Releases: gjanders/SplunkAdmins
4.0.6
New macros:
indexes_extraction(1)- to extract indexes from search logs
Updated reports/alerts:
AllSplunkEnterpriseLevel - Splunkd Crash Logs Have Appeared in Production- updated based on email feedback to use sourcetype (as source matching needed wildcards)IndexerLevel - Slow peer from remote searches- corrected comment in search onlySearchHeadLevel - Search Queries summary exact matchSearchHeadLevel - Search Queries summary non-exact matchSearchHeadLevel - SmartStore cache misses - dashboardsSearchHeadLevel - SmartStore cache misses - savedsearchesSearchHeadLevel - SmartStore cache misses - combinedSearchHeadLevel - Datamodel REST endpoint indexes in useSearchHeadLevel - indexes per savedsearchSearchHeadLevel - Indexes for savedsearch without subsearchesSearchHeadLevel - indexes per dashboard
Updated reports/alerts:
AllSplunkEnterpriseLevel - Splunk Scheduler excessive delays in executing searchAllSplunkEnterpriseLevel - sendmodalert errors- `SearchHeadLevel - Alerts that have not fired an action in X days
SearchHeadLevel - Scheduled Search Efficiency
To extract savedsearch_name (as I found you can have savedsearches with double quotes in the title).
4.0.5
New alerts:
AllSplunkEnterpriseLevel - Splunk servers with resource starvation v2
New reports:
SearchHeadLevel - indexes per dashboard
Updated reports/alerts:
AllSplunkEnterpriseLevel - Splunk Servers with resource starvation- reference to new versionAllSplunkEnterpriseLevel - Splunkd Log Messages Admins Only- additional criteriaIndexerLevel - Slow peer from remote searches- updated regex for Splunk 9.4 and aboveIndexerLevel - RemoteSearches Indexes Stats Wilcard- updated regex for Splunk 9.4 and aboveIndexerLevel - RemoteSearches Indexes Stats- updated regex for Splunk 9.4 and aboveSearchHeadLevel - Excessive REST API usage- added semantic jobs endpointsSearchHeadLevel - platform_stats.remote_searches metrics populating searchSearchHeadLevel - platform_stats access summary- added semantic jobs endpointsSearchHeadLevel - SHC Captain unable to establish common bundle- additional criteriaSearchHeadLevel - Search Messages admins only- additional criteria
4.0.4
Updated alert:
AllSplunkEnterpriseLevel - Email Sending Failures- to exclude a 9.3.3 warning
Updated macro:
search_type_from_sid- for subsearches
Updated reports:
SearchHeadLevel - Lookup file owners- description/comment updateSearchHeadLevel - Detect lookups that have not being accessed for a period of time- description/comment update
4.0.3
New reports:
SearchHeadLevel - Datamodel access summary
Updated alerts:
AllSplunkEnterpriseLevel - File integrity check failure- removed wildcard, feedback from Gregg WoodcockAllSplunkEnterpriseLevel - Splunkd Log Messages Admins Only- removed extra "AND", feedback from Gregg Woodcock
Updated reports:
SearchHeadLevel - Accelerated DataModels Access Info - updated descriptionSearchHeadLevel - Datamodel REST endpoint indexes in use- correct indexin multivalued extractionSearchHeadLevel - indexes per savedsearch- correct indexin multivalued extractionSearchHeadLevel - Indexes for savedsearch without subsearches- correct indexin multivalued extractionSearchHeadLevel - Lookups within savedsearches- included the action.lookup.filenameSearchHeadLevel - Search Queries summary exact match- correct indexin multivalued extractionSearchHeadLevel - Search Queries summary non-exact match- correct indexin multivalued extractionSearchHeadLevel - SmartStore cache misses - dashboards- correct indexin multivalued extractionSearchHeadLevel - SmartStore cache misses - savedsearches- correct indexin multivalued extractionSearchHeadLevel - SmartStore cache misses - combined- correct indexin multivalued extraction
4.0.2
Updated alerts:
MonitoringConsole - one or more servers require configuration automated- added missing , issue #25 (thanks to barrettnet)SearchHeadLevel - Detect MongoDB errors- included warning level entries
Updated dashboards:
indexer_max_data_queue_sizes_by_name- improved replication panelindexer_max_data_queue_sizes_by_name_v8- improved replication panel
Updated reports:
SearchHeadLevel - indexes per savedsearch- updated regex for union/set/multisearchSearchHeadLevel - Search Queries summary exact match- updated regex for union/set/multisearchSearchHeadLevel - Search Queries summary non-exact match- updated regex for union/set/multisearchSearchHeadLevel - Search Queries summary loadjob and savedsearch usage in audit logs- updated rexgex, rewrote search to find map, join, appendcols and other commands
4.0.1
New dashboard:
-heavy_forwarder_analysis - as found in the conf24 presentation PLA1509B
New reports:
