Use the Health (preview) dashboard
Splunk Cloud Platform administrators use the Health dashboard to review the status of their deployment. The dashboard provides information about the overall health of the deployment and its data collection, indexing, and search performance. If an indicator shows non-optimal performance, see the Suggested Actions area for the indicator in the All Indicators table for possible mitigation steps.
Preview features are provided by Splunk to you "as is" without any warranties, maintenance and support, or service level commitments. Splunk makes this preview feature available in its sole discretion and may discontinue it at any time. Use of preview features is subject to the Splunk General Terms.
Review the health indicator gauges
Select a gauge icon to see summary information about the number of indicators that are in conformance versus indicators that have warning or critical status. The totals for the Conform, Warning, and Critical categories correspond to the individual data points displayed in an indicator's Results column.
- Overall health: Provides a combined summary view of your deployment's data collection, data indexing, and data search performance in context of indicators provided in the indicator table.
- Data collection: Shows the current state of your deployment's universal forwarders and heavy forwarders as they collect data.
- Data indexing: Shows the current state of bucket size and availability per index for your deployment.
- Data search: Shows the current state of skipped searches, high memory searches, and cache activity in your deployment.
Review indicator results and actions
In the summary collapsed view, an indicator row shows the corresponding gauge, the health check validation criteria, and the results of the health check. The individual results data for a specific indicator correlate to the Conform, Warning, and Critical totals that display in the corresponding gauge.
Select the toggle for an indicator to review descriptive information and suggested mitigation actions for indicators with a Warning or Critical status.
|For more information about||See|
|Forwarder version compatibility||Monitor forwarder deployments in the Splunk Cloud Platform Admin Manual|
Supported forwarder versions in the Splunk Cloud Platform Service Description
|Skipped searches||Investigate skipped scheduled searches in the Splunk Cloud Platform Admin Manual|
|Improved search queries||Write better searches in the Splunk Cloud Platform Search Manual|
|Time stamp and line break errors||Verify data quality in the Splunk Cloud Platform Admin Manual|
Use the Overview dashboard
Use the Alerts panel
This documentation applies to the following versions of Splunk Cloud Platform™: 8.1.2103, 8.2.2105, 8.2.2106, 8.2.2107, 8.2.2109, 8.2.2111, 8.2.2112, 8.2.2201, 8.2.2202, 8.2.2203 (latest FedRAMP release), 9.0.2205, 9.0.2208