3.0.2
Merged pull request from jeffland-consist via github including various changes
New alerts:
IndexerLevel - replicationdatareceiverthread close to 100% utilisation
New macros:
splunkadmins_metrics_sourcesplunkadmins_hec_metrics_source
New reports:
SearchHeadLevel - Accelerated DataModels Access InfoSearchHeadLevel - Dashboards resulting in concurrency issuesSearchHeadLevel - Dashboards that may benefit from base or post-process searchesSearchHeadLevel - Searches by search type
Updated macros:
splunkadmins_splunkd_sourcesplunkadmins_splunkuf_sourcesplunkadmins_mongo_sourcesplunkadmins_license_usage_source
To include a trailing wildcard (so splunkd.log.1 matches or similar)
Updated alerts:
AllSplunkEnterpriseLevel - Core Dumps Disabled- updated matching criteriaAllSplunkEnterpriseLevel - Non-existent roles are assigned to users- updated matching criteriaAllSplunkEnterpriseLevel - Splunk Servers throwing runScript errors- updated matching criteriaAllSplunkEnterpriseLevel - sendmodalert errors- updated matching criteriaAllSplunkEnterpriseLevel - Splunkd Log Messages Admins Only- updated matching criteriaAllSplunkEnterpriseLevel - Splunk Servers with resource starvation- updated to usesplunkadmins_splunkd_sourcemacroAllSplunkLevel - No recent metrics.log data- corrected comment to be after tstats, updated to usesplunkadmins_metrics_sourcemacroAllSplunkLevel - DeploymentServer Application Installation Error- updated matching criteriaDeploymentServer - Application Not Found On Deployment Server- updated matching criteriaForwarderLevel - Channel churn issues- updated to usesplunkadmins_metrics_sourcemacroForwarderLevel - Forwarders connecting to a single endpoint for extended periods- updated to usesplunkadmins_metrics_sourcemacroForwarderLevel - Forwarders connecting to a single endpoint for extended periods UF level- updated to usesplunkadmins_metrics_sourcemacroForwarderLevel - Splunk HTTP Listener Overwhelmed- updated matching criteriaForwarderLevel - Splunk Universal Forwarders Exceeding the File Descriptor Cache- updated matching criteriaForwarderLevel - Splunk Universal Forwarders that are time shifting- updated matching criteriaForwarderLevel - Stopping all listening ports- updated to usesplunkadmins_splunkd_sourcemacroIndexerLevel - Buckets changes per day- updated matching criteria, updated to usesplunkadmins_splunkd_sourcemacroIndexerLevel - Indexer Queues May Have Issues- updated to usesplunkadmins_metrics_sourcemacroIndexerLevel - Knowledge bundle upload stats- updated to usesplunkadmins_metrics_sourcemacroIndexerLevel - platform_stats.indexers totalgb_thruput measurement- updated to usesplunkadmins_metrics_sourcemacroIndexerLevel - platform_stats.indexers stddev measurement- updated to usesplunkadmins_metrics_sourcemacroIndexerLevel - platform_stats.indexers stddev incoming measurement- updated to usesplunkadmins_metrics_sourcemacroIndexerLevel - Weekly Broken Events Report- updated matching criteriaIndexerLevel - Time format has changed multiple log types in one sourcetype- updated matching criteriaIndexerLevel - Buckets have being frozen due to index sizing- updated matching criteriaIndexerLevel - Unclean Shutdown - Fsck- updated matching criteriaIndexerLevel - Index not defined- updated matching criteriaIndexerLevel - Timestamp parsing issues combined alert- updated to usesplunkadmins_splunkd_sourcemacroIndexerLevel - S2SFileReceiver Error- updated matching criteriaMonitoringConsole - Core dumps have appeared on the filesystem- corrected to useindexer_cluster_namemacroMonitoringConsole - Crash logs have appeared on the filesystem- corrected descriptionSearchHeadLevel - LDAP users have been disabled or left the company cleanup required- updated matching criteriaSearchHeadLevel - Long filenames may be causing issues- updated matching criteriaSearchHeadLevel - SHCluster Artifact Replication Issues- updated matching criteriaSearchHeadLevel - Captain Switchover Occurring- updated matching criteriaSearchHeadLevel - Knowledge bundle replication times metrics.log- updated to usesplunkadmins_metrics_sourcemacroSearchHeadLevel - Detect bundle pushes no longer occurring- updated to usesplunkadmins_metrics_sourcemacroSearchHeadLevel - WLM aborted searches- updated matching criteriaSearchHeadLevel - SHC Captain unable to establish common bundle- updated to usesplunkadmins_splunkd_sourcemacro
Updated dashboards:
ClusterMasterJobs.xmlheavyforwarders_max_data_queue_sizes_by_name.xmlheavyforwarders_max_data_queue_sizes_by_name_v8.xmlhec_performance.xmlindexer_data_spread.xmlindexer_max_data_queue_sizes_by_name.xmlindexer_max_data_queue_sizes_by_name_v8.xmlrolled_buckets_by_index.xmlsmartstore_stats.xmlsplunk_forwarder_data_balance_tuning.xmlsplunk_forwarder_output_tuning.xml
To use splunkadmins_splunkd_source and/or splunkadmins_metrics_source macros