<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cannot Disable Health Report Features in 8.2.2 in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/Cannot-Disable-Health-Report-Features-in-8-2-2/m-p/612093#M13824</link>
    <description>&lt;P&gt;Did you manage to resolve this issue?&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;You need to change the thresholds, or disable iowait, on each enterprise instance. See Answers&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://community.splunk.com/t5/Splunk-Enterprise/Where-do-I-configure-the-health-conf-so-that-I-can-disable-the/m-p/596827" target="_blank" rel="noopener"&gt;https://community.splunk.com/t5/Splunk-Enterprise/Where-do-I-configure-the-health-conf-so-that-I-can...&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 06 Sep 2022 12:09:21 GMT</pubDate>
    <dc:creator>pellegrini</dc:creator>
    <dc:date>2022-09-06T12:09:21Z</dc:date>
    <item>
      <title>Cannot Disable Health Report Features in 8.2.2</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Cannot-Disable-Health-Report-Features-in-8-2-2/m-p/564366#M9779</link>
      <description>&lt;P&gt;I am not sure if anyone else has encountered this, but in our distributed environment that was just upgraded from 8.0.3 to 8.2.2, we have noticed issues with the health report manager.&amp;nbsp; The new IOWait feature in the health report is extremely "chatty" even though all other aspects of the deployment are in great shape.&amp;nbsp; Even though we can successfully disable the IOWait feature in the console and via a local health.conf file, the feature is still being included in the health report.&amp;nbsp; I've opened up a case with Splunk support, but was just wondering if anyone else has encountered this behavior.&lt;/P&gt;</description>
      <pubDate>Mon, 23 Aug 2021 15:02:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Cannot-Disable-Health-Report-Features-in-8-2-2/m-p/564366#M9779</guid>
      <dc:creator>kisstian</dc:creator>
      <dc:date>2021-08-23T15:02:55Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot Disable Health Report Features in 8.2.2</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Cannot-Disable-Health-Report-Features-in-8-2-2/m-p/567166#M9988</link>
      <description>&lt;P&gt;Just in case anyone else experiences this issue, what I did to resolve it was disable the distributed health report which is enabled by default in 8.2.&amp;nbsp; Once done, I was able to successfully disable the feature&amp;nbsp; in the health report manager.&lt;/P&gt;</description>
      <pubDate>Wed, 15 Sep 2021 22:40:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Cannot-Disable-Health-Report-Features-in-8-2-2/m-p/567166#M9988</guid>
      <dc:creator>kisstian</dc:creator>
      <dc:date>2021-09-15T22:40:28Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot Disable Health Report Features in 8.2.2</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Cannot-Disable-Health-Report-Features-in-8-2-2/m-p/569697#M10228</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/8.2.2/DMC/Aboutfeaturemonitoring" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/8.2.2/DMC/Aboutfeaturemonitoring &lt;/A&gt;: "&lt;SPAN&gt;By default, the distributed health report is disabled." do you speak about same setting?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 05 Oct 2021 13:12:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Cannot-Disable-Health-Report-Features-in-8-2-2/m-p/569697#M10228</guid>
      <dc:creator>splunkreal</dc:creator>
      <dc:date>2021-10-05T13:12:19Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot Disable Health Report Features in 8.2.2</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Cannot-Disable-Health-Report-Features-in-8-2-2/m-p/569701#M10230</link>
      <description>&lt;P&gt;Yes, that is what I was talking about.&amp;nbsp; Even though the documentation indicates that the distributed report is disabled by default, I noticed in my environment that after upgrading from 8.0.3 to 8.2.2, the feature was enabled everywhere.&lt;/P&gt;</description>
      <pubDate>Tue, 05 Oct 2021 13:23:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Cannot-Disable-Health-Report-Features-in-8-2-2/m-p/569701#M10230</guid>
      <dc:creator>kisstian</dc:creator>
