Skip to content

Commit 37d3954

Browse files
committed
New macros:
- `sysloghosts` New reports: - `SearchHeadLevel - Knowledge Bundle contents` - `syslog-ng - cache statistics summary` - as contributed by Marc Andersen, company: NIL815 ApS Updated dashboards: - `splunk_forwarder_output_tuning` - added fillnull for `ingest_pipe` Updated alerts: - `AllSplunkLevel - No recent metrics.log data` - updated to use prestats - `AllSplunkLevel - TCP Output Processor has paused the data flow` - updated criteria - `AllSplunkEnterpriseLevel - ulimit on Splunk enterprise servers is below 8192` - now 64,000 (could be renamed in future) - `AllSplunkEnterpriseLevel - Splunkd Log Messages Admins Only` - updated criteria - `ForwarderLevel - Splunk universal forwarders with ulimit issues` - updated keywords - `SearchHeadLevel - Scheduled Searches That Cannot Run` - excluded the require command - `SearchHeadLevel - Detect MongoDB errors` - updated to use prestats, added `_time` field - `SearchHeadLevel - SHC Captain unable to establish common bundle` - added new criteria - `SearchHeadLevel - Search Messages user level` - updated criteria
1 parent 50ea44b commit 37d3954

File tree

5 files changed

+103
-20
lines changed

5 files changed

+103
-20
lines changed

README.md

Lines changed: 24 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -256,6 +256,7 @@ The below list of alerts and reports are actively used since version 8.0.x and i
256256
- `SearchHeadLevel - Splunk alert actions exceeding the max_action_results limit`
257257
- `SearchHeadLevel - Splunk Scheduler logs have not appeared in the last`
258258
- `SearchHeadLevel - Users exceeding the disk quota`
259+
- `syslog-ng - cache statistics summary`
259260

260261
## KVStore Usage
261262
Some CSV lookups are now replaced with kvstore entries due to the ability to sync the kvstore across multiple search head or search head cluster(s) via apps like [KV Store Tools Redux](https://splunkbase.splunk.com/app/5328/)
@@ -308,9 +309,31 @@ The following ideas relate to this issue:
308309
Feel free to open an issue on github or use the contact author on the SplunkBase link and I will try to get back to you when possible, thanks!
309310

310311
## Release Notes
312+
### 3.0.7
313+
New macros:
314+
- `sysloghosts`
315+
316+
New reports:
317+
- `SearchHeadLevel - Knowledge Bundle contents`
318+
- `syslog-ng - cache statistics summary` - as contributed by Marc Andersen, company: NIL815 ApS
319+
320+
Updated dashboards:
321+
- `splunk_forwarder_output_tuning` - added fillnull for `ingest_pipe`
322+
323+
Updated alerts:
324+
- `AllSplunkLevel - No recent metrics.log data` - updated to use prestats
325+
- `AllSplunkLevel - TCP Output Processor has paused the data flow` - updated criteria
326+
- `AllSplunkEnterpriseLevel - ulimit on Splunk enterprise servers is below 8192` - now 64,000 (could be renamed in future)
327+
- `AllSplunkEnterpriseLevel - Splunkd Log Messages Admins Only` - updated criteria
328+
- `ForwarderLevel - Splunk universal forwarders with ulimit issues` - updated keywords
329+
- `SearchHeadLevel - Scheduled Searches That Cannot Run` - excluded the require command
330+
- `SearchHeadLevel - Detect MongoDB errors` - updated to use prestats, added `_time` field
331+
- `SearchHeadLevel - SHC Captain unable to establish common bundle` - added new criteria
332+
- `SearchHeadLevel - Search Messages user level` - updated criteria
333+
311334
### 3.0.6
312335
Updated dashboards:
313-
- `Splunk forwarder output tuning` - added fillnull ingest_pipe
336+
- `Splunk forwarder output tuning` - added fillnull `ingest_pipe`
314337

315338
Updated reports/alerts:
316339
- `SearchHeadLevel - Dashboards using special characters` - updated to use spath command instead of rex

default/app.conf

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -12,7 +12,7 @@ label = SplunkAdmins
1212
[launcher]
1313
author = Gareth Anderson
1414
description = Alerts and dashboards as described in the Splunk 2017 conf presentation How did you get so big?
15-
version = 3.0.6
15+
version = 3.0.7
1616

