icon/x Created with Sketch.

Splunk Cookie Policy

We use our own and third-party cookies to provide you with a great online experience. We also use these cookies to improve our products and services, support our marketing campaigns, and advertise to you on our website and other websites. Some cookies may continue to collect information after you have left our website. Learn more (including how to update your settings) here.
Accept Cookie Policy

Accept License Agreements

This app is provided by a third party and your right to use the app is in accordance with the license provided by that third-party licensor. Splunk is not responsible for any third-party apps and does not provide any warranty or support. If you have any questions, complaints or claims with respect to this app, please contact the licensor directly.

Thank You

Downloading Fire Brigade version 2
SHA256 checksum (fire-brigade-version-2_203.tgz) de6c0dd7fa1314074aa198b464706f27a3dce6baf45c9cae2d8a6f9cbe3c509c SHA256 checksum (fire-brigade-version-2_202.tgz) 1320873b0cd2edbdac2adba7e7a4e9cf0ea021809378e0493e6060dc4a1898f8 SHA256 checksum (fire-brigade-version-2_201.tgz) 6fe1f531f0c17cc96d595dbe6620361e1ca05511766c2368f87abd4f20a2f830 SHA256 checksum (fire-brigade-version-2_20.tgz) d39fe364127f52a852ca8aeaf474b3507045111cf9609ae92dc5cfb25678fcac
To install your download
For instructions specific to your download, click the Details tab after closing this window.

Flag As Inappropriate

Fire Brigade version 2

Overview
Details
Updates to this particular "app" page have been suspended. New versions of this app are available with the original "Fire Brigade" app title (version 2.0.4+).

Fire Brigade app 2.0

A Splunk app to provide insight into index state


This application is aimed at helping administrators understand the current
state of their index, as it relates to disk footprint, and the retention
settings for the index.

Due to changes in the operation of dbinspect introduced in Splunk 6.0, as well
as changes to the application packaging, this app by itself is no longer
sufficient to collect data for a standalone system. The TA-fire_brigade
application will also be required, to act as the data collection source.
In a distributed environment, the TA-fire_brigade app will also be required.
In small environments, a single installation of the TA on the search head can
collect data from all of the indexers. In larger installations, however, the
TA should be installed on all indexing nodes, and not on the search head.

The TA (and a saved search within the full app) collects data using the
dbinspect search command. This detail of the constituent buckets in the index
is used to drive several visualizations about the state of the index.

Compatibility

The output from the dbinspect command changed in version 6.0. This app is
specifically tuned for version 6.0 and higher. If you're running Splunk 4.3 or
Splunk 5.x, use TA-fire_brigade version 1.

Thanks and Acknowledgements

Thanks to all of the sites that tested early versions of the application. My
colleagues were helpful in getting the application to a wider audience, as
well as providing critical feedback in improving the dashboards.

Dritan Bitincka, Yisroel Bongart, Tian Chen, Michael Cormier, Joe Cramasta,
Fred de Boer, Octavio di Sciullo, John Dunlea, Nick Filippi, Charles Fox,
Marc Francoeur, Adam Gabel, Thomas Gadbois, Jim Goddard, Bob Hartley,
Tim Hatcher, Zhiyi Huang, Robert Knoeppler, Mark Lindsey, James Lord,
Mike Loven, Nick Malecky, Nate McKervey, Erick Mechler, Craig Nelson,
Shane Newman, Chad O'Neal, Drew Osborne, David Paper, Cheryl Phair,
Rich Prescott, Greg Quale, Vladimir Serebryany, Matthew Settipane,
Sandy Voellinger, Brian Wooden

Supporting Add-Ons

For distributed search environments, this application only needs to be installed on the Search Heads. However, a data collection add-on, TA-fire_brigade version 2 should be installed on the indexers to collect the data required for Fire Brigade.

Release Notes

Version 2.0.3
Aug. 1, 2014

* Fix the "Bucket Age vs. Age Limit" view to show the searchable span for both live and thawed data.
* Account for the default value of 0 (instead of null) in homePath.maxDataSizeMB and coldPath.maxDataSizeMB.
* Add a new view, the "Retention Overview" to show all of the retention dials on an index at once. This view is interactive, featuring in-page drilldown (6.0 compatible).
* Separated the "time trend" searches from the "current state" searches for improved dashboard performance. It results in more running searches, but the searches themselves are more focused, and can therefore complete more quicky.
* Improve the "Reason" detection / parsing of the "Bucket Lifecycle" view.

Version 2.0.2
May 2, 2014

* New view added to the nav: Matrix Overview. This is purely REST, and therefore doesn't require waiting on dbinspect (TA-fire_brigade) to do its job.
* Added a search bar to the nav so that it's easy to search with Fire Brigade's macros and knowledge objects.
* Improved the visualization of the "Indexer Host Overview", making it easy to spot at-or-near capacity indexes.
* Various bugfixes.

Version 2.0.1
Dec. 16, 2013

Fix a user-discovered bug: environments making use of the new distributed dbinspect from the search head alone will observe all the data usage as arising from the search head in some views.

Version 2.0
Nov. 13, 2013

Provides support for Splunk Enterprise 6.

Showcases some of the new visualization features in Splunk Enterprise 6.

252
Installs
2,806
Downloads
Share Subscribe LOGIN TO DOWNLOAD

Subscribe Share

AppInspect Tooling

Splunk AppInspect evaluates Splunk apps against a set of Splunk-defined criteria to assess the validity and security of an app package and components.

Are you a developer?

As a Splunkbase app developer, you will have access to all Splunk development resources and receive a 50GB license to build an app that will help solve use cases for customers all over the world. Splunkbase has 1000+ apps and add-ons from Splunk, our partners and our community. Find an app or add-on for most any data source and user need, or simply create your own with help from our developer portal.

Follow Us:
© 2005-2019 Splunk Inc. All rights reserved.
Splunk®, Splunk>®, Listen to Your Data®, The Engine for Machine Data®, Hunk®, Splunk Cloud™, Splunk Light™, SPL™ and Splunk MINT™ are trademarks and registered trademarks of Splunk Inc. in the United States and other countries. All other brand names, product names, or trademarks belong to their respective owners.