Splunk Enterprise Security

How to change frequency of messages received in splunk

alexspunkshell
Contributor

I am receiving lot of messages in Splunk. I want to change the frequency of the messages receiving in splunk. Kindly help here

0 Karma

nickhills
Ultra Champion

Messages relating to File Integrity checks means that one of the 'default' files from an installation is missing or has been changed.

You should not modify files in any ./default folder. (or outside of ./local for that matter)
Periodically (and after a restart) Splunk will compare the installation files with the manifiest, and report files that have been modified.

The message should indicate which file has changed, you should then replace/or revert this to the original version, and if necessary make the ammendment to the relevent file in ./local

If you want to retrigger the message so you can review which files are affected you can restart the Splunk server, or without restarting review the events in index=_internal

If my comment helps, please give it a thumbs up!

nickhills
Ultra Champion

I think you need to be a little bit clearer in your question.
Do you mean you are recieving a high number of alerts?
If so, are they the same alert, or a range of different alerts?

If my comment helps, please give it a thumbs up!
0 Karma

alexspunkshell
Contributor

@nickhillscpl Thanks for your response. I am receiving lot of messages in Splunk. For example i am receiving File Integrity checks found message frequently in Splunk web. Now i want only once to give the message. Can you please help?

0 Karma
Get Updates on the Splunk Community!

Splunk App for Anomaly Detection End of Life Announcment

Q: What is happening to the Splunk App for Anomaly Detection?A: Splunk is officially announcing the ...

Aligning Observability Costs with Business Value: Practical Strategies

 Join us for an engaging Tech Talk on Aligning Observability Costs with Business Value: Practical ...

Mastering Data Pipelines: Unlocking Value with Splunk

 In today's AI-driven world, organizations must balance the challenges of managing the explosion of data with ...