      <dc:date>2021-10-05T13:23:09Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot Disable Health Report Features in 8.2.2</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Cannot-Disable-Health-Report-Features-in-8-2-2/m-p/569703#M10231</link>
      <description>&lt;P&gt;Thanks it works, did you log support case regarding this?&lt;/P&gt;&lt;P&gt;Also this surely removes lots of interesting features...&lt;/P&gt;</description>
      <pubDate>Tue, 05 Oct 2021 13:41:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Cannot-Disable-Health-Report-Features-in-8-2-2/m-p/569703#M10231</guid>
      <dc:creator>splunkreal</dc:creator>
      <dc:date>2021-10-05T13:41:08Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot Disable Health Report Features in 8.2.2</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Cannot-Disable-Health-Report-Features-in-8-2-2/m-p/569750#M10240</link>
      <description>&lt;P&gt;I noticed the same thing upon upgrading to 8.2.2 with IOWait.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I had to disable the IOWait health check on the Search Head and also on the Indexers, but it sounds like disabling the&amp;nbsp;&lt;SPAN&gt;distributed health report would be a better solution.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 05 Oct 2021 18:00:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Cannot-Disable-Health-Report-Features-in-8-2-2/m-p/569750#M10240</guid>
      <dc:creator>brad_thomas</dc:creator>
      <dc:date>2021-10-05T18:00:00Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot Disable Health Report Features in 8.2.2</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Cannot-Disable-Health-Report-Features-in-8-2-2/m-p/569868#M10248</link>
      <description>&lt;P&gt;Excellent, I am glad I was able to assist.&amp;nbsp; I did open a ticket and included this information within it.&lt;/P&gt;</description>
      <pubDate>Wed, 06 Oct 2021 12:25:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Cannot-Disable-Health-Report-Features-in-8-2-2/m-p/569868#M10248</guid>
      <dc:creator>kisstian</dc:creator>
      <dc:date>2021-10-06T12:25:59Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot Disable Health Report Features in 8.2.2</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Cannot-Disable-Health-Report-Features-in-8-2-2/m-p/569870#M10249</link>
      <description>&lt;P&gt;Nice good, please keep us updated!&lt;/P&gt;</description>
      <pubDate>Wed, 06 Oct 2021 12:35:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Cannot-Disable-Health-Report-Features-in-8-2-2/m-p/569870#M10249</guid>
      <dc:creator>splunkreal</dc:creator>
      <dc:date>2021-10-06T12:35:55Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot Disable Health Report Features in 8.2.2</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Cannot-Disable-Health-Report-Features-in-8-2-2/m-p/572609#M10476</link>
      <description>&lt;P&gt;I also found this issue on 8.2.2.1, and Splunk is tracking this on&amp;nbsp;SPL-213405.&lt;/P&gt;&lt;P&gt;My issue is that I disable IOWait and Buckets health check on the Search Heads, but as long as search peers report issues with these features, they'll still show up. Except if we disable&amp;nbsp;&lt;SPAN&gt;distributed health report, but then we lose visibility on a lot of other health checks.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;And apparently, the documentation now reports that&amp;nbsp;&lt;SPAN&gt;distributed health report is enabled by default.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 27 Oct 2021 09:31:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Cannot-Disable-Health-Report-Features-in-8-2-2/m-p/572609#M10476</guid>
      <dc:creator>nunoaragao</dc:creator>
      <dc:date>2021-10-27T09:31:06Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot Disable Health Report Features in 8.2.2</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Cannot-Disable-Health-Report-Features-in-8-2-2/m-p/574425#M10663</link>
      <description>&lt;P&gt;Thanks to you all for reporting this. We experienced the same issue in our upgrade from 8.0.3 to 8.2.2.1. Our Splunk support contact confirmed they're aware of it, and for now we're hoping for a expeditious resolution rather than disabling reporting on it.&lt;/P&gt;&lt;P&gt;Question for &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/31038"&gt;@nunoaragao&lt;/a&gt;,&amp;nbsp;is there a public page where we can track the status of SPL-213405? I was hoping it was a public bug report, but not being able to find it with Google, I gather that's the ticket number for the case you opened with support?&lt;/P&gt;</description>
