Skip to content

Commit da8b07f

Browse files
committed
Updated alert:
AllSplunkEnterpriseLevel - Email Sending Failures - to exclude a 9.3.3 warning Updated macro: search_type_from_sid - for subsearches Updated reports: SearchHeadLevel - Lookup file owners - description/comment update SearchHeadLevel - Detect lookups that have not being accessed for a period of time - description/comment update
1 parent 525bce7 commit da8b07f

File tree

5 files changed

+112
-44
lines changed

5 files changed

+112
-44
lines changed

README.md

Lines changed: 18 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -359,6 +359,24 @@ These are appear to be from premium apps but it does imply that there is a mecha
359359
Feel free to open an issue on github or use the contact author on the SplunkBase link and I will try to get back to you when possible, thanks!
360360

361361
## Release Notes
362+
### 4.0.4
363+
New reports:
364+
- `SearchHeadLevel - access logs kvstore usage`
365+
- `SearchHeadLevel - Lookup Watcher Recent Modification Summary`
366+
367+
Updated alert:
368+
- `AllSplunkEnterpriseLevel - Email Sending Failures` - to exclude a warning noticed in 9.3.3
369+
370+
Updated macro:
371+
- `search_type_from_sid` - for subsearches
372+
373+
Updated reports:
374+
- `SearchHeadLevel - Lookup file owners` - description/comment update
375+
- `SearchHeadLevel - Detect lookups that have not being accessed for a period of time` - description/comment update
376+
377+
378+
Updated cron schedules of various reports to move them to different times
379+
362380
### 4.0.3
363381
New reports:
364382
- `SearchHeadLevel - Datamodel access summary`

default/app.conf

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -14,7 +14,7 @@ supported_themes = light,dark
1414
[launcher]
1515
author = Gareth Anderson
1616
description = Alerts and dashboards as described in the Splunk 2017 conf presentation How did you get so big?
17-
version = 4.0.3
17+
version = 4.0.4
1818