1717
[package]
1818
id = SplunkAdmins

default/data/ui/nav/default.xml

Lines changed: 9 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -143,6 +143,9 @@
143143
<view name="splunk_introspection_io_stats" />
144144
<a href="/app/SplunkAdmins/alert?s=%2FservicesNS%2Fnobody%2FSplunkAdmins%2Fsaved%2Fsearches%2FForwarderLevel%20-%20Channel%20churn%20issues">Channel churn issues</a>
145145
</collection>
146+
<collection label="syslog-ng">
147+
<saved name="syslog-ng - cache statistics summary" />
148+
</collection>
146149
</collection>
147150
<collection label="IndexerLevel">
148151
<collection label="Bucket Related">
@@ -329,6 +332,7 @@
329332
<a href="/app/SplunkAdmins/alert?s=%2FservicesNS%2Fnobody%2FSplunkAdmins%2Fsaved%2Fsearches%2FSearchHeadLevel%20-%20Search%20Messages%20user%20level">Search Messages user level</a>
330333
<a href="/app/SplunkAdmins/alert?s=%2FservicesNS%2Fnobody%2FSplunkAdmins%2Fsaved%2Fsearches%2FSearchHeadLevel%20-%20Search%20Messages%20admins%20only">Search Messages admins only</a>
331334
</collection>
335+
<saved name="SearchHeadLevel - Knowledge Bundle contents" />
332336
</collection>
333337
<collection label="Non best-practice">
334338
<collection label="Realtime searches">
@@ -363,6 +367,7 @@
363367
<saved name="SearchHeadLevel - audit logs showing all time searches" />
364368
<saved name="IndexerLevel - RemoteSearches find all time searches" />
365369
<a href="/app/SplunkAdmins/alert?s=%2FservicesNS%2Fnobody%2FSplunkAdmins%2Fsaved%2Fsearches%2FSearchHeadLevel%20-%20Excessive%20REST%20API%20usage">SearchHeadLevel - Excessive REST API usage</a>
370+
<saved name="SearchHeadLevel - Knowledge Bundle contents" />
366371
</collection>
367372
</collection>
368373
<collection label="Performance Issues">
@@ -378,14 +383,15 @@
378383
<a href="/app/SplunkAdmins/alert?s=%2FservicesNS%2Fnobody%2FSplunkAdmins%2Fsaved%2Fsearches%2FIndexerLevel%20-%20Slow%20peer%20from%20remote%20searches">Slow peer from remote searches</a>
379384
<saved name="SearchHeadLevel - Search Messages field extractor slow" />
380385
<a href="/app/SplunkAdmins/alert?s=%2FservicesNS%2Fnobody%2FSplunkAdmins%2Fsaved%2Fsearches%2FSearchHeadLevel%20-%20Excessive%20REST%20API%20usage">SearchHeadLevel - Excessive REST API usage</a>
381-
<saved name="SearchHeadLevel - Knowledge bundle replication times metrics.log" />
386+
<saved name="SearchHeadLevel - Knowledge bundle replication times metrics.log" />
382387
</collection>
383388
<collection label="Proactive">
384389
<a href="/app/SplunkAdmins/alert?s=%2FservicesNS%2Fnobody%2FSplunkAdmins%2Fsaved%2Fsearches%2FSearchHeadLevel%20-%20LDAP%20users%20have%20been%20disabled%20or%20left%20the%20company%20cleanup%20required">LDAP users have been disabled or left the company cleanup required</a>
385390
<a href="/app/SplunkAdmins/alert?s=%2FservicesNS%2Fnobody%2FSplunkAdmins%2Fsaved%2Fsearches%2FSearchHeadLevel%20-%20Saved%20Searches%20with%20privileged%20owners%20and%20excessive%20write%20perms">Saved Searches with privileged owners and excessive write perms</a>
386391
<a href="/app/SplunkAdmins/alert?s=%2FservicesNS%2Fnobody%2FSplunkAdmins%2Fsaved%2Fsearches%2FSearchHeadLevel%20-%20Scheduled%20Searches%20Configured%20with%20incorrect%20sharing">Scheduled Searches Configured with incorrect sharing</a>
387392
<a href="/app/SplunkAdmins/alert?s=%2FservicesNS%2Fnobody%2FSplunkAdmins%2Fsaved%2Fsearches%2FSearchHeadLevel%20-%20Splunk%20login%20attempts%20from%20users%20that%20do%20not%20have%20any%20LDAP%20roles">Splunk login attempts from users that do not have any LDAP roles</a>
388393
<a href="/app/SplunkAdmins/alert?s=%2FservicesNS%2Fnobody%2FSplunkAdmins%2Fsaved%2Fsearches%2FSearchHeadLevel%20-%20authorize.conf%20settings%20will%20prevent%20some%20users%20from%20appearing%20in%20the%20UI">SearchHeadLevel - authorize.conf settings will prevent some users from appearing in the UI</a>
394+
<saved name="SearchHeadLevel - Knowledge Bundle contents" />
389395
</collection>
390396
<collection label="Quotas">
391397
<a href="/app/SplunkAdmins/alert?s=%2FservicesNS%2Fnobody%2FSplunkAdmins%2Fsaved%2Fsearches%2FSearchHeadLevel%20-%20Splunk%20Max%20Historic%20Search%20Limits%20Reached">Splunk Max Historic Search Limits Reached</a>
@@ -432,6 +438,8 @@
432438
<view name="lookup_audit" />
433439
<saved name="SearchHeadLevel - Knowledge bundle status on indexers" />
434440
<saved name="SearchHeadLevel - Knowledge bundle replication times metrics.log" />
441+
<saved name="SearchHeadLevel - Knowledge Bundle contents" />
442+
<saved name="syslog-ng - cache statistics summary" />
435443
</collection>
436444
<collection label="Summary_Reports">
437445
<saved name="SearchHeadLevel - platform_stats.audit metrics searches" />

default/macros.conf

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -38,6 +38,10 @@ iseval = 0
3838
definition = host=*
3939
iseval = 0
4040

41+
[sysloghosts]
42+
definition = host=*
43+
iseval = 0
44+
4145
[searchheadsplunkservers]
4246
definition = splunk_server=*
4347
iseval = 0

0 commit comments

Comments
 (0)