and it's coming in from GitHub, but the Repository Audit and User Change Audit dashboards have none of the expected data.

I have verified the macro are pointing to the correct indexes, everything looks good and as per documentation.

I have the following installed:
Splunk Enterprise 8.2.9
Apps:
Splunk Add-on for Github 2.1.1
GitHub App for Splunk 2.1.1
image
image
image
image
image

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant