Splunk® App for ES Health Check

User Guide

Download manual as PDF

Download topic as PDF

Release notes for the Splunk App for ES Health Check

Known Issues

Date Issue number Description
Release SOLNESS-8953 On instances running Splunk Enterprise 6.1.x through 6.2.x, the panel Overview: Bundle Replication Attempts - Last 24 Hours is empty.
Release SOLNESS-8955 On instances running Splunk Enterprise 6.1.x through 6.2.x, the panel Overview: Detected Deployment will not display the CPU core count.
Release SOLNESS-8792 On instances running Windows OS, the panel Resources: Average Normalized CPU Load by Instance is empty.
Release SOLNESS-9034 On search head instances running Splunk Enterprise 6.1.x, the Analyzer dashboard will display each selected metric on its own chart.
Release SOLNESS-9065 On search head instances running Splunk Enterprise 6.3.x and later, editing the Indicator threshold options using the UI will override the pre-set range mapping. This prevents a new threshold value from changing the indicator colors.
Workaround: remove .../etc/apps/splunk_app_eshealthcheck/local/overview.xml to reset the panel to the default threshold.
2017-05-10 SOLNESS-12056, SOLNESS-12106 On instances running Splunk Enterprise Security 4.6.0 or later, the Get Enabled Correlation Searches panel does not show results.
Workaround:
Replace the search with the following syntax: | rest splunk_server=local count=0 /services/saved/searches | search action.correlationsearch.enabled = 1 | stats count as total, count(eval(disabled=0)) as enabled | eval op = enabled . "/" . total | fields op

Third-party software attributions

This version of the Splunk App for ES Health Check does not incorporate any third-party software or libraries.

PREVIOUS
About the Splunk App for ES Health Check
  NEXT
Hardware and software requirements

This documentation applies to the following versions of Splunk® App for ES Health Check: 1.0.0


Was this documentation topic helpful?

Enter your email address, and someone from the documentation team will respond to you:

Please provide your comments here. Ask a question or make a suggestion.

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters