<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk Health Alerts after upgrade to 8.2 in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/Why-am-getting-Splunk-Health-Alerts-after-upgrade-to-8-2/m-p/606116#M13374</link>
    <description>&lt;P&gt;For more details on this issue, go to the following Splunk Answer: &lt;A href="https://community.splunk.com/t5/Splunk-Enterprise/Cannot-Disable-Health-Report-Features-in-8-2-2/m-p/564366" target="_blank" rel="noopener"&gt;https://community.splunk.com/t5/Splunk-Enterprise/Cannot-Disable-Health-Report-Features-in-8-2-2/m-p/564366&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;From &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/31038"&gt;@nunoaragao&lt;/a&gt;:&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Splunk have now updated their documentation regarding &lt;A href="https://docs.splunk.com/Documentation/Splunk/8.2.3/DMC/Configurefeaturemonitoring#Disable_a_feature" target="_blank" rel="noopener nofollow noreferrer"&gt;disable health report features&lt;/A&gt;.&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;It states in a box:&lt;/EM&gt;&lt;/P&gt;&lt;P class="lia-indent-padding-left-30px"&gt;&lt;EM&gt;"If distributed health reporting is enabled for your deployment, disabling a feature on the local instance will not be reflected in the health report."&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;It seems, the workaround to disable a feature in +8.2 has just became a feature. The old behavior in +8.1 in which you could disable a single feature regardless of distributed health report has been "improved"/&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;My case(s) with Splunk Support were #2733102 and #2737559 ..&amp;nbsp;SPL-213405 is Splunk's internal JIRA to track this issue. It may, or not, then show up on Splunk's release notes as known issue. It's still being investigated. If you deal with Support you can ask to link with it.&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;My issue is that &lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/DMC/Configurefeaturemonitoring#Disable_a_feature" target="_blank" rel="noopener nofollow noreferrer"&gt;Docs&amp;nbsp;&lt;/A&gt;say "You can disable any feature (...)&amp;nbsp;for example, if you want to exclude a feature's status from the health report". So we expect to be able to disable a specific feature (i.e. Buckets) without requiring to disable&amp;nbsp;distributed_health_reporter, which would also disable/hide a lot of other features if we're on a typical topology where we have search head clusters and clustered indexers. In other words, tell the Search Head to gray out a Indexer peer feature even if that peer is reporting health.&lt;/EM&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 19 Jul 2022 09:40:33 GMT</pubDate>
    <dc:creator>rkantamaneni</dc:creator>
    <dc:date>2022-07-19T09:40:33Z</dc:date>
    <item>
      <title>Why am getting Splunk Health Alerts after upgrade to 8.2?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Why-am-getting-Splunk-Health-Alerts-after-upgrade-to-8-2/m-p/572631#M10479</link>
      <description>&lt;P&gt;I upgraded from 7.2 to 8.0 and then 8.0 to 8.2&lt;/P&gt;
&lt;P&gt;After the upgrade to our distributed deployment, I am getting bombarded with email Health Alerts.&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;"sum_top3_cpu_percs__max_last_3m"&amp;nbsp;&amp;nbsp;is red due to the following: "Sum of 3 highest per-cpu iowaits reached red threshold of 15"&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;"avg_cpu__max_perc_last_3m"&amp;nbsp;is red due to the following: "System iowait reached red threshold of 3"&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;"single_cpu__max_perc_last_3m"&amp;nbsp;is red due to the following: "Maximum per-cpu iowait reached red threshold of 10"&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I was getting them on my Indexers yesterday but this morning it seems to be our Enterprise Security SH, our Deployment Server,&amp;nbsp; and our regular Search Head.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I am unable to disable these alerts due to our Company's policy.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;What can I do to either a.) resolve this cpu/iowait issue or b.) change the alert settings?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I don't notice a difference in performance. I'm just curious as to what's causing this CPU usage spike?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Because it seems to me - as in the example of avg cpu max percent if the CPU usage is above 3%, it is going to alert me?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 27 Jul 2022 15:15:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Why-am-getting-Splunk-Health-Alerts-after-upgrade-to-8-2/m-p/572631#M10479</guid>
      <dc:creator>Stefanie</dc:creator>
      <dc:date>2022-07-27T15:15:59Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Health Alerts after upgrade to 8.2</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Why-am-getting-Splunk-Health-Alerts-after-upgrade-to-8-2/m-p/573443#M10590</link>
