<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk Restart Tracking in Dashboards &amp; Visualizations</title>
    <link>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-Restart-Tracking/m-p/394385#M41656</link>
    <description>&lt;P&gt;Thanks, these queries all work&lt;/P&gt;

&lt;P&gt;except for&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;splunkShuttingDown
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;which is not a thing, at least in 7.2.0&lt;/P&gt;</description>
    <pubDate>Thu, 02 Jan 2020 20:21:36 GMT</pubDate>
    <dc:creator>nick405060</dc:creator>
    <dc:date>2020-01-02T20:21:36Z</dc:date>
    <item>
      <title>Splunk Restart Tracking</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-Restart-Tracking/m-p/394380#M41651</link>
      <description>&lt;P&gt;Hi folks,&lt;/P&gt;

&lt;P&gt;I want to setup a dashboard to track Splunk activities. I need to know how to track who restarted Splunk via both UI and audit logs in Splunk Dashboard?&lt;/P&gt;

&lt;P&gt;Thanks in-advance.&lt;/P&gt;</description>
      <pubDate>Wed, 09 May 2018 15:32:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-Restart-Tracking/m-p/394380#M41651</guid>
      <dc:creator>mbasharat</dc:creator>
      <dc:date>2018-05-09T15:32:43Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Restart Tracking</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-Restart-Tracking/m-p/394381#M41652</link>
      <description>&lt;P&gt;hello there,&lt;/P&gt;

&lt;P&gt;check the _internal index for &lt;CODE&gt;"splunkd started"&lt;/CODE&gt; or &lt;CODE&gt;"(build"&lt;/CODE&gt;&lt;BR /&gt;
many answers here about that, here are couple examples:&lt;BR /&gt;
&lt;A href="https://answers.splunk.com/answers/242618/how-to-count-the-number-of-times-splunk-is-restart.html"&gt;https://answers.splunk.com/answers/242618/how-to-count-the-number-of-times-splunk-is-restart.html&lt;/A&gt;&lt;BR /&gt;
&lt;A href="https://answers.splunk.com/answers/105128/how-to-determine-how-long-splunk-has-been-up.html"&gt;https://answers.splunk.com/answers/105128/how-to-determine-how-long-splunk-has-been-up.html&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;hope it helps&lt;/P&gt;</description>
      <pubDate>Wed, 09 May 2018 15:42:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-Restart-Tracking/m-p/394381#M41652</guid>
      <dc:creator>adonio</dc:creator>
      <dc:date>2018-05-09T15:42:32Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Restart Tracking</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-Restart-Tracking/m-p/394382#M41653</link>
      <description>&lt;P&gt;Thanks Adonio, is there a way to populate them in a clean list from events. I see my own name in that event and I never started it!&lt;/P&gt;</description>
      <pubDate>Wed, 09 May 2018 18:09:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-Restart-Tracking/m-p/394382#M41653</guid>
      <dc:creator>mbasharat</dc:creator>
      <dc:date>2018-05-09T18:09:15Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Restart Tracking</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-Restart-Tracking/m-p/394383#M41654</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/86891"&gt;@mbasharat&lt;/a&gt;&lt;/P&gt;

&lt;P&gt;Please use these searches&lt;/P&gt;

&lt;P&gt;index=_audit  action=restart_splunkd | stats c by user&lt;BR /&gt;
index=_audit action=splunkStarting&lt;BR /&gt;
index=_audit action=splunkShuttingDown&lt;/P&gt;

&lt;P&gt;for UI restart its writes in Splunkd_stdout.log &lt;/P&gt;

&lt;P&gt;index=_internal  sourcetype=splunkd_stdout&lt;/P&gt;

