|
166 | 166 | <a href="/app/SplunkAdmins/alert?s=%2FservicesNS%2Fnobody%2FSplunkAdmins%2Fsaved%2Fsearches%2FIndexerLevel%20-%20Index%20not%20defined">Index not defined</a> |
167 | 167 | <a href="/app/SplunkAdmins/alert?s=%2FservicesNS%2Fnobody%2FSplunkAdmins%2Fsaved%2Fsearches%2FForwarderLevel%20-%20Stopping%20all%20listening%20ports">ForwarderLevel - Stopping all listening ports</a> |
168 | 168 | <a href="/app/SplunkAdmins/alert?s=%2FservicesNS%2Fnobody%2FSplunkAdmins%2Fsaved%2Fsearches%2FIndexerLevel%20-%20replicationdatareceiverthread%20close%20to%20100%25%20utilisation">IndexerLevel - replicationdatareceiverthread close to 100% utilisation</a> |
| 169 | + <saved name="SearchHeadLevel - license usage per sourcetype per index" /> |
169 | 170 | </collection> |
170 | 171 | <collection label="Data Parsing"> |
171 | 172 | <a href="/app/SplunkAdmins/alert?s=%2FservicesNS%2Fnobody%2FSplunkAdmins%2Fsaved%2Fsearches%2FIndexerLevel%20-%20Failures%20To%20Parse%20Timestamp%20Correctly%20%28excluding%20breaking%20issues%29">Failures To Parse Timestamp Correctly (excluding breaking issues)</a> |
|
238 | 239 | <saved name="IndexerLevel - Maximum memory utilisation per search" /> |
239 | 240 | <saved name="IndexerLevel - RemoteSearches find all time searches" /> |
240 | 241 | <saved name="IndexerLevel - RemoteSearches find datamodel acceleration with wildcards" /> |
| 242 | + <saved name="IndexerLevel - RemoteSearches - lookup usage" /> |
241 | 243 | <collection label="SmartStore"> |
242 | 244 | <saved name="SearchHeadLevel - SmartStore cache misses - savedsearches" /> |
243 | 245 | <saved name="SearchHeadLevel - SmartStore cache misses - dashboards" /> |
|
268 | 270 | <saved name="SearchHeadLevel - platform_stats.user_stats.introspection metrics populating search" /> |
269 | 271 | <saved name="SearchHeadLevel - platform_stats access summary" /> |
270 | 272 | <saved name="SearchHeadLevel - platform_stats.remote_searches metrics populating search" /> |
| 273 | + <saved name="SearchHeadLevel - audit.log - lookup usage" /> |
271 | 274 | <saved name="IndexerLevel - platform_stats.counters hosts" /> |
272 | 275 | <saved name="IndexerLevel - platform_stats.counters hosts 24hour" /> |
273 | 276 | <saved name="IndexerLevel - platform_stats.indexers totalgb measurement" /> |
|
276 | 279 | <saved name="IndexerLevel - platform_stats.indexers stddev incoming measurement" /> |
277 | 280 | <saved name="IndexerLevel - RemoteSearches Indexes Stats" /> |
278 | 281 | <saved name="IndexerLevel - RemoteSearches Indexes Stats Wilcard" /> |
| 282 | + <saved name="IndexerLevel - RemoteSearches - lookup usage" /> |
279 | 283 | </collection> |
280 | 284 | <collection label="External"> |
281 | 285 | <a href="https://github.com/silkyrich/cluster_health_tools/">The cluster_health_tools git repository contains very useful dashboards for various indexer related performance stats</a> |
|
286 | 290 | </collection> |
287 | 291 | <collection label="SearchHeadLevel"> |
288 | 292 | <collection label="Analytics"> |
289 | | - <saved name="SearchHeadLevel - Search Queries Per Day Audit Logs" /> |
| 293 | + <saved name="SearchHeadLevel - audit.log - lookup usage" /> |
| 294 | + <saved name="SearchHeadLevel - Search Queries Per Day Audit Logs" /> |
290 | 295 | <saved name="SearchHeadLevel - Search Queries By Type Audit Logs" /> |
291 | 296 | <saved name="SearchHeadLevel - Search Queries By Type Audit Logs macro version" /> |
292 | 297 | <saved name="SearchHeadLevel - Search Queries By Type Audit Logs macro version other" /> |
|
297 | 302 | <saved name="SearchHeadLevel - Search Queries summary exact match by index" /> |
298 | 303 | <saved name="SearchHeadLevel - Sourcetypes usage from search telemetry data" /> |
299 | 304 | <saved name="SearchHeadLevel - Searches by search type" /> |
300 | | - <saved name="SearchHeadLevel - IndexesPerUser Report" /> |
| 305 | + <saved name="SearchHeadLevel - IndexesPerUser Report" /> |
| 306 | + <saved name="SearchHeadLevel - license usage per sourcetype per index" /> |
| 307 | + <saved name="SearchHeadLevel - Lookup file owners" /> |
301 | 308 | <saved name="IndexerLevel - RemoteSearches Indexes Stats" /> |
302 | | - <saved name="IndexerLevel - RemoteSearches Indexes Stats Wilcard" /> |
| 309 | + <saved name="IndexerLevel - RemoteSearches Indexes Stats Wilcard" /> |
| 310 | + <saved name="IndexerLevel - RemoteSearches - lookup usage" /> |
303 | 311 | </collection> |
304 | 312 | <collection label="Data Models"> |
305 | 313 | <saved name="SearchHeadLevel - Data Model Acceleration Completion Status" /> |
|
361 | 369 | <saved name="SearchHeadLevel - SavedSearches using special characters" /> |
362 | 370 | <a href="/app/SplunkAdmins/alert?s=%2FservicesNS%2Fnobody%2FSplunkAdmins%2Fsaved%2Fsearches%2FSearchHeadLevel%20-%20Splunk%20alert%20actions%20exceeding%20the%20max_action_results%20limit">Splunk alert actions exceeding the max_action_results limit</a> |
363 | 371 | <a href="/app/SplunkAdmins/alert?s=%2FservicesNS%2Fnobody%2FSplunkAdmins%2Fsaved%2Fsearches%2FSearchHeadLevel%20-%20Splunk%20Scheduler%20logs%20have%20not%20appeared%20in%20the%20last">Splunk Scheduler logs have not appeared in the last</a> |
| 372 | + <a href="/app/SplunkAdmins/alert?s=%2FservicesNS%2Fnobody%2FSplunkAdmins%2Fsaved%2Fsearches%2FSearchHeadLevel%20-%20summary%20indexing%20searches%20not%20using%20durable%20search">SearchHeadLevel - summary indexing searches not using durable search</a> |
364 | 373 | </collection> |
365 | 374 | <collection label="Other"> |
366 | 375 | <saved name="SearchHeadLevel - Knowledge bundle replication times metrics.log" /> |
|
392 | 401 | <a href="/app/SplunkAdmins/alert?s=%2FservicesNS%2Fnobody%2FSplunkAdmins%2Fsaved%2Fsearches%2FSearchHeadLevel%20-%20Splunk%20login%20attempts%20from%20users%20that%20do%20not%20have%20any%20LDAP%20roles">Splunk login attempts from users that do not have any LDAP roles</a> |
393 | 402 | <a href="/app/SplunkAdmins/alert?s=%2FservicesNS%2Fnobody%2FSplunkAdmins%2Fsaved%2Fsearches%2FSearchHeadLevel%20-%20authorize.conf%20settings%20will%20prevent%20some%20users%20from%20appearing%20in%20the%20UI">SearchHeadLevel - authorize.conf settings will prevent some users from appearing in the UI</a> |
394 | 403 | <saved name="SearchHeadLevel - Knowledge Bundle contents" /> |
| 404 | + <a href="/app/SplunkAdmins/alert?s=%2FservicesNS%2Fnobody%2FSplunkAdmins%2Fsaved%2Fsearches%2FSearchHeadLevel%20-%20summary%20indexing%20searches%20not%20using%20durable%20search">SearchHeadLevel - summary indexing searches not using durable search</a> |
395 | 405 | </collection> |
396 | 406 | <collection label="Quotas"> |
397 | 407 | <a href="/app/SplunkAdmins/alert?s=%2FservicesNS%2Fnobody%2FSplunkAdmins%2Fsaved%2Fsearches%2FSearchHeadLevel%20-%20Splunk%20Max%20Historic%20Search%20Limits%20Reached">Splunk Max Historic Search Limits Reached</a> |
|
425 | 435 | <saved name="SearchHeadLevel - Searches dispatched as owner by other users" /> |
426 | 436 | <saved name="SearchHeadLevel - Lookup CSV size" /> |
427 | 437 | <saved name="SearchHeadLevel - audit logs showing all time searches" /> |
| 438 | + <saved name="SearchHeadLevel - audit.log - lookup usage" /> |
428 | 439 | <saved name="IndexerLevel - RemoteSearches find all time searches" /> |
429 | 440 | <saved name="IndexerLevel - RemoteSearches find datamodel acceleration with wildcards" /> |
| 441 | + <saved name="IndexerLevel - RemoteSearches - lookup usage" /> |
430 | 442 | <saved name="SearchHeadLevel - Search Messages field extractor slow" /> |
431 | 443 | <saved name="SearchHeadLevel - SmartStore cache misses - savedsearches" /> |
432 | 444 | <saved name="SearchHeadLevel - SmartStore cache misses - dashboards" /> |
|
436 | 448 | <view name="knowledge_objects_by_app" /> |
437 | 449 | <view name="lookups_in_use_finder" /> |
438 | 450 | <view name="lookup_audit" /> |
| 451 | + <saved name="SearchHeadLevel - Lookup file owners" /> |
439 | 452 | <saved name="SearchHeadLevel - Knowledge bundle status on indexers" /> |
440 | 453 | <saved name="SearchHeadLevel - Knowledge bundle replication times metrics.log" /> |
441 | 454 | <saved name="SearchHeadLevel - Knowledge Bundle contents" /> |
| 455 | + <saved name="SearchHeadLevel - license usage per sourcetype per index" /> |
442 | 456 | <saved name="syslog-ng - cache statistics summary" /> |
443 | 457 | </collection> |
444 | 458 | <collection label="Summary_Reports"> |
| 459 | + <saved name="SearchHeadLevel - audit.log - lookup usage" /> |
| 460 | + <saved name="SearchHeadLevel - license usage per sourcetype per index" /> |
445 | 461 | <saved name="SearchHeadLevel - platform_stats.audit metrics searches" /> |
446 | 462 | <saved name="SearchHeadLevel - platform_stats.audit metrics users" /> |
447 | 463 | <saved name="SearchHeadLevel - platform_stats.audit metrics users 24hour" /> |
|
450 | 466 | <saved name="SearchHeadLevel - platform_stats.audit metrics api" /> |
451 | 467 | <saved name="SearchHeadLevel - platform_stats.user_stats.introspection metrics populating search" /> |
452 | 468 | <saved name="SearchHeadLevel - platform_stats access summary" /> |
453 | | - <saved name="SearchHeadLevel - platform_stats.remote_searches metrics populating search" /> |
| 469 | + <saved name="SearchHeadLevel - platform_stats.remote_searches metrics populating search" /> |
454 | 470 | <saved name="IndexerLevel - platform_stats.counters hosts" /> |
455 | 471 | <saved name="IndexerLevel - platform_stats.counters hosts 24hour" /> |
456 | 472 | <saved name="IndexerLevel - platform_stats.indexers totalgb measurement" /> |
457 | 473 | <saved name="IndexerLevel - platform_stats.indexers totalgb_thruput measurement" /> |
458 | 474 | <saved name="IndexerLevel - platform_stats.indexers stddev measurement" /> |
459 | 475 | <saved name="IndexerLevel - platform_stats.indexers stddev incoming measurement" /> |
460 | 476 | <saved name="IndexerLevel - RemoteSearches Indexes Stats" /> |
461 | | - <saved name="IndexerLevel - RemoteSearches Indexes Stats Wilcard" /> |
| 477 | + <saved name="IndexerLevel - RemoteSearches Indexes Stats Wilcard" /> |
| 478 | + <saved name="IndexerLevel - RemoteSearches - lookup usage" /> |
462 | 479 | </collection> |
463 | 480 | <collection label="Scheduled Search Failures"> |
464 | 481 | <a href="/app/SplunkAdmins/alert?s=%2FservicesNS%2Fnobody%2FSplunkAdmins%2Fsaved%2Fsearches%2FSearchHeadLevel%20-%20Scheduled%20searches%20failing%20in%20cluster%20with%20404%20error">Scheduled searches failing in cluster with 404 error</a> |
|
477 | 494 | <saved name="SearchHeadLevel - EventTypes report" /> |
478 | 495 | <saved name="SearchHeadLevel - Users exceeding the disk quota introspection cleanup" /> |
479 | 496 | <saved name="SearchHeadLevel - RMD5 to savedsearch_name lookupgen report" /> |
| 497 | + <saved name="SearchHeadLevel - Lookup file owners" /> |
480 | 498 | </collection> |
481 | 499 | <collection label="Recommended (externally hosted)"> |
482 | 500 | <a href="https://github.com/dpaper-splunk/public/tree/master/dashboards" target="_blank">Extended Search Reporting (and others)</a> |
483 | 501 | <a href="https://github.com/nicovdw/splunk_concurrency_helper" target="_blank">Search Scheduler Tuning searches</a> |
484 | 502 | <a href="https://splunkbase.splunk.com/app/6449/" target="_blank">Sideview UI (User Activity details)</a> |
485 | 503 | <a href="https://splunkbase.splunk.com/app/6368/" target="_blank">Admins Little Helper for Splunk (btool, bundle utils and similar)</a> |
486 | 504 | <a href="https://splunkbase.splunk.com/app/4621/" target="_blank">TrackMe (Data Ingestion)</a> |
| 505 | + <a href="https://github.com/redvelociraptor/gettingsmarter/tree/main">Getting Smarter about Splunk SmartStore (including HEC dashboards)</a> |
487 | 506 | </collection> |
488 | 507 | </collection> |
489 | 508 | <collection label="Summary_Reports"> |
| 509 | + <saved name="SearchHeadLevel - audit.log - lookup usage" /> |
490 | 510 | <saved name="SearchHeadLevel - platform_stats.audit metrics searches" /> |
491 | 511 | <saved name="SearchHeadLevel - platform_stats.audit metrics users" /> |
492 | 512 | <saved name="SearchHeadLevel - platform_stats.audit metrics api" /> |
|
503 | 523 | <saved name="IndexerLevel - platform_stats.indexers stddev measurement" /> |
504 | 524 | <saved name="IndexerLevel - platform_stats.indexers stddev incoming measurement" /> |
505 | 525 | <saved name="IndexerLevel - RemoteSearches Indexes Stats" /> |
506 | | - <saved name="IndexerLevel - RemoteSearches Indexes Stats Wilcard" /> |
| 526 | + <saved name="IndexerLevel - RemoteSearches Indexes Stats Wilcard" /> |
| 527 | + <saved name="IndexerLevel - RemoteSearches - lookup usage" /> |
507 | 528 | </collection> |
508 | 529 | <collection label="Users"> |
509 | 530 | <saved name="What Access Do I Have Without REST?" /> |
|
0 commit comments