Troubleshoot the TISC add-on in Splunk
Enable debug logging on the add-on, view the resulting log entries in Splunk, and check input execution status from the Input Metadata Lookup KV store.
Before you begin
Role required: Splunk admin
The TISC add-on is installed and configured. See Configure TISC add-on in Splunk.
About this task
Use this procedure when an input is not pulling observables from TISC as expected, when records appear stale or missing in the KV store, or to inspect the execution history of a configured input.
Procedure
Result
You have collected the diagnostic information needed to identify why an input failed or returned unexpected results. Provide the relevant log entries and the input's metadata record when raising a support case or working with the add-on team.