      <pubDate>Wed, 10 Nov 2021 15:16:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Cannot-Disable-Health-Report-Features-in-8-2-2/m-p/574425#M10663</guid>
      <dc:creator>samjenk_2</dc:creator>
      <dc:date>2021-11-10T15:16:11Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot Disable Health Report Features in 8.2.2</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Cannot-Disable-Health-Report-Features-in-8-2-2/m-p/574432#M10665</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/183909"&gt;@samjenk_2&lt;/a&gt;&amp;nbsp;, my case(s) with Splunk Support were #2733102 and #2737559 ..&amp;nbsp;&lt;SPAN&gt;SPL-213405 is Splunk's internal JIRA to track this issue. It may, or not, then show up on Splunk's release notes as known issue. It's still being investigated. If you deal with Support you can ask to link with it.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;My issue is that &lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/DMC/Configurefeaturemonitoring#Disable_a_feature" target="_blank" rel="noopener"&gt;Docs&amp;nbsp;&lt;/A&gt;say "&lt;SPAN&gt;You can disable any feature (...)&amp;nbsp;for example, if you want to exclude a feature's status from the health report". So we expect to be able to disable a specific feature (i.e. Buckets) without requiring to disable&amp;nbsp;distributed_health_reporter, which would also disable/hide a lot of other features if we're on a typical topology where we have search head clusters and clustered indexers. In other words, tell the Search Head to gray out a Indexer peer feature even if that peer is reporting health.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;It matches your scenario ?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 10 Nov 2021 15:39:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Cannot-Disable-Health-Report-Features-in-8-2-2/m-p/574432#M10665</guid>
      <dc:creator>nunoaragao</dc:creator>
      <dc:date>2021-11-10T15:39:50Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot Disable Health Report Features in 8.2.2</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Cannot-Disable-Health-Report-Features-in-8-2-2/m-p/574553#M10680</link>
      <description>&lt;P&gt;Just got an answer from Splunk Support,&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/69457"&gt;@kisstian&lt;/a&gt;&amp;nbsp; /&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/183909"&gt;@samjenk_2&lt;/a&gt;&amp;nbsp; / everyone&lt;/P&gt;&lt;P&gt;Splunk have now updated their documentation regarding &lt;A href="https://docs.splunk.com/Documentation/Splunk/8.2.3/DMC/Configurefeaturemonitoring#Disable_a_feature" target="_blank" rel="noopener"&gt;disable health report features&lt;/A&gt;.&lt;BR /&gt;It states in a box:&lt;/P&gt;&lt;LI-CODE lang="css"&gt;If distributed health reporting is enabled for your deployment, disabling a feature on the local instance will not be reflected in the health report.&lt;/LI-CODE&gt;&lt;P&gt;It seems, the workaround to disable a feature in +8.2 has just became a feature. The old behavior in +8.1 in which you could disable a single feature regardless of distributed health report has been "improved"&lt;/P&gt;&lt;P&gt;If anyone submits an Idea to bring the old behavior back, let me know. You get my vote.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 11 Nov 2021 12:16:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Cannot-Disable-Health-Report-Features-in-8-2-2/m-p/574553#M10680</guid>
      <dc:creator>nunoaragao</dc:creator>
      <dc:date>2021-11-11T12:16:56Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot Disable Health Report Features in 8.2.2</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Cannot-Disable-Health-Report-Features-in-8-2-2/m-p/575009#M10715</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;looks like documentation has been updated :&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/Splunk/8.2.2/DMC/Aboutfeaturemonitoring" target="_blank" rel="noopener"&gt;https://docs.splunk.com/Documentation/Splunk/8.2.2/DMC/Aboutfeaturemonitoring&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;"By default, the distributed health report is enabled (set to&amp;nbsp;&lt;/SPAN&gt;disabled = 0&lt;SPAN&gt;) in&amp;nbsp;&lt;/SPAN&gt;health.conf"&lt;/P&gt;</description>