SearchHeadLevel - Job performance data per indexer handoff timeSearchHeadLevel - KVStore collection sizeSearchHeadLevel - Savedsearches with schedules and no next_scheduled_time
Updated alerts:
AllSplunkEnterpriseLevel - Splunkd Log Messages Admins Only- search updatesAllSplunkEnterpriseLevel - Email Sending Failures- added app contextIndexerLevel - These Indexes Are Approaching The warmDBCount limit- added datatype=all argumentIndexerLevel - Cold data location approaching size limits- added datatype=all argumentIndexerLevel - Unclean Shutdown - Fsck- added datatype=all argumentSearchHeadLevel - Peer timeouts or authentication issues- updates to use Splunkd sourceSearchHeadLevel - Splunk alert actions exceeding the max_action_results limit- excluded summary indexingSearchHeadLevel - Scheduled Searches without a configured earliest and latest time- rewrote search for efficiencySearchHeadLevel - Search Messages user level- search updatesSearchHeadLevel - Search Messages admins only- search updates
Updated dashboards:
splunk_forwarder_output_tuning- updated comments, removed heartbeatFrequency
Updated macros:
search_type_from_sid- minor tweaks to regex
Updated reports:
SearchHeadLevel - indexes per savedsearch- corrected typo on multisearch, re-wrote parts of the query to include subsearches as wellSearchHeadLevel - Indexes for savedsearch without subsearches- corrected typo on multisearchSearchHeadLevel - Search Queries summary non-exact match- added delim for index IN (a b c), corrected typo on multisearch, updated description to link to https://github.com/TheWoodRanger/presentation-conf_24_audittrail_native_telemetrySearchHeadLevel - Search Queries summary exact match- added delim for index IN (a b c), corrected typo on multisearch, updated description to link to https://github.com/TheWoodRanger/presentation-conf_24_audittrail_native_telemetry
Also updated the navigation menu.
4.0.0
- Merged pull request from sifters relating to replacing comment macro with the triple backtick option introduced in Splunk 8.1. This involved editing many searches to change the format of the comments.
New reports:
SearchHeadLevel - configtracker index example2
The version number has moved to 4.0.0 as this change has the potential to introduce issues with the change of comment syntax. I've completed multiple reviews and I believe there should be no broken alerts but please report them via the contact the author if you find any
This version removes compatibility with Splunk versions below 8.1 due to the use of the newer comment syntax
3.0.14
New reports:
SearchHeadLevel - Lookup definitions with no lookup file or kvstore collectionSearchHeadLevel - User created kvstore collectionsSearchHeadLevel - Search Queries summary loadjob and savedsearch usage in audit logs
Updated alerts:
AllSplunkEnterpriseLevel - Splunkd Log Messages Admins OnlySearchHeadLevel - Detect bundle pushes no longer occurringSearchHeadLevel - macros in useSearchHeadLevel - Search Messages user level
Updated reports:
SearchHeadLevel - audit.log - lookup usage- added regex as the search field sometimes doesn't auto-extract correctlySearchHeadLevel - Detect lookups that have not being accessed for a period of time- added automatic lookups inSearchHeadLevel - platform_stats access summary- criteria updateSearchHeadLevel - Lookup file owners- corrections to ensure that automatic lookups are not includedSearchHeadLevel - Search Queries summary non-exact match- minor criteria update
3.0.13
New reports:
IndexerLevel - events per second benchmarkIndexerLevel - savedsearches by indexer execution timeSearchHeadLevel - indexes per savedsearchSearchHeadLevel - macros in useSearchHeadLevel - Indexes for savedsearch without subsearchesSearchHeadLevel - platform_stats.remote_searches metrics populating search 24 hour
Updated alerts:
AllSplunkEnterpriseLevel - Splunkd Log Messages Admins Only- updated criteriaIndexerLevel - RemoteSearches find datamodel acceleration with wildcards- updated regexMonitoringConsole - one or more servers require configuration- changed criteriaMonitoringConsole - one or more servers require configuration automated- rewrote the alertSearchHeadLevel - Indexer Peer Connection Failures- updated commentsSearchHeadLevel - Detect searches hitting corrupt buckets- updated commentsSearchHeadLevel - Users with auto-finalized searches- updated commentsSearchHeadLevel - splunk_search_messages dispatch- updated commentsSearchHeadLevel - Lookups within savedsearches- corrected URLSearchHeadLevel - Sourcetypes usage from search telemetry data- description updateSearchHeadLevel - Jobs endpoint example- updated descriptionSearchHeadLevel - SmartStore cache misses - dashboards- minor update to regexSearchHeadLevel - SmartStore cache misses - combined- minor update to regexSearchHeadLevel - Search Messages field extractor slow- updated commentsSearchHeadLevel - Search Messages user level- updated commentsSearchHeadLevel - Search Messages admins only- updated criteria and comments
