Troubleshoot entity-index mappings
This document shares possible solutions to common errors in entity-index mappings.
| Error message | Likely cause | Troubleshooting action |
|---|---|---|
| No mappings are visible | The realm or organization flag is not active. |
Verify the flag status. Contact your Splunk representative if the status is not correct. |
|
Partial mappings only |
You have missing aliases or your concurrent jobs reached their limit. |
Add aliases and retry generating mappings again later. |
|
“*” values in entity name |
Pod or container entities are short-lived. |
This is expected wildcard behavior. |
|
Related content is missing for pods or containers |
Your logs are missing one or more Kubernetes chain fields. |
All Kubernetes fields must co-exist in an event. |
|
Related content is missing for APM services |
Your service names do not match. |
Check the consistency of your service names. |
|
Mapping is taking too long or is stuck at queued |
You've reached the concurrency limit. |
Retry later; Check the Skynet Job Manager. |
|
Logs are not loading or are timing out |
You have hit the usage quota or your queued jobs have overflowed. |
Clear jobs in Skynet Job Manager. |
|
The UI is in an unexpected empty state |
Your search or filter are too narrow. |
Suggest removing filters or adjusting time range. |