3.0.13
New reports:
IndexerLevel - events per second benchmarkIndexerLevel - savedsearches by indexer execution timeSearchHeadLevel - indexes per savedsearchSearchHeadLevel - macros in useSearchHeadLevel - Indexes for savedsearch without subsearchesSearchHeadLevel - platform_stats.remote_searches metrics populating search 24 hour
Updated alerts:
AllSplunkEnterpriseLevel - Splunkd Log Messages Admins Only- updated criteriaIndexerLevel - RemoteSearches find datamodel acceleration with wildcards- updated regexMonitoringConsole - one or more servers require configuration- changed criteriaMonitoringConsole - one or more servers require configuration automated- rewrote the alertSearchHeadLevel - Indexer Peer Connection Failures- updated commentsSearchHeadLevel - Detect searches hitting corrupt buckets- updated commentsSearchHeadLevel - Users with auto-finalized searches- updated commentsSearchHeadLevel - splunk_search_messages dispatch- updated commentsSearchHeadLevel - Lookups within savedsearches- corrected URLSearchHeadLevel - Sourcetypes usage from search telemetry data- description updateSearchHeadLevel - Jobs endpoint example- updated descriptionSearchHeadLevel - SmartStore cache misses - dashboards- minor update to regexSearchHeadLevel - SmartStore cache misses - combined- minor update to regexSearchHeadLevel - Search Messages field extractor slow- updated commentsSearchHeadLevel - Search Messages user level- updated commentsSearchHeadLevel - Search Messages admins only- updated criteria and comments
Updated reports:
IndexerLevel - RemoteSearches - lookup usage- typo fixed in descriptionIndexerLevel - Report on bucket corruption- updated commentsSearchHeadLevel - summary indexing searches not using durable search- corrected REST contextSearchHeadLevel - Lookups within savedsearches- corrected REST contextSearchHeadLevel - platform_stats.audit metrics users- added v2/v1 endpoints for search/jobs/exportSearchHeadLevel - platform_stats.audit metrics api- added v2/v1 endpoints for search/jobs/exportSearchHeadLevel - platform_stats.audit metrics users 24hour- added v2/v1 endpoints for search/jobs/export
Updated to use macro splunkadmins_clustermaster_host instead of splunk_server=local:
ClusterMasterLevel - Primary bucket count per peerClusterMasterLevel - excess buckets on masterIndexerLevel - ClusterMaster Advising SearchOrRep Factor Not Met
Updated to use macro splunkadmins_restmacro instead of splunk_server=local:
IndexerLevel - Indexer replication queue issues to some peersSearchHeadLevel - Alerts that have not fired an action in X daysSearchHeadLevel - Accelerated DataModels Access InfoSearchHeadLevel - Accelerated DataModels with wildcard or no index specifiedSearchHeadLevel - authorize.conf settings will prevent some users from appearing in the UISearchHeadLevel - Data Model Acceleration Completion StatusSearchHeadLevel - DataModel FieldsSearchHeadLevel - Dashboard refresh intervalsSearchHeadLevel - Dashboards using depends and running searches in the backgroundSearchHeadLevel - Dashboards using special charactersSearchHeadLevel - Dashboards with all time searches setSearchHeadLevel - Dashboards that may benefit from base or post-process searchesSearchHeadLevel - DataModels reportSearchHeadLevel - Disabled modular inputs are runningSearchHeadLevel - Detect changes to knowledge objects non-directorySearchHeadLevel - EventTypes reportSearchHeadLevel - Index access list by userSearchHeadLevel - IndexesPerUser ReportSearchHeadLevel - Knowledge bundle status on indexersSearchHeadLevel - Lookup file ownersSearchHeadLevel - Lookup CSV sizeSearchHeadLevel - Macro reportSearchHeadLevel - platform_stats.users savedsearchesSearchHeadLevel - platform_stats.users dashboardsSearchHeadLevel - Saved Searches with privileged owners and excessive write permsSearchHeadLevel - Summary searches using realtime search schedulingSearchHeadLevel - SavedSearches using special charactersSearchHeadLevel - Splunk alert actions exceeding the max_action_results limitSearchHeadLevel - summary indexing searches not using durable searchSearchHeadLevel - Tags report
Other macro updates:
DeploymentServer - Count by application