Release notes¶
TrackMe has transitioned to a new licensing model.
The Free Community Edition has been discontinued.
What this means for you:
Existing licensed customers are not impacted. Your current license continues unchanged.
Community users are automatically upgraded to a Foundation Edition trial for 90 days, with full functionality enabled.
After the trial period:
TrackMe remains active and fully usable for monitoring
The platform enters read-only mode
You can continue to view data, dashboards, alerts, and history
Creation of new tenants, trackers, or entities will be disabled
To continue using TrackMe with full capabilities after the trial, a Foundation license is required.
Buy Foundation Edition: https://trackme-solutions.com/get-foundation/
Contact us: contact@trackme-solutions.com
Hint
TrackMe 2.4.x — the AI-native generation of TrackMe.
TrackMe Agentic — opt-in, consent-driven AI Advisors and an AI Assistant that inspect, explain and, with your approval, act on the monitored estate.
Topology Studio — introduced in 2.4.9 and now a central pillar of the product: author live, alerting-capable topology maps of your environment, or have AI generate them from plain language. Available to every edition, and maturing release after release into what makes TrackMe a full-scope premium product — from data monitoring to the living map of everything it watches.
Every release below details its own changes; start with the Artificial Intelligence and Topology Studio chapters for the full feature documentation.
Version 2.4.14 - build 1788188553 (31/08/2026)¶
Hint
TrackMe 2.4.14 — Topology Studio shapes, images and text, real email conversation threading, Configuration Guardian improvements, critical FIPS fix.
Topology Studio — the canvas becomes a diagramming surface. Draw shapes, drop images and place free text directly on the canvas. Style everything from the context menu, align decorations as part of bulk selections, and let image-aware size limits keep large decorated views safe. Set an explicit canvas size per view — existing views keep their current presentation — and find all creation actions grouped in a compact toolbar.
Stateful alert emails — real conversation threading. Alert emails now thread correctly in standards-compliant mail clients: RFC 5322 compliant
Date,Message-IDandReferencesheaders, plus a static or templated incident subject for clean Outlook/Exchange conversation grouping.Configuration Guardian — three ways better. The sourcetype-explosion safeguard becomes a first-class managed Guardian check with enable, snooze and threshold tuning; SHC member discovery works on newer Splunk Cloud stacks; and UI updates preserve your catalog context.
Critical — FIPS-enabled Splunk 10.4.x+ compatibility. A TLS call rejected by the OpenSSL FIPS provider broke every TrackMe page with “Splunk Service Unavailable”. The call is now guarded — FIPS deployments on Splunk 10.4.x+ should prioritise this upgrade.
The release also brings policy application at very large scale, an SLA manual-override contract fix, subgroup-aware group-by options for FLX and WLK, and the cycle’s dependency refresh.
SHA-256: 64f2985a2c53f7ebd9b3438a00340a7eab40aa0a9e87098d677f729de9202606
Issue Number |
Description |
Details |
|---|---|---|
feature - Topology Studio: canvas shapes and images |
Topology views become genuine diagrams: draw shapes and drop images directly on the canvas, then move, resize and style them like any other canvas element. Shapes offer multiple forms with configurable line style, colour and width; images embed into the view itself (PNG and JPEG, with transparency control and aspect-ratio lock), so duplicated views, version history and portable exports remain fully self-contained. Decorations participate in bulk selections and alignment actions alongside nodes, and the whole-graph size limit is image-aware, keeping heavily decorated views within safe storage and rendering bounds. Server-side validation enforces the same size, byte and pixel limits as the editor. |
|
feature - Topology Studio: text canvas decorations |
Free text can be placed anywhere on the canvas: titles, zone labels, annotations. Text decorations support font family, style, size and colour, all adjustable inline from the context menu, and render identically in the editor, in PNG exports and for view-only users. |
|
feature - Topology Studio: canvas size control |
Authors can set an explicit logical canvas size per view from a new Canvas size dialog. Fully backward compatible: existing views keep the historical fit-to-content presentation until an author applies a size, and the dialog suggests a size derived from the view’s current visible canvas, so accepting it preserves the presentation. Once a size is applied, centered and full-screen modes fit the complete canvas boundary, content stays visible when shrinking, and automatic canvas growth, undo and save/reload behave as before. |
|
feature - Alerting: static incident subject for Outlook/Exchange conversation grouping |
Stateful alert emails can use a static subject across the whole incident lifecycle (opened, updates, closed), so clients that group conversations by subject — Outlook and Exchange in particular — keep the entire incident in one conversation thread. |
|
feature - Alerting: configurable incident subject template |
The incident email subject becomes a configurable template with token substitution, so teams can shape the subject line to their routing and filtering conventions while preserving the threading behaviour. |
|
feature - Configuration Guardian: managed sourcetype-explosion safeguard |
The DSM sourcetype-explosion safeguard (which blocks runaway per-index sourcetype creation) becomes a first-class managed Guardian check: enable or disable it, snooze it, and tune the per-index threshold from the Guardian management UI, with the standard Guardian alert lifecycle including email notifications. The legacy hidden setting is imported automatically during the upgrade and historical alerts are migrated to the canonical Guardian collection. |