Updated reports:
IndexerLevel - RemoteSearches - lookup usage- typo fixed in descriptionIndexerLevel - Report on bucket corruption- updated commentsSearchHeadLevel - summary indexing searches not using durable search- corrected REST contextSearchHeadLevel - Lookups within savedsearches- corrected REST contextSearchHeadLevel - platform_stats.audit metrics users- added v2/v1 endpoints for search/jobs/exportSearchHeadLevel - platform_stats.audit metrics api- added v2/v1 endpoints for search/jobs/exportSearchHeadLevel - platform_stats.audit metrics users 24hour- added v2/v1 endpoints for search/jobs/export
Updated to use macro splunkadmins_clustermaster_host instead of splunk_server=local:
ClusterMasterLevel - Primary bucket count per peerClusterMasterLevel - excess buckets on masterIndexerLevel - ClusterMaster Advising SearchOrRep Factor Not Met
Updated to use macro splunkadmins_restmacro instead of splunk_server=local:
IndexerLevel - Indexer replication queue issues to some peersSearchHeadLevel - Alerts that have not fired an action in X daysSearchHeadLevel - Accelerated DataModels Access InfoSearchHeadLevel - Accelerated DataModels with wildcard or no index specifiedSearchHeadLevel - authorize.conf settings will prevent some users from appearing in the UISearchHeadLevel - Data Model Acceleration Completion StatusSearchHeadLevel - DataModel FieldsSearchHeadLevel - Dashboard refresh intervalsSearchHeadLevel - Dashboards using depends and running searches in the backgroundSearchHeadLevel - Dashboards using special charactersSearchHeadLevel - Dashboards with all time searches setSearchHeadLevel - Dashboards that may benefit from base or post-process searchesSearchHeadLevel - DataModels reportSearchHeadLevel - Disabled modular inputs are runningSearchHeadLevel - Detect changes to knowledge objects non-directorySearchHeadLevel - EventTypes reportSearchHeadLevel - Index access list by userSearchHeadLevel - IndexesPerUser ReportSearchHeadLevel - Knowledge bundle status on indexersSearchHeadLevel - Lookup file ownersSearchHeadLevel - Lookup CSV sizeSearchHeadLevel - Macro reportSearchHeadLevel - platform_stats.users savedsearchesSearchHeadLevel - platform_stats.users dashboardsSearchHeadLevel - Saved Searches with privileged owners and excessive write permsSearchHeadLevel - Summary searches using realtime search schedulingSearchHeadLevel - SavedSearches using special charactersSearchHeadLevel - Splunk alert actions exceeding the max_action_results limitSearchHeadLevel - summary indexing searches not using durable searchSearchHeadLevel - Tags report
Other macro updates:
DeploymentServer - Count by application
3.0.12
New alerts:
MonitoringConsole - one or more servers require configurationMonitoringConsole - one or more servers require configuration automatedSearchHeadLevel - Peer timeouts or authentication issues
New macros:
splunkadmins_macro_sub
New reports:
SearchHeadLevel - Datamodel REST endpoint indexes in useSearchHeadLevel - Job performance data per indexerSearchHeadLevel - Jobs endpoint exampleSearchHeadLevel - configtracker index example
Updated alerts:
AllSplunkEnterpriseLevel - Splunkd Log Messages Admins Only- more criteriaSearchHeadLevel - Search Messages user level- more criteriaSearchHeadLevel - Search Messages admins only- more criteria
Updated dashboards:
splunk_forwarder_output_tuning- to reference NLB/load balanced version of asynchronous forwarding
Updated macros:
whataccessdoihave- comments and added srchIndexesDisallowed
Updated reports:
SearchHeadLevel - IndexesPerRole Remote Report- comment updates onlySearchHeadLevel - Lookup file owners- comment updates only
Alerts added to future removal list:
ClusterMasterLevel - Per index status
Updated to use splunkadmins_macro_sub macro:
SearchHeadLevel - Dashboards with all time searches setSearchHeadLevel - Scheduled searches not specifying an index macro versionSearchHeadLevel - Search Queries By Type Audit Logs macro versionSearchHeadLevel - Search Queries By Type Audit Logs macro version otherSearchHeadLevel - Search Queries summary exact matchSearchHeadLevel - Search Queries summary non-exact matchSearchHeadLevel - User - Dashboards searching all indexes macro version
Misc:
- Added supported themes settings in app.conf to allow the usage of dark theme (for 9.1 enterprise users and above)