Installation

stop all users seeing a license warning message

chrispolk
Explorer

Is there a way to stop all our users from seeing the license warning messages and have only our admins see this?

Obviously the fix is to not exceed the license, but periodically we run over with new sources coming online. I dont want our less technical dashboard focussed users seeing these license warning messages. Really these messages are only relevant for our admins who can actually do something about it.

Tags (2)
0 Karma
1 Solution

RicoSuave
Builder

Hello Chris,
Unfortunately there is no way to control which users see these messages. Enhancement request 2431 has been filed to address this very issue. There is no ETA on when this will be implemented. There is one workaround. It involves removing the message module from the views your users access.

View solution in original post

gooza
Communicator

What about filtering the messages in the relevant apps with application.js as suggested in:

http://splunk-base.splunk.com/answers/3123/message-module-filter-values

0 Karma

chris_lewis
New Member

Is there any progress on this? I see errors like this at one of my sites on the search head consistently:

The running job "1366883794.12593.hostname" was canceled remotely or expired.

I would like to be able to disable the warning as multiple warnings pop up at once. Any advice on what may be causing this would also help?

0 Karma

ryancammer_kaba
New Member

use adblock and just block the element. there's some warning on my splunk instance about some pool warning, for a splunk instance that we haven't hardly used, with some warning about a pool violation, which makes no sense. i just applied the following adblock filter:

LI[class="message warn"]

and if splunk stops working, we'll just uninstall it and use nurelic instead, since we're indexing so little data.

0 Karma

RicoSuave
Builder

Hello Chris,
Unfortunately there is no way to control which users see these messages. Enhancement request 2431 has been filed to address this very issue. There is no ETA on when this will be implemented. There is one workaround. It involves removing the message module from the views your users access.

mikelanghorst
Motivator

Would be nice to be able to "acknowledge" the message so you don't constantly have it up all day.

0 Karma

RicoSuave
Builder

Yes, that is real answer. Or you can buy a bigger license 😉

0 Karma

chrispolk
Explorer

Thank you.

Ultimately we need to get better at managing the volumes.

0 Karma
Get Updates on the Splunk Community!

.conf24 | Day 0

Hello Splunk Community! My name is Chris, and I'm based in Canberra, Australia's capital, and I travelled for ...

Enhance Security Visibility with Splunk Enterprise Security 7.1 through Threat ...

 (view in My Videos)Struggling with alert fatigue, lack of context, and prioritization around security ...

Troubleshooting the OpenTelemetry Collector

  In this tech talk, you’ll learn how to troubleshoot the OpenTelemetry collector - from checking the ...