Splunk Search

Why do i get a warning triangle before actions on top right

pc591f
Explorer

I'm regularly seeing a warning triangle appear, who to I search to fine our what is causing this 

0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

Thanks for the clarification.  There are many places where a yellow triangle can appear so it was hard to know which you were seeing.

I recommend ignoring the IOWait alert since it tends to be over-sensitive.  Tune the health check (Settings->Health Report Manager) so the alert appears less often.

---
If this reply helps you, Karma would be appreciated.

View solution in original post

richgalloway
SplunkTrust
SplunkTrust

Clicking on the triangle should display explanatory text.  Share that text here if you need help understanding it.

---
If this reply helps you, Karma would be appreciated.
0 Karma

deepakc
Builder

Without giveout more information so we can help you (it's better to provide more context as to your issue, screen shots etc) that said it sounds like its related to risky commands.

Maybe its to do with this.
https://docs.splunk.com/Documentation/Splunk/9.2.1/Security/SPLsafeguards

0 Karma

pc591f
Explorer

pc591f_0-1714050018792.png

It showing as green circle at the moment,  but it keeps flashing a warning  see screen shot below

pc591f_1-1714051227643.png

 

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Thanks for the clarification.  There are many places where a yellow triangle can appear so it was hard to know which you were seeing.

I recommend ignoring the IOWait alert since it tends to be over-sensitive.  Tune the health check (Settings->Health Report Manager) so the alert appears less often.

---
If this reply helps you, Karma would be appreciated.
Get Updates on the Splunk Community!

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...

Cloud Monitoring Console - Unlocking Greater Visibility in SVC Usage Reporting

For Splunk Cloud customers, understanding and optimizing Splunk Virtual Compute (SVC) usage and resource ...

Automatic Discovery Part 3: Practical Use Cases

If you’ve enabled Automatic Discovery in your install of the Splunk Distribution of the OpenTelemetry ...