1919
[package]
2020
id = SplunkAdmins

default/data/ui/nav/default.xml

Lines changed: 10 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -277,6 +277,8 @@
277277
<saved name="SearchHeadLevel - platform_stats.remote_searches metrics populating search 24 hour" />
278278
<saved name="SearchHeadLevel - audit.log - lookup usage" />
279279
<saved name="SearchHeadLevel - Lookup Editor lookup updates" />
280+
<saved name="SearchHeadLevel - Lookup Watcher Recent Modification Summary" />
281+
<saved name="SearchHeadLevel - access logs kvstore usage" />
280282
<saved name="IndexerLevel - platform_stats.counters hosts" />
281283
<saved name="IndexerLevel - platform_stats.counters hosts 24hour" />
282284
<saved name="IndexerLevel - platform_stats.indexers totalgb measurement" />
@@ -310,6 +312,7 @@
310312
<saved name="SearchHeadLevel - Search Queries summary exact match by index" />
311313
<saved name="SearchHeadLevel - Search Queries summary loadjob and savedsearch usage in audit logs" />
312314
<saved name="SearchHeadLevel - Sourcetypes usage from search telemetry data" />
315+
<saved name="SearchHeadLevel - access logs kvstore usage" />
313316
<saved name="SearchHeadLevel - Searches by search type" />
314317
<saved name="SearchHeadLevel - IndexesPerUser Report" />
315318
<saved name="SearchHeadLevel - license usage per sourcetype per index" />
@@ -322,6 +325,7 @@
322325
<saved name="SearchHeadLevel - Jobs endpoint example" />
323326
<saved name="SearchHeadLevel - configtracker index example" />
324327
<saved name="SearchHeadLevel - configtracker index example2" />
328+
<saved name="SearchHeadLevel - Lookup Watcher Recent Modification Summary" />
325329
<saved name="IndexerLevel - RemoteSearches Indexes Stats" />
326330
<saved name="IndexerLevel - RemoteSearches Indexes Stats Wilcard" />
327331
<saved name="IndexerLevel - RemoteSearches - lookup usage" />
@@ -468,6 +472,7 @@
468472
<saved name="SearchHeadLevel - Lookup Editor lookup updates" />
469473
<saved name="SearchHeadLevel - REST API usage via audit.log" />
470474
<saved name="SearchHeadLevel - User created kvstore collections" />
475+
<saved name="SearchHeadLevel - access logs kvstore usage" />
471476
<saved name="IndexerLevel - RemoteSearches find all time searches" />
472477
<saved name="IndexerLevel - RemoteSearches find datamodel acceleration with wildcards" />
473478
<saved name="IndexerLevel - RemoteSearches - lookup usage" />
@@ -483,6 +488,7 @@
483488
<saved name="SearchHeadLevel - Lookup file owners" />
484489
<saved name="SearchHeadLevel - Lookups within a dashboard" />
485490
<saved name="SearchHeadLevel - Lookups within savedsearches" />
491+
<saved name="SearchHeadLevel - Lookup Watcher Recent Modification Summary" />
486492
<saved name="SearchHeadLevel - Knowledge bundle status on indexers" />
487493
<saved name="SearchHeadLevel - Knowledge bundle replication times metrics.log" />
488494
<saved name="SearchHeadLevel - Knowledge Bundle contents" />
@@ -495,6 +501,8 @@
495501
<collection label="Summary_Reports">
496502
<saved name="SearchHeadLevel - audit.log - lookup usage" />
497503
<saved name="SearchHeadLevel - Lookup Editor lookup updates" />
504+
<saved name="SearchHeadLevel - Lookup Watcher Recent Modification Summary" />
505+
<saved name="SearchHeadLevel - access logs kvstore usage" />
498506
<saved name="SearchHeadLevel - license usage per sourcetype per index" />
499507
<saved name="SearchHeadLevel - indexes per savedsearch" />
500508
<saved name="SearchHeadLevel - macros in use" />
@@ -551,8 +559,10 @@
551559
<collection label="Summary_Reports">
552560
<saved name="SearchHeadLevel - audit.log - lookup usage" />
553561
<saved name="SearchHeadLevel - Lookup Editor lookup updates" />
562+
<saved name="SearchHeadLevel - Lookup Watcher Recent Modification Summary" />
554563
<saved name="SearchHeadLevel - license usage per sourcetype per index" />
555564
<saved name="SearchHeadLevel - indexes per savedsearch" />
565+
<saved name="SearchHeadLevel - access logs kvstore usage" />
556566
<saved name="SearchHeadLevel - macros in use" />
557567
<saved name="SearchHeadLevel - platform_stats.audit metrics searches" />
558568
<saved name="SearchHeadLevel - platform_stats.audit metrics users" />

default/macros.conf

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -708,6 +708,7 @@ iseval = 0
708708
args = search_id
709709
definition = eval from=null(), username=null(), searchname2=null(), searchname=null()\
710710
| rex field=$search_id$ "'?(_rt)?(_?subsearch)*_?(?P<from>[^_]+)((_(?P<base64username>[^_]+))|(__(?P<username>[^_]+)))((__(?P<app>[^_]+)__(?P<searchname2>[^_]+))|(_(?P<base64appname>[^_]+)__(?P<searchname>[^_]+)))"\
711+
| rex field=$search_id$ "subsearch_(?P<username>[^_]+)__[^_]+(__(?P<app>[^_]+)__(?P<searchname2>[^_]+))" \
711712
| rex field=$search_id$ "^_?(?P<from>SummaryDirector)"\
712713
```Pattern appears to vary but remote_<hostname>_ is consistent along with the optional _subsearch, the _from can be <username>__ownername__appname__RMD for dashboards as one pattern, it can also be unixepoch (ad-hoc), or scheduler__username__appname (scheduled search), or username__owner__(something)__dashboardview, among others. RMD values can be translated via audit.log, scheduler.log or remote_searches.log (if savedsearch_name is there)!```\
713714
| fillnull from value="adhoc"\

0 commit comments

Comments
 (0)