4.0.1
New dashboard:
-heavy_forwarder_analysis - as found in the conf24 presentation PLA1509B
New reports:
SearchHeadLevel - Job performance data per indexer handoff timeSearchHeadLevel - KVStore collection sizeSearchHeadLevel - Savedsearches with schedules and no next_scheduled_time
Updated alerts:
AllSplunkEnterpriseLevel - Splunkd Log Messages Admins Only- search updatesAllSplunkEnterpriseLevel - Email Sending Failures- added app contextIndexerLevel - These Indexes Are Approaching The warmDBCount limit- added datatype=all argumentIndexerLevel - Cold data location approaching size limits- added datatype=all argumentIndexerLevel - Unclean Shutdown - Fsck- added datatype=all argumentSearchHeadLevel - Peer timeouts or authentication issues- updates to use Splunkd sourceSearchHeadLevel - Splunk alert actions exceeding the max_action_results limit- excluded summary indexingSearchHeadLevel - Scheduled Searches without a configured earliest and latest time- rewrote search for efficiencySearchHeadLevel - Search Messages user level- search updatesSearchHeadLevel - Search Messages admins only- search updates
Updated dashboards:
splunk_forwarder_output_tuning- updated comments, removed heartbeatFrequency
Updated macros:
search_type_from_sid- minor tweaks to regex
Updated reports:
SearchHeadLevel - indexes per savedsearch- corrected typo on multisearch, re-wrote parts of the query to include subsearches as wellSearchHeadLevel - Indexes for savedsearch without subsearches- corrected typo on multisearchSearchHeadLevel - Search Queries summary non-exact match- added delim for index IN (a b c), corrected typo on multisearch, updated description to link to https://github.com/TheWoodRanger/presentation-conf_24_audittrail_native_telemetrySearchHeadLevel - Search Queries summary exact match- added delim for index IN (a b c), corrected typo on multisearch, updated description to link to https://github.com/TheWoodRanger/presentation-conf_24_audittrail_native_telemetry
Also updated the navigation menu.