&lt;P&gt;Thanks &lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 19:30:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-Restart-Tracking/m-p/394383#M41654</guid>
      <dc:creator>PowerPacked</dc:creator>
      <dc:date>2020-09-29T19:30:38Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Restart Tracking</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-Restart-Tracking/m-p/394384#M41655</link>
      <description>&lt;P&gt;THANK YOU!!&lt;/P&gt;</description>
      <pubDate>Thu, 10 May 2018 01:17:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-Restart-Tracking/m-p/394384#M41655</guid>
      <dc:creator>mbasharat</dc:creator>
      <dc:date>2018-05-10T01:17:02Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Restart Tracking</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-Restart-Tracking/m-p/394385#M41656</link>
      <description>&lt;P&gt;Thanks, these queries all work&lt;/P&gt;

&lt;P&gt;except for&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;splunkShuttingDown
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;which is not a thing, at least in 7.2.0&lt;/P&gt;</description>
      <pubDate>Thu, 02 Jan 2020 20:21:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-Restart-Tracking/m-p/394385#M41656</guid>
      <dc:creator>nick405060</dc:creator>
      <dc:date>2020-01-02T20:21:36Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Restart Tracking</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-Restart-Tracking/m-p/394386#M41657</link>
      <description>&lt;P&gt;Splunk Restart Dashboard&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;&amp;lt;form theme="dark"&amp;gt;
  &amp;lt;label&amp;gt;Splunk Restarts&amp;lt;/label&amp;gt;
  &amp;lt;fieldset submitButton="false"&amp;gt;
    &amp;lt;input type="time" token="time" searchWhenChanged="true"&amp;gt;
      &amp;lt;label&amp;gt;Time Range&amp;lt;/label&amp;gt;
      &amp;lt;default&amp;gt;
        &amp;lt;earliest&amp;gt;-24h@h&amp;lt;/earliest&amp;gt;
        &amp;lt;latest&amp;gt;now&amp;lt;/latest&amp;gt;
      &amp;lt;/default&amp;gt;
    &amp;lt;/input&amp;gt;
    &amp;lt;input type="text" token="host_include_pattern" searchWhenChanged="true"&amp;gt;
      &amp;lt;label&amp;gt;Host Include Pattern (host1,host2)&amp;lt;/label&amp;gt;
      &amp;lt;initialValue&amp;gt;*&amp;lt;/initialValue&amp;gt;
    &amp;lt;/input&amp;gt;
    &amp;lt;input type="text" token="host_exclude_pattern" searchWhenChanged="true"&amp;gt;
      &amp;lt;label&amp;gt;Host Exclude Pattern&amp;lt;/label&amp;gt;
      &amp;lt;default&amp;gt;null&amp;lt;/default&amp;gt;
      &amp;lt;prefix&amp;gt;NOT host="*&amp;lt;/prefix&amp;gt;
      &amp;lt;suffix&amp;gt;*"&amp;lt;/suffix&amp;gt;
    &amp;lt;/input&amp;gt;
  &amp;lt;/fieldset&amp;gt;
  &amp;lt;row&amp;gt;
    &amp;lt;panel&amp;gt;
      &amp;lt;title&amp;gt;Unique Instance Restarts&amp;lt;/title&amp;gt;
      &amp;lt;single&amp;gt;
        &amp;lt;search&amp;gt;
          &amp;lt;query&amp;gt;index=_internal sourcetype=splunkd source="*splunkd.log" "Splunkd starting" host IN ($host_include_pattern$) $host_exclude_pattern$ 
|  stats dc(host)&amp;lt;/query&amp;gt;
          &amp;lt;earliest&amp;gt;$time.earliest$&amp;lt;/earliest&amp;gt;
