All Apps and Add-ons

Admin BEWARE! (index=* w/ accelerated datamodels)

jtrujillo
Path Finder

This app should be index=f5-* by default rather than index=*. If the default on the iApp side is f5-* .... just use that please.

This is a VERY DANGEROUS app to put into a production environment.

Please be aware that this could negatively impact your environment if installed in a vanilla state.

Owner, I can/will/want to take this down if the app is reconfigured to have a default of index=f5-*

Also, please disable the DM acceleration by default.

awillcox
Explorer

I wish I would have seen this earlier. We've been having performance issues with our system for months and they finally alleviated themselves once we disabled the this app from Splunk among other things. Considering the poor results I'm getting from trying to rely on Syslog, I may end up re-implementing this iApp.

0 Karma

gjanders
SplunkTrust
SplunkTrust

Alerts for Splunk Admins has some alerts around this but not sure if I covered data models or not 🙂
Beware of all time data models as well

0 Karma

gjanders
SplunkTrust
SplunkTrust

I believe this is part of a larger problem that Splunk does not publish a best practice list for the apps.

The app inspect program is the closest that is available currently and it does do various checks for "best practice", this app does not have the app inspect badge

Get Updates on the Splunk Community!

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer at Splunk .conf24 ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...