This TA can be used to fill in detection gaps following a period of data collection interruption. Once data are recovered in Splunk, this application can be used to restart scheduled searches during this outage. You can automatically create your list of backfills using a dedicated dashboard based on an outage period and a regexp on savedsearches that need to be rerun. You can manage the backlog of all your rescheduled searches (backfills are run periodically to avoid performance issues over the platform) You can monitor the reruns based on the internal logs and a full details of logging provided in the python scripts
(0)
Categories
Created By
Type
Downloads
Licensing
Splunk Answers
Resources