Installation

stop all users seeing a license warning message

chrispolk
Explorer

Is there a way to stop all our users from seeing the license warning messages and have only our admins see this?

Obviously the fix is to not exceed the license, but periodically we run over with new sources coming online. I dont want our less technical dashboard focussed users seeing these license warning messages. Really these messages are only relevant for our admins who can actually do something about it.

Tags (2)
0 Karma
1 Solution

RicoSuave
Builder

Hello Chris,
Unfortunately there is no way to control which users see these messages. Enhancement request 2431 has been filed to address this very issue. There is no ETA on when this will be implemented. There is one workaround. It involves removing the message module from the views your users access.

View solution in original post

gooza
Communicator

What about filtering the messages in the relevant apps with application.js as suggested in:

http://splunk-base.splunk.com/answers/3123/message-module-filter-values

0 Karma

chris_lewis
New Member

Is there any progress on this? I see errors like this at one of my sites on the search head consistently:

The running job "1366883794.12593.hostname" was canceled remotely or expired.

I would like to be able to disable the warning as multiple warnings pop up at once. Any advice on what may be causing this would also help?

0 Karma

ryancammer_kaba
New Member

use adblock and just block the element. there's some warning on my splunk instance about some pool warning, for a splunk instance that we haven't hardly used, with some warning about a pool violation, which makes no sense. i just applied the following adblock filter:

LI[class="message warn"]

and if splunk stops working, we'll just uninstall it and use nurelic instead, since we're indexing so little data.

0 Karma

RicoSuave
Builder

Hello Chris,
Unfortunately there is no way to control which users see these messages. Enhancement request 2431 has been filed to address this very issue. There is no ETA on when this will be implemented. There is one workaround. It involves removing the message module from the views your users access.

mikelanghorst
Motivator

Would be nice to be able to "acknowledge" the message so you don't constantly have it up all day.

0 Karma

RicoSuave
Builder

Yes, that is real answer. Or you can buy a bigger license 😉

0 Karma

chrispolk
Explorer

Thank you.

Ultimately we need to get better at managing the volumes.

0 Karma
Get Updates on the Splunk Community!

The Splunk Success Framework: Your Guide to Successful Splunk Implementations

Splunk Lantern is a customer success center that provides advice from Splunk experts on valuable data ...

Splunk Training for All: Meet Aspiring Cybersecurity Analyst, Marc Alicea

Splunk Education believes in the value of training and certification in today’s rapidly-changing data-driven ...

Investigate Security and Threat Detection with VirusTotal and Splunk Integration

As security threats and their complexities surge, security analysts deal with increased challenges and ...