Knowledge Management

What is the purpose of Report "Audit - Index Readiness" under SA-Utils apps ?

ekcsoc
Path Finder

This Report "Audit - Index Readiness" under SA-Utils apps is running for every 30 minutes for last 24 hours time range and getting skipped in Search head. Just wanted to know what is the purpose of this report and can it be disabled ?

0 Karma

ssmiesko
Explorer

The saved search Audit - Index Readiness, along with a few other searches in SA-Utils and the lookups the write out to, are the basis for the data returned by the contentinfo REST endpoint. These are then queried by various dashboards (like ESS Content Library) in order to show whether or not data is available for use-cases.

0 Karma

BainM
Communicator

It is exactly what it states. It searches all Splunk indexers and evaluates whether an indexer is sending throughput to the metrics.log group. If it detects throughput, cool, assign a 1 to it. If it doesn't it gets a 0. It then writes this to a lookup file and a report. I would assume that this rolls up into a general Splunk health report for the security audits. Security needs continuity and responsiveness. If it doesn't get this from the Splunk env, then it has a problem.

Hope this helps,
Mike

ashishamalviya1
Explorer

As this search is heavy on search head, as running every 30 min and search for last 24 hour for all the index, can we customize this search to be lighter on CPU, 
i.e. edit search query, increase schedule interval and reduce search time frame. etc..
Thanking,

Ashish M

lesly_trinidad
Engager

i'm wondering this same thing, can the schedule be modified since it's pretty resource intensive. Haven't seen a response on this thread in while. 

0 Karma

ekcsoc
Path Finder

Thanks for the info. I wanted to know exactly in which Dashboard this is being used, since its not schedule to send an email or throw an alert

0 Karma

harsmarvania57
Ultra Champion

What is the Splunk ES version ? I can't see that report in ES 5.2

0 Karma

ekcsoc
Path Finder

ES version - 5.3.1

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Data Persistence in the OpenTelemetry Collector

This blog post is part of an ongoing series on OpenTelemetry. What happens if the OpenTelemetry collector ...

Thanks for the Memories! Splunk University, .conf25, and our Community

Thank you to everyone in the Splunk Community who joined us for .conf25, which kicked off with our iconic ...

Introducing Splunk 10.0: Smarter, Faster, and More Powerful Than Ever

Now On Demand Whether you're managing complex deployments or looking to future-proof your data ...