|
143 | 143 | <view name="splunk_introspection_io_stats" /> |
144 | 144 | <a href="/app/SplunkAdmins/alert?s=%2FservicesNS%2Fnobody%2FSplunkAdmins%2Fsaved%2Fsearches%2FForwarderLevel%20-%20Channel%20churn%20issues">Channel churn issues</a> |
145 | 145 | </collection> |
| 146 | + <collection label="syslog-ng"> |
| 147 | + <saved name="syslog-ng - cache statistics summary" /> |
| 148 | + </collection> |
146 | 149 | </collection> |
147 | 150 | <collection label="IndexerLevel"> |
148 | 151 | <collection label="Bucket Related"> |
|
329 | 332 | <a href="/app/SplunkAdmins/alert?s=%2FservicesNS%2Fnobody%2FSplunkAdmins%2Fsaved%2Fsearches%2FSearchHeadLevel%20-%20Search%20Messages%20user%20level">Search Messages user level</a> |
330 | 333 | <a href="/app/SplunkAdmins/alert?s=%2FservicesNS%2Fnobody%2FSplunkAdmins%2Fsaved%2Fsearches%2FSearchHeadLevel%20-%20Search%20Messages%20admins%20only">Search Messages admins only</a> |
331 | 334 | </collection> |
| 335 | + <saved name="SearchHeadLevel - Knowledge Bundle contents" /> |
332 | 336 | </collection> |
333 | 337 | <collection label="Non best-practice"> |
334 | 338 | <collection label="Realtime searches"> |
|
363 | 367 | <saved name="SearchHeadLevel - audit logs showing all time searches" /> |
364 | 368 | <saved name="IndexerLevel - RemoteSearches find all time searches" /> |
365 | 369 | <a href="/app/SplunkAdmins/alert?s=%2FservicesNS%2Fnobody%2FSplunkAdmins%2Fsaved%2Fsearches%2FSearchHeadLevel%20-%20Excessive%20REST%20API%20usage">SearchHeadLevel - Excessive REST API usage</a> |
| 370 | + <saved name="SearchHeadLevel - Knowledge Bundle contents" /> |
366 | 371 | </collection> |
367 | 372 | </collection> |
368 | 373 | <collection label="Performance Issues"> |
|
378 | 383 | <a href="/app/SplunkAdmins/alert?s=%2FservicesNS%2Fnobody%2FSplunkAdmins%2Fsaved%2Fsearches%2FIndexerLevel%20-%20Slow%20peer%20from%20remote%20searches">Slow peer from remote searches</a> |
379 | 384 | <saved name="SearchHeadLevel - Search Messages field extractor slow" /> |
380 | 385 | <a href="/app/SplunkAdmins/alert?s=%2FservicesNS%2Fnobody%2FSplunkAdmins%2Fsaved%2Fsearches%2FSearchHeadLevel%20-%20Excessive%20REST%20API%20usage">SearchHeadLevel - Excessive REST API usage</a> |
381 | | - <saved name="SearchHeadLevel - Knowledge bundle replication times metrics.log" /> |
| 386 | + <saved name="SearchHeadLevel - Knowledge bundle replication times metrics.log" /> |
382 | 387 | </collection> |
383 | 388 | <collection label="Proactive"> |
384 | 389 | <a href="/app/SplunkAdmins/alert?s=%2FservicesNS%2Fnobody%2FSplunkAdmins%2Fsaved%2Fsearches%2FSearchHeadLevel%20-%20LDAP%20users%20have%20been%20disabled%20or%20left%20the%20company%20cleanup%20required">LDAP users have been disabled or left the company cleanup required</a> |
385 | 390 | <a href="/app/SplunkAdmins/alert?s=%2FservicesNS%2Fnobody%2FSplunkAdmins%2Fsaved%2Fsearches%2FSearchHeadLevel%20-%20Saved%20Searches%20with%20privileged%20owners%20and%20excessive%20write%20perms">Saved Searches with privileged owners and excessive write perms</a> |
386 | 391 | <a href="/app/SplunkAdmins/alert?s=%2FservicesNS%2Fnobody%2FSplunkAdmins%2Fsaved%2Fsearches%2FSearchHeadLevel%20-%20Scheduled%20Searches%20Configured%20with%20incorrect%20sharing">Scheduled Searches Configured with incorrect sharing</a> |
387 | 392 | <a href="/app/SplunkAdmins/alert?s=%2FservicesNS%2Fnobody%2FSplunkAdmins%2Fsaved%2Fsearches%2FSearchHeadLevel%20-%20Splunk%20login%20attempts%20from%20users%20that%20do%20not%20have%20any%20LDAP%20roles">Splunk login attempts from users that do not have any LDAP roles</a> |
388 | 393 | <a href="/app/SplunkAdmins/alert?s=%2FservicesNS%2Fnobody%2FSplunkAdmins%2Fsaved%2Fsearches%2FSearchHeadLevel%20-%20authorize.conf%20settings%20will%20prevent%20some%20users%20from%20appearing%20in%20the%20UI">SearchHeadLevel - authorize.conf settings will prevent some users from appearing in the UI</a> |
| 394 | + <saved name="SearchHeadLevel - Knowledge Bundle contents" /> |
389 | 395 | </collection> |
390 | 396 | <collection label="Quotas"> |
391 | 397 | <a href="/app/SplunkAdmins/alert?s=%2FservicesNS%2Fnobody%2FSplunkAdmins%2Fsaved%2Fsearches%2FSearchHeadLevel%20-%20Splunk%20Max%20Historic%20Search%20Limits%20Reached">Splunk Max Historic Search Limits Reached</a> |
|
432 | 438 | <view name="lookup_audit" /> |
433 | 439 | <saved name="SearchHeadLevel - Knowledge bundle status on indexers" /> |
434 | 440 | <saved name="SearchHeadLevel - Knowledge bundle replication times metrics.log" /> |
| 441 | + <saved name="SearchHeadLevel - Knowledge Bundle contents" /> |
| 442 | + <saved name="syslog-ng - cache statistics summary" /> |
435 | 443 | </collection> |
436 | 444 | <collection label="Summary_Reports"> |
437 | 445 | <saved name="SearchHeadLevel - platform_stats.audit metrics searches" /> |
|
0 commit comments