          &amp;lt;latest&amp;gt;$time.latest$&amp;lt;/latest&amp;gt;
          &amp;lt;sampleRatio&amp;gt;1&amp;lt;/sampleRatio&amp;gt;
          &amp;lt;refresh&amp;gt;30s&amp;lt;/refresh&amp;gt;
          &amp;lt;refreshType&amp;gt;delay&amp;lt;/refreshType&amp;gt;
        &amp;lt;/search&amp;gt;
        &amp;lt;option name="colorMode"&amp;gt;block&amp;lt;/option&amp;gt;
        &amp;lt;option name="drilldown"&amp;gt;none&amp;lt;/option&amp;gt;
        &amp;lt;option name="rangeColors"&amp;gt;["0x6db7c6","0x6db7c6"]&amp;lt;/option&amp;gt;
        &amp;lt;option name="rangeValues"&amp;gt;[0]&amp;lt;/option&amp;gt;
        &amp;lt;option name="refresh.display"&amp;gt;progressbar&amp;lt;/option&amp;gt;
        &amp;lt;option name="trellis.enabled"&amp;gt;0&amp;lt;/option&amp;gt;
        &amp;lt;option name="trellis.scales.shared"&amp;gt;1&amp;lt;/option&amp;gt;
        &amp;lt;option name="trellis.size"&amp;gt;medium&amp;lt;/option&amp;gt;
        &amp;lt;option name="useColors"&amp;gt;1&amp;lt;/option&amp;gt;
      &amp;lt;/single&amp;gt;
    &amp;lt;/panel&amp;gt;
  &amp;lt;/row&amp;gt;
  &amp;lt;row&amp;gt;
    &amp;lt;panel&amp;gt;
      &amp;lt;title&amp;gt;Host Restart Timeline&amp;lt;/title&amp;gt;
      &amp;lt;chart&amp;gt;
        &amp;lt;search&amp;gt;
          &amp;lt;query&amp;gt;index=_internal sourcetype=splunkd source="*splunkd.log" "Splunkd starting" host IN ($host_include_pattern$) $host_exclude_pattern$ 
| timechart limit=100 count by host&amp;lt;/query&amp;gt;
          &amp;lt;earliest&amp;gt;$time.earliest$&amp;lt;/earliest&amp;gt;
          &amp;lt;latest&amp;gt;$time.latest$&amp;lt;/latest&amp;gt;
          &amp;lt;sampleRatio&amp;gt;1&amp;lt;/sampleRatio&amp;gt;
          &amp;lt;refresh&amp;gt;30s&amp;lt;/refresh&amp;gt;
          &amp;lt;refreshType&amp;gt;delay&amp;lt;/refreshType&amp;gt;
        &amp;lt;/search&amp;gt;
        &amp;lt;option name="charting.axisLabelsX.majorLabelStyle.overflowMode"&amp;gt;ellipsisNone&amp;lt;/option&amp;gt;
        &amp;lt;option name="charting.axisLabelsX.majorLabelStyle.rotation"&amp;gt;0&amp;lt;/option&amp;gt;
        &amp;lt;option name="charting.axisTitleX.visibility"&amp;gt;visible&amp;lt;/option&amp;gt;
        &amp;lt;option name="charting.axisTitleY.visibility"&amp;gt;collapsed&amp;lt;/option&amp;gt;
        &amp;lt;option name="charting.axisTitleY2.visibility"&amp;gt;visible&amp;lt;/option&amp;gt;
        &amp;lt;option name="charting.axisX.scale"&amp;gt;linear&amp;lt;/option&amp;gt;
        &amp;lt;option name="charting.axisY.scale"&amp;gt;linear&amp;lt;/option&amp;gt;
        &amp;lt;option name="charting.axisY2.enabled"&amp;gt;0&amp;lt;/option&amp;gt;
        &amp;lt;option name="charting.axisY2.scale"&amp;gt;inherit&amp;lt;/option&amp;gt;
        &amp;lt;option name="charting.chart"&amp;gt;column&amp;lt;/option&amp;gt;
        &amp;lt;option name="charting.chart.bubbleMaximumSize"&amp;gt;50&amp;lt;/option&amp;gt;
        &amp;lt;option name="charting.chart.bubbleMinimumSize"&amp;gt;10&amp;lt;/option&amp;gt;
        &amp;lt;option name="charting.chart.bubbleSizeBy"&amp;gt;area&amp;lt;/option&amp;gt;
