<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic New Splunk Assist Logging is Undocumented in Monitoring Splunk</title>
    <link>https://community.splunk.com/t5/Monitoring-Splunk/New-Splunk-Assist-Logging-is-Undocumented/m-p/603027#M8987</link>
    <description>&lt;P&gt;After install of a new Enterprise 9.0 instance, there's a&amp;nbsp;&lt;EM&gt;lot&lt;/EM&gt; of new logging appearing in _internal.&lt;/P&gt;&lt;P&gt;Notably, this log line is being generated every 15 seconds and there's no clear indication in documentation how to disable it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;2022-06-23 09:25:05,957 INFO [assist::supervisor_modular_input.py] [context] [build_supervisor_secrets] [4932] Secret load failed, key=tenant_id, error=[HTTP 404] https://127.0.0.1:8090/servicesNS/nobody/splunk_assist/storage/passwords/tenant_id?output_mode=json&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;source = D:\Splunk\var\log\splunk\splunk_assist_supervisor_modular_input.log&lt;BR /&gt;sourcetype = splunk_assist_uiassets_modular_input.log*&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;This is a substantial increase in overall volume of logs with "error" in them, not to mention the rest of the logging related to these new "assist supervisor" processes.&amp;nbsp;&lt;BR /&gt;&lt;EM&gt;splunkd.log&lt;/EM&gt; is flooded with messages from&amp;nbsp;&lt;EM&gt;instance_id_modular_input.py&lt;/EM&gt; executing.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The Splunk Assist documentation (&lt;A href="https://docs.splunk.com/Documentation/Splunk/9.0.0/DMC/AssistIntro" target="_blank" rel="noopener"&gt;https://docs.splunk.com/Documentation/Splunk/9.0.0/DMC/AssistIntro&lt;/A&gt;) has no information on how to adjust the log level or disable specific components.&lt;/P&gt;&lt;P&gt;This is on an instance *without* a Splunk Assist activation code installed, meaning this is generating at this volume out-of-box.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It's incredibly frustrating that searching this log file name "splunk_assist_uiassets_modular_input.log" returns 0 results in all of Splunk Docs.&lt;/P&gt;&lt;P&gt;How is this useful if there's no information on what to do with it, and why am I paying more for Cloud Compute to ingest all this additional volume without any instruction for how to configure it?&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Any assistance in finding relevant documentation would be appreciated.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Edit&lt;/STRONG&gt;: There's a new .conf file for this -&amp;nbsp;&lt;EM&gt;assist.conf&lt;/EM&gt; - that is completely undocumented. Nothing in the configuration file reference doc page.&lt;BR /&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/9.0.0/Admin/assistconf" target="_blank" rel="noopener"&gt;https://docs.splunk.com/Documentation/Splunk/9.0.0/Admin/assistconf&lt;/A&gt;&lt;/P&gt;&lt;P&gt;The inputs generating all this extra logging are located in &lt;EM&gt;$SPLUNK_HOME/etc/apps/splunk_assist&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;Until more information becomes available, I've disabled them:&lt;/P&gt;&lt;PRE&gt;[supervisor_modular_input://default]
disabled = 1

[instance_id_modular_input://default]
disabled = 1

[uiassets_modular_input://default]
disabled = 1

[selfupdate_modular_input://default]
disabled = 1&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 23 Jun 2022 14:58:39 GMT</pubDate>
    <dc:creator>TheWoodRanger</dc:creator>
    <dc:date>2022-06-23T14:58:39Z</dc:date>
    <item>
      <title>New Splunk Assist Logging is Undocumented</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/New-Splunk-Assist-Logging-is-Undocumented/m-p/603027#M8987</link>
      <description>&lt;P&gt;After install of a new Enterprise 9.0 instance, there's a&amp;nbsp;&lt;EM&gt;lot&lt;/EM&gt; of new logging appearing in _internal.&lt;/P&gt;&lt;P&gt;Notably, this log line is being generated every 15 seconds and there's no clear indication in documentation how to disable it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;2022-06-23 09:25:05,957 INFO [assist::supervisor_modular_input.py] [context] [build_supervisor_secrets] [4932] Secret load failed, key=tenant_id, error=[HTTP 404] https://127.0.0.1:8090/servicesNS/nobody/splunk_assist/storage/passwords/tenant_id?output_mode=json&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;source = D:\Splunk\var\log\splunk\splunk_assist_supervisor_modular_input.log&lt;BR /&gt;sourcetype = splunk_assist_uiassets_modular_input.log*&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;This is a substantial increase in overall volume of logs with "error" in them, not to mention the rest of the logging related to these new "assist supervisor" processes.&amp;nbsp;&lt;BR /&gt;&lt;EM&gt;splunkd.log&lt;/EM&gt; is flooded with messages from&amp;nbsp;&lt;EM&gt;instance_id_modular_input.py&lt;/EM&gt; executing.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The Splunk Assist documentation (&lt;A href="https://docs.splunk.com/Documentation/Splunk/9.0.0/DMC/AssistIntro" target="_blank" rel="noopener"&gt;https://docs.splunk.com/Documentation/Splunk/9.0.0/DMC/AssistIntro&lt;/A&gt;) has no information on how to adjust the log level or disable specific components.&lt;/P&gt;&lt;P&gt;This is on an instance *without* a Splunk Assist activation code installed, meaning this is generating at this volume out-of-box.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It's incredibly frustrating that searching this log file name "splunk_assist_uiassets_modular_input.log" returns 0 results in all of Splunk Docs.&lt;/P&gt;&lt;P&gt;How is this useful if there's no information on what to do with it, and why am I paying more for Cloud Compute to ingest all this additional volume without any instruction for how to configure it?&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Any assistance in finding relevant documentation would be appreciated.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Edit&lt;/STRONG&gt;: There's a new .conf file for this -&amp;nbsp;&lt;EM&gt;assist.conf&lt;/EM&gt; - that is completely undocumented. Nothing in the configuration file reference doc page.&lt;BR /&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/9.0.0/Admin/assistconf" target="_blank" rel="noopener"&gt;https://docs.splunk.com/Documentation/Splunk/9.0.0/Admin/assistconf&lt;/A&gt;&lt;/P&gt;&lt;P&gt;The inputs generating all this extra logging are located in &lt;EM&gt;$SPLUNK_HOME/etc/apps/splunk_assist&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;Until more information becomes available, I've disabled them:&lt;/P&gt;&lt;PRE&gt;[supervisor_modular_input://default]
disabled = 1

[instance_id_modular_input://default]
disabled = 1

[uiassets_modular_input://default]
disabled = 1

[selfupdate_modular_input://default]
disabled = 1&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 23 Jun 2022 14:58:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/New-Splunk-Assist-Logging-is-Undocumented/m-p/603027#M8987</guid>
      <dc:creator>TheWoodRanger</dc:creator>
      <dc:date>2022-06-23T14:58:39Z</dc:date>
    </item>
    <item>
      <title>Re: New Splunk Assist Logging is Undocumented</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/New-Splunk-Assist-Logging-is-Undocumented/m-p/603056#M8988</link>
      <description>&lt;P&gt;Submit feedback on the docs page(s) where you think more information is needed.&lt;/P&gt;</description>
      <pubDate>Thu, 23 Jun 2022 18:03:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/New-Splunk-Assist-Logging-is-Undocumented/m-p/603056#M8988</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2022-06-23T18:03:24Z</dc:date>
    </item>
  </channel>
</rss>