      <description>&lt;P&gt;You can change them via health.conf &lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/Admin/Healthconf" target="_blank" rel="noopener"&gt;https://docs.splunk.com/Documentation/Splunk/latest/Admin/Healthconf&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I think many have found the iowait check too sensitive in 8.2...including myself&lt;/P&gt;</description>
      <pubDate>Wed, 03 Nov 2021 06:51:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Why-am-getting-Splunk-Health-Alerts-after-upgrade-to-8-2/m-p/573443#M10590</guid>
      <dc:creator>gjanders</dc:creator>
      <dc:date>2021-11-03T06:51:36Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Health Alerts after upgrade to 8.2</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Why-am-getting-Splunk-Health-Alerts-after-upgrade-to-8-2/m-p/606116#M13374</link>
      <description>&lt;P&gt;For more details on this issue, go to the following Splunk Answer: &lt;A href="https://community.splunk.com/t5/Splunk-Enterprise/Cannot-Disable-Health-Report-Features-in-8-2-2/m-p/564366" target="_blank" rel="noopener"&gt;https://community.splunk.com/t5/Splunk-Enterprise/Cannot-Disable-Health-Report-Features-in-8-2-2/m-p/564366&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;From &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/31038"&gt;@nunoaragao&lt;/a&gt;:&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Splunk have now updated their documentation regarding &lt;A href="https://docs.splunk.com/Documentation/Splunk/8.2.3/DMC/Configurefeaturemonitoring#Disable_a_feature" target="_blank" rel="noopener nofollow noreferrer"&gt;disable health report features&lt;/A&gt;.&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;It states in a box:&lt;/EM&gt;&lt;/P&gt;&lt;P class="lia-indent-padding-left-30px"&gt;&lt;EM&gt;"If distributed health reporting is enabled for your deployment, disabling a feature on the local instance will not be reflected in the health report."&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;It seems, the workaround to disable a feature in +8.2 has just became a feature. The old behavior in +8.1 in which you could disable a single feature regardless of distributed health report has been "improved"/&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;My case(s) with Splunk Support were #2733102 and #2737559 ..&amp;nbsp;SPL-213405 is Splunk's internal JIRA to track this issue. It may, or not, then show up on Splunk's release notes as known issue. It's still being investigated. If you deal with Support you can ask to link with it.&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;My issue is that &lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/DMC/Configurefeaturemonitoring#Disable_a_feature" target="_blank" rel="noopener nofollow noreferrer"&gt;Docs&amp;nbsp;&lt;/A&gt;say "You can disable any feature (...)&amp;nbsp;for example, if you want to exclude a feature's status from the health report". So we expect to be able to disable a specific feature (i.e. Buckets) without requiring to disable&amp;nbsp;distributed_health_reporter, which would also disable/hide a lot of other features if we're on a typical topology where we have search head clusters and clustered indexers. In other words, tell the Search Head to gray out a Indexer peer feature even if that peer is reporting health.&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 19 Jul 2022 09:40:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Why-am-getting-Splunk-Health-Alerts-after-upgrade-to-8-2/m-p/606116#M13374</guid>
      <dc:creator>rkantamaneni</dc:creator>
      <dc:date>2022-07-19T09:40:33Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Health Alerts after upgrade to 8.2</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Why-am-getting-Splunk-Health-Alerts-after-upgrade-to-8-2/m-p/607215#M13467</link>
      <description>&lt;P&gt;Hi there,&lt;/P&gt;&lt;P&gt;Had a similar issue with Io:Wait being way too sensitive and not being able to deactivate it.&lt;/P&gt;&lt;P&gt;Had the same answer about SPL-213405.&lt;/P&gt;&lt;P&gt;Wait and see !&lt;/P&gt;&lt;P&gt;Ema&lt;/P&gt;</description>
      <pubDate>Wed, 27 Jul 2022 15:09:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Why-am-getting-Splunk-Health-Alerts-after-upgrade-to-8-2/m-p/607215#M13467</guid>
      <dc:creator>emallinger</dc:creator>
      <dc:date>2022-07-27T15:09:26Z</dc:date>
    </item>
    <item>
      <title>Re: Why am getting Splunk Health Alerts after upgrade to 8.2?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Why-am-getting-Splunk-Health-Alerts-after-upgrade-to-8-2/m-p/612088#M13823</link>
      <description>&lt;P&gt;You can change the thresholds on each enterprise instance. Most of what is described here is locally configured on each instance. See Answers&amp;nbsp;&lt;A href="https://community.splunk.com/t5/Splunk-Enterprise/Where-do-I-configure-the-health-conf-so-that-I-can-disable-the/m-p/596827" target="_blank"&gt;https://community.splunk.com/t5/Splunk-Enterprise/Where-do-I-configure-the-health-conf-so-that-I-can-disable-the/m-p/596827&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 06 Sep 2022 11:56:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Why-am-getting-Splunk-Health-Alerts-after-upgrade-to-8-2/m-p/612088#M13823</guid>
      <dc:creator>pellegrini</dc:creator>
      <dc:date>2022-09-06T11:56:00Z</dc:date>
    </item>
  </channel>
</rss>

