Hey All, I have some questions about health.conf and web hooks. Recently I've been toying around with health.conf and testing some alerting. I noticed in my conf file I have a...
...configuring the health.conf in the wrong server or the wrong folder, or what? When I run a cmd btool health list, I see the configuration there, but Splunk is not doing as it is being told! If I am d...
...onsole and via a local health.conf file, the feature is still being included in the health report. I've opened up a case with Splunk support, but was just wondering if anyone else has e...
...bout what splunk actually does in the background to collect these values. You can find something like this in health.conf: [feature:iowait] display_name = IOWait i...
Hi Folks, we would like Load balancer to check Splunk search head health before redirecting. Could you please share the URL that be configured on load balancer? looking at using /debug/echo?ping=O...
...ost_dest= inside output group group1 from host_src=XXXXP13 has been blocked for blocked_seconds=10. This can stall the data flow towards indexing and other network outputs. Review the receiving system's health...
Hi All, I have requirement to do splunk DB connect onboarding in a distributed environment, Do I need to install the splunk DB connect in the search head or heavy forwarder? My second question is c...
I upgraded from 7.2 to 8.0 and then 8.0 to 8.2 After the upgrade to our distributed deployment, I am getting bombarded with email Health Alerts. "sum_top3_cpu_percs__max_last_3m" is r...
There appears to be a bug in splunk_monitoring_console\default\checklist.conf .
After running the Health Checks, the GUI drill-down for "Search scheduler skip ratio" states "This checks whether s...
Hello, I am recieving the following warning on my alerts: Health Check: Detected deprecated Threat Intelligence Manager inputs that are not supported by Enterprise Security version 6.4.0...