Splunk Search

Why do i get a warning triangle before actions on top right

pc591f
Explorer

I'm regularly seeing a warning triangle appear, who to I search to fine our what is causing this 

Labels (1)
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

Thanks for the clarification.  There are many places where a yellow triangle can appear so it was hard to know which you were seeing.

I recommend ignoring the IOWait alert since it tends to be over-sensitive.  Tune the health check (Settings->Health Report Manager) so the alert appears less often.

---
If this reply helps you, Karma would be appreciated.

View solution in original post

richgalloway
SplunkTrust
SplunkTrust

Clicking on the triangle should display explanatory text.  Share that text here if you need help understanding it.

---
If this reply helps you, Karma would be appreciated.
0 Karma

deepakc
Builder

Without giveout more information so we can help you (it's better to provide more context as to your issue, screen shots etc) that said it sounds like its related to risky commands.

Maybe its to do with this.
https://docs.splunk.com/Documentation/Splunk/9.2.1/Security/SPLsafeguards

0 Karma

pc591f
Explorer

pc591f_0-1714050018792.png

It showing as green circle at the moment,  but it keeps flashing a warning  see screen shot below

pc591f_1-1714051227643.png

 

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Thanks for the clarification.  There are many places where a yellow triangle can appear so it was hard to know which you were seeing.

I recommend ignoring the IOWait alert since it tends to be over-sensitive.  Tune the health check (Settings->Health Report Manager) so the alert appears less often.

---
If this reply helps you, Karma would be appreciated.
Get Updates on the Splunk Community!

Continuing Innovation & New Integrations Unlock Full Stack Observability For Your ...

You’ve probably heard the latest about AppDynamics joining the Splunk Observability portfolio, deepening our ...

Monitoring Amazon Elastic Kubernetes Service (EKS)

As we’ve seen, integrating Kubernetes environments with Splunk Observability Cloud is a quick and easy way to ...

Cloud Platform & Enterprise: Classic Dashboard Export Feature Deprecation

As of Splunk Cloud Platform 9.3.2408 and Splunk Enterprise 9.4, classic dashboard export features are now ...