All Apps and Add-ons

Splunk for k8s - please review savedsearches.conf and add default time range constraints

guilmxm
Influencer

Hello,

Reviewing the new Splunk for k8s addon, you could please review the savedsearches.conf and add a minimal default earliest and latest timerange to the searches ?

For example:

dispatch.earliest_time = -24h
dispatch.latest_time = now

Currently the searches will run over All time by default since only the search definition exist on a per stanza statement.
That is not good practices for customers.

Kind regards,

Guilhem

0 Karma
1 Solution

mattymo
Splunk Employee
Splunk Employee

Hey Guilmxm!

Thanks for pointing this out. I provided the same feedback and am working with the team to clean up :).

Will report back once it is done. Also feel free to provide any other feedback you might have!

Matt

- MattyMo

View solution in original post

0 Karma

mattymo
Splunk Employee
Splunk Employee

Hey Guilmxm!

Thanks for pointing this out. I provided the same feedback and am working with the team to clean up :).

Will report back once it is done. Also feel free to provide any other feedback you might have!

Matt

- MattyMo
0 Karma
Get Updates on the Splunk Community!

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...

September Community Champions: A Shoutout to Our Contributors!

As we close the books on another fantastic month, we want to take a moment to celebrate the people who are the ...

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...