      <pubDate>Tue, 16 Nov 2021 08:50:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Cannot-Disable-Health-Report-Features-in-8-2-2/m-p/575009#M10715</guid>
      <dc:creator>splunkreal</dc:creator>
      <dc:date>2021-11-16T08:50:43Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot Disable Health Report Features in 8.2.2</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Cannot-Disable-Health-Report-Features-in-8-2-2/m-p/575646#M10767</link>
      <description>&lt;P&gt;Thanks for the ticket references, &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/31038"&gt;@nunoaragao&lt;/a&gt;.&amp;nbsp;I just heard from our Splunk administrator that Splunk has gotten back to him on this matter. With the caveat that your Splunk deployment (and the deployment of others) may be different from ours, they told us that the IOWait thresholds were simply set too aggressively, and that we can either disable the health report like others are doing, or tune the IOWait thresholds in health.conf, as described here:&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/8.2.3/DMC/Configurefeaturemonitoring" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/8.2.3/DMC/Configurefeaturemonitoring&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Disappointingly, it looks like the example health.conf file in Splunk's online documentation [1] doesn't include a description of the iowait feature stanza, but it's reasonably documented in the file $SPLUNK/etc/system/default/health.conf. There are several different metrics tracked in this feature, and in our file, they all have to do with CPU utilization (I would have thought disc I/O).&lt;/P&gt;&lt;P&gt;Personally, I'm inclined to monitor CPU utilization with other tools to work out what an typical load is like for these metrics, and adjust the thresholds accordingly. Or maybe disable the IOWait feature, but leave the rest of the health features enabled.&lt;/P&gt;&lt;P&gt;[1] &lt;A href="https://docs.splunk.com/Documentation/Splunk/8.2.3/Admin/Healthconf#health.conf.example" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/8.2.3/Admin/Healthconf#health.conf.example&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 19 Nov 2021 14:35:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Cannot-Disable-Health-Report-Features-in-8-2-2/m-p/575646#M10767</guid>
      <dc:creator>samjenk_2</dc:creator>
      <dc:date>2021-11-19T14:35:58Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot Disable Health Report Features in 8.2.2</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Cannot-Disable-Health-Report-Features-in-8-2-2/m-p/575684#M10771</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/183909"&gt;@samjenk_2&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;These are the events used to toggle health colours in Splunk's Health Report.&lt;BR /&gt;So we get to know what are the typical values, and in which servers.&lt;/P&gt;&lt;LI-CODE lang="python"&gt;index=_introspection sourcetype=splunk_resource_usage component=IOWait &lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 19 Nov 2021 16:29:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Cannot-Disable-Health-Report-Features-in-8-2-2/m-p/575684#M10771</guid>
      <dc:creator>nunoaragao</dc:creator>
      <dc:date>2021-11-19T16:29:57Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot Disable Health Report Features in 8.2.2</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Cannot-Disable-Health-Report-Features-in-8-2-2/m-p/612093#M13824</link>
      <description>&lt;P&gt;Did you manage to resolve this issue?&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;You need to change the thresholds, or disable iowait, on each enterprise instance. See Answers&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://community.splunk.com/t5/Splunk-Enterprise/Where-do-I-configure-the-health-conf-so-that-I-can-disable-the/m-p/596827" target="_blank" rel="noopener"&gt;https://community.splunk.com/t5/Splunk-Enterprise/Where-do-I-configure-the-health-conf-so-that-I-can...&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 06 Sep 2022 12:09:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Cannot-Disable-Health-Report-Features-in-8-2-2/m-p/612093#M13824</guid>
      <dc:creator>pellegrini</dc:creator>
      <dc:date>2022-09-06T12:09:21Z</dc:date>
    </item>
  </channel>
</rss>

