Comment: Usage of dashboard is a bad practice as this adds a lot of load to splunk.
My question: How do I validate this? I want to find in what frequency are dashboards being used. Most of the time people use them occasionally.
Another team want to run these queries regularly and move them to graphite to which I disagree.
Another team at office 🙂
Take a look at the SoS app's UI and User Search Activity dashboard to get a quick view of what's being used when and how often: http://apps.splunk.com/app/748/
Thanks Martin. Will check
This query could be a start (not fine tuned)
index=_internal source=*access.log */app/* | rex "\/app\/(?<AppName>\w+)\/(?<ViewName>\w+)\"" | search AppName=* AND ViewName=* | table _time, AppName, ViewName, user
I am a Splunk admin..and the view was created by me.. but looks like when others use, I don't see it being reported.
index=internal source=access.log */app/ | rex "\/app\/(?
I will try it out.
Just a question: who is saying what? No, using dashboards is not "bad practice" because it's a vital part for many of using Splunk.