Splunk Enterprise Security

How to change frequency of messages received in splunk

alexspunkshell
Contributor

I am receiving lot of messages in Splunk. I want to change the frequency of the messages receiving in splunk. Kindly help here

0 Karma

nickhills
Ultra Champion

Messages relating to File Integrity checks means that one of the 'default' files from an installation is missing or has been changed.

You should not modify files in any ./default folder. (or outside of ./local for that matter)
Periodically (and after a restart) Splunk will compare the installation files with the manifiest, and report files that have been modified.

The message should indicate which file has changed, you should then replace/or revert this to the original version, and if necessary make the ammendment to the relevent file in ./local

If you want to retrigger the message so you can review which files are affected you can restart the Splunk server, or without restarting review the events in index=_internal

If my comment helps, please give it a thumbs up!

nickhills
Ultra Champion

I think you need to be a little bit clearer in your question.
Do you mean you are recieving a high number of alerts?
If so, are they the same alert, or a range of different alerts?

If my comment helps, please give it a thumbs up!
0 Karma

alexspunkshell
Contributor

@nickhillscpl Thanks for your response. I am receiving lot of messages in Splunk. For example i am receiving File Integrity checks found message frequently in Splunk web. Now i want only once to give the message. Can you please help?

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.


Introducing Unified TDIR with the New Enterprise Security 8.2

Read the blog

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...