Releases: gjanders/SplunkAdmins
3.0.12
New alerts:
MonitoringConsole - one or more servers require configurationMonitoringConsole - one or more servers require configuration automatedSearchHeadLevel - Peer timeouts or authentication issues
New macros:
splunkadmins_macro_sub
New reports:
SearchHeadLevel - Datamodel REST endpoint indexes in useSearchHeadLevel - Job performance data per indexerSearchHeadLevel - Jobs endpoint exampleSearchHeadLevel - configtracker index example
Updated alerts:
AllSplunkEnterpriseLevel - Splunkd Log Messages Admins Only- more criteriaSearchHeadLevel - Search Messages user level- more criteriaSearchHeadLevel - Search Messages admins only- more criteria
Updated dashboards:
splunk_forwarder_output_tuning- to reference NLB/load balanced version of asynchronous forwarding
Updated macros:
whataccessdoihave- comments and added srchIndexesDisallowed
Updated reports:
SearchHeadLevel - IndexesPerRole Remote Report- comment updates onlySearchHeadLevel - Lookup file owners- comment updates only
Alerts added to future removal list:
ClusterMasterLevel - Per index status
Updated to use splunkadmins_macro_sub macro:
SearchHeadLevel - Dashboards with all time searches setSearchHeadLevel - Scheduled searches not specifying an index macro versionSearchHeadLevel - Search Queries By Type Audit Logs macro versionSearchHeadLevel - Search Queries By Type Audit Logs macro version otherSearchHeadLevel - Search Queries summary exact matchSearchHeadLevel - Search Queries summary non-exact matchSearchHeadLevel - User - Dashboards searching all indexes macro version
Misc:
- Added supported themes settings in app.conf to allow the usage of dark theme (for 9.1 enterprise users and above)
3.0.11
Updated alerts:
AllSplunkEnterpriseLevel - ulimit on Splunk enterprise servers is below 8192- missing parenthesis, thanks Gregg WoodcockIndexerLevel - replicationdatareceiverthread close to 100% utilisation- incorrect macroMonitoringConsole - Crash logs have appeared on the filesystem- incorrect macro, github issue #22, thanks SANSd20
Added lookup file:
splunkadmins_indexlist_by_cluster.csv
3.0.10
3.0.9
In version 3.0.8 the lookup file splunkadmins_hec_reply_code_lookup.csv was updated based on gettingsmarter (github repo), the updated lookup was created by @jgedeon and additionally includes some health endpoint return codes (as well as those returned by the standard HEC endpoint)
Updated alerts:
SplunkEnterpriseLevel - Splunkd Log Messages Admins Only- more criteriaSearchHeadLevel - Scheduled Searches That Cannot Run- correcting issue #20 (thanks @barrettnet)
Updated reports:
SearchHeadLevel - Search Queries summary exact match- added provenanceSearchHeadLevel - Search Queries summary non-exact match- added provenanceSearchHeadLevel - audit.log - lookup usage- updated to handle mlspl files as well (apply command)SearchHeadLevel - Lookup file owners- now includes an additional join that can be used if TA-webtools is installed (to improve accuracy/exclude default lookup definitions/files)
New reports:
SearchHeadLevel - Detect lookups that have not being accessed for a period of timeSearchHeadLevel - Lookup Editor lookup updatesSearchHeadLevel - Lookups within dashboardsSearchHeadLevel - Lookups within savedsearchesSearchHeadLevel - REST API usage via audit.log
3.0.8
New alerts:
SearchHeadLevel - summary indexing searches not using durable search
New macros:
indexer_cluster_namewithout any parameters created as per issue #19 (barrettnet)
New reports:
SearchHeadLevel - audit.log - lookup usageSearchHeadLevel - license usage per sourcetype per indexSearchHeadLevel - Lookup file ownersIndexerLevel - RemoteSearches - lookup usage
Updated alerts:
AllSplunkEnterpriseLevel - Splunkd Log Messages Admins Only- more matching criteriaSearchHeadLevel - Scheduled Searches That Cannot Run- as per issue #18 (AHCL1)SearchHeadLevel - SHC Captain unable to establish common bundle- additional exclusion for Splunk 9.0.x
Updated reports:
IndexerLevel - platform_stats.indexers totalgb measurement- added * to the end oflicense_usage.log, updatedindexer_cluster_namewith parameter as per issue #19 (barrettnet)IndexerLevel - platform_stats.indexers totalgb_thruput measurement- updatedindexer_cluster_namewith parameter as per issue #19 (barrettnet)SearchHeadLevel - Search Queries summary exact match- removed newlines to improve accuracySearchHeadLevel - Search Queries summary non-exact match- removed newlines to improve accuracy
Updated recommended links in nav menu
3.0.7
New macros:
sysloghosts
New reports:
