In DX NetOps Portal, syslog reports function correctly when set to a 24-hour timeframe. However, when the same report is set to a 7-day timeframe for devices with large syslog message sets, the report returns a "no data available" message even though data exists in Splunk.
Symptoms:
This issue is potentially caused by a product defect in the data retrieval path between DX NetOps Portal and Splunk when handling large datasets over extended timeframes.
Insufficient data exists in releases 25.4.9 and earlier to determine the case. DE203725 was opened with engineering to add debug features allowing for new messages to expose the cause. These were added to 25.4.10+ releases.
If this problem is being observed upgrade to 25.4.10 to validate the issue remains. If it remains open a new case with support for assistance. We'll gather debug to determine the root cause.
Enhanced debug logging for the Splunk data path has been added to version 25.4.10 to facilitate further analysis. Users experiencing this issue should upgrade to 25.4.10 to enable this logging and assist in the final verification of the fix.
If you have seen this issue, and continue to see if post upgrade to 25.4.10+ releases, open a support case referencing this article for further assistance.
To stay updated on the status of this fix, please .
For software downloads, see: .
If you require immediate assistance before the fix is validated, please contact