        &amp;lt;option name="charting.chart.nullValueMode"&amp;gt;gaps&amp;lt;/option&amp;gt;
        &amp;lt;option name="charting.chart.showDataLabels"&amp;gt;none&amp;lt;/option&amp;gt;
        &amp;lt;option name="charting.chart.sliceCollapsingThreshold"&amp;gt;0.01&amp;lt;/option&amp;gt;
        &amp;lt;option name="charting.chart.stackMode"&amp;gt;stacked&amp;lt;/option&amp;gt;
        &amp;lt;option name="charting.chart.style"&amp;gt;shiny&amp;lt;/option&amp;gt;
        &amp;lt;option name="charting.drilldown"&amp;gt;none&amp;lt;/option&amp;gt;
        &amp;lt;option name="charting.layout.splitSeries"&amp;gt;0&amp;lt;/option&amp;gt;
        &amp;lt;option name="charting.layout.splitSeries.allowIndependentYRanges"&amp;gt;0&amp;lt;/option&amp;gt;
        &amp;lt;option name="charting.legend.labelStyle.overflowMode"&amp;gt;ellipsisMiddle&amp;lt;/option&amp;gt;
        &amp;lt;option name="charting.legend.placement"&amp;gt;bottom&amp;lt;/option&amp;gt;
        &amp;lt;option name="refresh.display"&amp;gt;progressbar&amp;lt;/option&amp;gt;
        &amp;lt;option name="trellis.enabled"&amp;gt;0&amp;lt;/option&amp;gt;
        &amp;lt;option name="trellis.scales.shared"&amp;gt;1&amp;lt;/option&amp;gt;
        &amp;lt;option name="trellis.size"&amp;gt;medium&amp;lt;/option&amp;gt;
      &amp;lt;/chart&amp;gt;
    &amp;lt;/panel&amp;gt;
  &amp;lt;/row&amp;gt;
  &amp;lt;row&amp;gt;
    &amp;lt;panel&amp;gt;
      &amp;lt;title&amp;gt;Events&amp;lt;/title&amp;gt;
      &amp;lt;table&amp;gt;
        &amp;lt;search&amp;gt;
          &amp;lt;query&amp;gt;index=_internal sourcetype=splunkd source="*splunkd.log" "Splunkd starting" host IN ($host_include_pattern$) $host_exclude_pattern$ 
| bucket _time span=5m 
| table _time host _raw 
| sort -_time 
| transaction _time 
| table _time host _raw&amp;lt;/query&amp;gt;
          &amp;lt;earliest&amp;gt;$time.earliest$&amp;lt;/earliest&amp;gt;
          &amp;lt;latest&amp;gt;$time.latest$&amp;lt;/latest&amp;gt;
          &amp;lt;sampleRatio&amp;gt;1&amp;lt;/sampleRatio&amp;gt;
          &amp;lt;refresh&amp;gt;30s&amp;lt;/refresh&amp;gt;
          &amp;lt;refreshType&amp;gt;delay&amp;lt;/refreshType&amp;gt;
        &amp;lt;/search&amp;gt;
        &amp;lt;option name="count"&amp;gt;20&amp;lt;/option&amp;gt;
        &amp;lt;option name="drilldown"&amp;gt;none&amp;lt;/option&amp;gt;
        &amp;lt;option name="refresh.display"&amp;gt;progressbar&amp;lt;/option&amp;gt;
      &amp;lt;/table&amp;gt;
    &amp;lt;/panel&amp;gt;
  &amp;lt;/row&amp;gt;
&amp;lt;/form&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Fri, 03 Jan 2020 02:05:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-Restart-Tracking/m-p/394386#M41657</guid>
      <dc:creator>bandit</dc:creator>
      <dc:date>2020-01-03T02:05:05Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Restart Tracking</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-Restart-Tracking/m-p/519705#M41658</link>
      <description>Nice. Thanks!</description>
      <pubDate>Tue, 15 Sep 2020 14:22:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-Restart-Tracking/m-p/519705#M41658</guid>
      <dc:creator>_smp_</dc:creator>
      <dc:date>2020-09-15T14:22:12Z</dc:date>
    </item>
  </channel>
</rss>

