Troubleshoot entity-index mappings

This document shares possible solutions to common errors in entity-index mappings.

The table below lists error messages you might see when setting up or using entity-index mappings. You can see error messages, their meanings, likely causes of the errors, and the actions you can take to resolve the problems.
Error messageLikely causeTroubleshooting action
No mappings are visibleThe realm or organization flag is not active.

Verify the flag status. Contact your Splunk representative if the status is not correct.

Partial mappings only

You have missing aliases or your concurrent jobs reached their limit.

Add aliases and retry generating mappings again later.

“*” values in entity name

Pod or container entities are short-lived.

This is expected wildcard behavior.

Related content is missing for pods or containers

Your logs are missing one or more Kubernetes chain fields.

All Kubernetes fields must co-exist in an event.

Related content is missing for APM services

Your service names do not match.

Check the consistency of your service names.

Mapping is taking too long or is stuck at queued

You've reached the concurrency limit.

Retry later; Check the Skynet Job Manager.

Logs are not loading or are timing out

You have hit the usage quota or your queued jobs have overflowed.

Clear jobs in Skynet Job Manager.

The UI is in an unexpected empty state

Your search or filter are too narrow.

Suggest removing filters or adjusting time range.