Security

How do you acknowledge or otherwise clear blue bar notifications?

SplunkTrust
SplunkTrust

On every view in the webgui I have a blue stripe notifying me of an unconfigured or disabled index. This issue seems to be corrected as far as I can tell. My question is then - how do you clear these notifications?

1 Solution

Champion

The "Clear Restart Message" button appears in Manager >> Server Controls as of version 4.1.2.

View solution in original post

Champion

The "Clear Restart Message" button appears in Manager >> Server Controls as of version 4.1.2.

View solution in original post

SplunkTrust
SplunkTrust

Thanks, didn't notice that button until I looked for it. Always was very quick to restart it.

0 Karma

Splunk Employee
Splunk Employee

as simeon mentioned, these notifications and other error messages will usually clear when you restart Splunk. you can do this through the UI by using the Manager > Server controls page where you can either Restart Splunk or Clear Restart Message, which really just refers to clearing the notice that tells you that you have to restart for any changes you made to take effect.

is there a specific notification that you are seeing?

for example, some messages will clear when you change views. like, when you have added data, you will see a message that tells you that the data was successfully saved to an index. and when you click to another page/view, you should no longer see that message.

then, there are notifications that require you to do something. for example, restart Splunk. Or another example, when your license is about to expire, you should see a notice to contact support to renew your license. this notice will remain until you have updated your license.

SplunkTrust
SplunkTrust

Thanks! Everything is clear now.

0 Karma

Splunk Employee
Splunk Employee

These errors will typically be cleared by a Splunk restart. Also, there is a way to manually clear the restart notification via the Splunk Web manager interface (Manager > Server Controls).

SplunkTrust
SplunkTrust

I haven't been able to find this setting in SplunkWeb manager.

0 Karma