SearchHeadLevel - Knowledge Bundle contentssyslog-ng - cache statistics summary- as contributed by Marc Andersen, company: NIL815 ApS
Updated dashboards:
splunk_forwarder_output_tuning- added fillnull foringest_pipe
Updated alerts:
AllSplunkLevel - No recent metrics.log data- updated to use prestatsAllSplunkLevel - TCP Output Processor has paused the data flow- updated criteriaAllSplunkEnterpriseLevel - ulimit on Splunk enterprise servers is below 8192- now 64,000 (could be renamed in future)AllSplunkEnterpriseLevel - Splunkd Log Messages Admins Only- updated criteriaForwarderLevel - Splunk universal forwarders with ulimit issues- updated keywordsSearchHeadLevel - Scheduled Searches That Cannot Run- excluded the require commandSearchHeadLevel - Detect MongoDB errors- updated to use prestats, added_timefieldSearchHeadLevel - SHC Captain unable to establish common bundle- added new criteriaSearchHeadLevel - Search Messages user level- updated criteria
3.0.6
Updated dashboards:
Splunk forwarder output tuning- added fillnull ingest_pipe
Updated reports/alerts:
SearchHeadLevel - Dashboards using special characters- updated to use spath command instead of rexSearchHeadLevel - Search Messages user level- excluded require commandIndexerLevel - RemoteSearches find all time searches- removed keyword
On reports/alerts:
IndexerLevel - RemoteSearches Indexes StatsIndexerLevel - RemoteSearches Indexes Stats WilcardIndexerLevel - Slow peer from remote searchesIndexerLevel - SmartStore cache misses - remote_searchesSearchHeadLevel - platform_stats.remote_searches metrics populating search
Updated keywords to terminated: or closed: (previously terminated)
On reports/alerts:
SearchHeadLevel - Detect Excessive Search Use - Dashboard - AutomatedSearchHeadLevel - platform_stats.audit metrics searchesSearchHeadLevel - platform_stats.audit metrics usersSearchHeadLevel - platform_stats.audit metrics users 24hourSearchHeadLevel - Search Queries By Type Audit LogsSearchHeadLevel - Search Queries By Type Audit Logs macro versionSearchHeadLevel - Search Queries By Type Audit Logs macro version otherSearchHeadLevel - Searches dispatched as owner by other usersSearchHeadLevel - SmartStore cache misses - dashboardsSearchHeadLevel - SmartStore cache misses - savedsearchesSearchHeadLevel - SmartStore cache misses - combinedSearchHeadLevel - Users with auto-finalized searches
Removed regex:
| rex "(?s)^(?:[^'\n]*'){4},\s+\w+='(?P<search>[\s\S]+)'\]($|\[[^\]]+\]$)"
As it is causing issues with max_matches, newer Splunk versions appear to accurately match the search field without this regex
3.0.5
New alerts:
IndexerLevel - Connection errors to SmartStore
New reports:
SearchHeadLevel - Sourcetypes usage from search telemetry data
Updated alerts:
AllSplunkEnterpriseLevel - Splunkd Log Messages Admins Only- more matching criteriaForwarderLevel - Data dropping duration- comment updateSearchHeadLevel - Search Queries summary exact match- regex updates and 1 regex removalSearchHeadLevel - Search Queries summary non-exact match- regex updates and 1 regex removal
Updated macro:
splunkadmins_metrics_source- corrected to include source=
Removed app.manifest file
3.0.4
Removed the app.manifest file, release notes from 3.0.3:
New alerts:
IndexerLevel - Buckets have being frozen due to index sizing SmartStore
Updated alerts:
AllSplunkEnterpriseLevel - Replication Failures- comment updateAllSplunkEnterpriseLevel - Splunkd Log Messages Admins Only- additional criteria and removed SHC restart timesIndexerLevel - Buckets have being frozen due to index sizing- comment update onlyIndexerLevel - IndexConfig Warnings from Splunk indexers- additional criteriaSearchHeadLevel - Script failures in the last daySearchHeadLevel - KVStore Or Conf Replication Issues Are OccurringSearchHeadLevel - SavedSearches using special charactersSearchHeadLevel - Search Messages user level- removed some messages from the alert
3.0.3
New alerts:
IndexerLevel - Buckets have being frozen due to index sizing SmartStore
Updated alerts:
AllSplunkEnterpriseLevel - Replication Failures- comment updateAllSplunkEnterpriseLevel - Splunkd Log Messages Admins Only- additional criteria and removed SHC restart timesIndexerLevel - Buckets have being frozen due to index sizing- comment update onlyIndexerLevel - IndexConfig Warnings from Splunk indexers- additional criteriaSearchHeadLevel - Script failures in the last daySearchHeadLevel - KVStore Or Conf Replication Issues Are OccurringSearchHeadLevel - SavedSearches using special charactersSearchHeadLevel - Search Messages user level- removed some messages from the alert