Splunk Enterprise Security

How to change frequency of messages received in splunk

Path Finder

I am receiving lot of messages in Splunk. I want to change the frequency of the messages receiving in splunk. Kindly help here

0 Karma

Ultra Champion

Messages relating to File Integrity checks means that one of the 'default' files from an installation is missing or has been changed.

You should not modify files in any ./default folder. (or outside of ./local for that matter)
Periodically (and after a restart) Splunk will compare the installation files with the manifiest, and report files that have been modified.

The message should indicate which file has changed, you should then replace/or revert this to the original version, and if necessary make the ammendment to the relevent file in ./local

If you want to retrigger the message so you can review which files are affected you can restart the Splunk server, or without restarting review the events in index=_internal

Ultra Champion

I think you need to be a little bit clearer in your question.
Do you mean you are recieving a high number of alerts?
If so, are they the same alert, or a range of different alerts?

0 Karma

Path Finder

@nickhillscpl Thanks for your response. I am receiving lot of messages in Splunk. For example i am receiving File Integrity checks found message frequently in Splunk web. Now i want only once to give the message. Can you please help?

0 Karma