|
feature - Policies: expose |
Lookup-based and search-based policy field mappings can now target the entity |
|
feature - Entities tables: subgroup-aware group-by options for FLX and WLK |
When FLX or WLK entities carry a subgroup, the entities tables offer subgroup-aware group-by options, so grouped views follow the structure of your Flex use cases and workload apps. |
Issue Number |
Description |
Details |
|---|---|---|
change - Topology Studio: compact authoring toolbar |
The six canvas authoring buttons are grouped into two keyboard-accessible menus — Add items (entities, aggregates, labels) and Add decoration (shapes, images, text) — keeping the full toolbar on one line across more viewport widths. |
|
change - Policies: policy application at very large scale |
Policy application now runs in-process in the policy trackers instead of a blocking REST call, removing the 600-second ceiling that aborted runs on very large tenants. Reads are projected to the fields the apply needs and writes are delta-only, so applying policies over hundreds of thousands of entities completes reliably and efficiently. |
|
change - Dependency maintenance |
Third-party dependencies were refreshed for the 2.4.14 cycle across two consolidated waves, including a security-driven update to |
Issue Number |
Description |
Details |
|---|---|---|
bug - Critical: FIPS-enabled Splunk 10.4.x+ compatibility |
On FIPS-enabled Splunk 10.4.x+ deployments, an unguarded TLS |
|
bug - Emails: RFC 5322 |
Every email sent by TrackMe now carries RFC 5322 compliant |
|
bug - Emails: spec-correct |
Stateful alert lifecycle emails (opened, updates, closed) now build a spec-correct |
|
bug - Policies: SLA manual-override contract honoured |
Manually assigned SLA classes are no longer overwritten by SLA policies: the manual-override guard is enforced, policy writes are no longer stamped as manual assignments, and existing installations are cleaned up automatically during the upgrade. |
|
bug - Configuration Guardian: SHC member self-heal discovery on newer Splunk Cloud stacks |
Search Head Cluster member discovery for the Guardian self-heal checks is now dual-source and system-configurable (SPL and earliest time), fixing empty member discovery on newer Splunk Cloud stacks. |
|
bug - Configuration Guardian: catalog context preserved during updates |
Guardian UI updates no longer reset the catalog context: the current filters and view state are preserved while alerts refresh. |
|
bug - Topology Studio: context-menu inspect state aligned with the selection |
The context menu’s inspect state now stays aligned with the current selection, removing cases where the menu offered inspect actions for a previously selected element. |
Version 2.4.13 - build 1787307707 (21/08/2026)¶
Hint
TrackMe 2.4.13 — Topology Studio sparklines and better AI, notes management improvements, label assignments at scale and in bulk, security fixes.
Topology Studio — Sparkline KPI display style: 24-hour trend lines on the canvas. A new Topology Studio KPI display style renders each selected KPI as its label, current value and a 24-hour mini trend line directly on the node — trends at a glance across the whole topology without opening a single panel. Scalable by design: the complete view’s trend history is fetched by one single batched search per refresh, regardless of how many nodes carry the style. The aggregate member preview card gains the same Metrics (24h) sparklines.
Topology Studio — Build with AI. Describe the topology you want in plain language and TrackMe generates a complete draft: aggregates with scopes and filters, pinned entities, dependency edges — laid out top-down and validated server-side. The draft lands on the canvas as a pending change you can review, adjust and undo before saving. Available from the editor toolbar, from the views index (create the view and open it in one step), and proposed by the AI Assistant in conversation when a topology would answer your question. Generation runs as a dedicated AI Builder agent, RBAC-scoped server-side to the tenants you select, and works across all supported AI providers.
EU AI Act Article 50(2) — machine-readable marking of AI-generated content. AI-generated email content and every AI Assistant chat response now carry a machine-readable “artificially generated” marking; deterministic (non-AI) content remains unmarked by design.
Label assignments can no longer lose data under pressure. An important fix closes a path where label edits performed under concurrent write pressure could drop existing assignments and automatic-label metadata. Deleting a label that an enabled automatic rule still references is now refused, so a deletion can no longer silently break the rule.
Backup & Restore portability. Convert a zstd archive to a portable gzip
.tgzwith automatic download, and export or import a complete run bundle — a whole backup run as one portable artifact — for deployment migrations.FQM collect-job wizard: richer benchmarking. The benchmark step gains event-distribution timecharts and a retrieved-events metric above the charts, so you can judge coverage and volume before creating the tracker; the generating-search type no longer breaks the CIM simulation, and the data-dictionary Test regex search now honours the trackers’ summary index(es).
Email delivery: one SMTP transport, per-account certificate control. Every send path now selects the SMTP transport the same way, and each email account gains an SSL certificate verification toggle for environments with internal certificate authorities.
Notes management: clear automated notes without touching yours. TrackMe’s system-generated notes (adaptive-delay summaries, threshold-lock reconciliations) can now be cleared selectively — all of them, or all except the most recent — and notes gain bulk management, so user-authored notes are never collateral of a cleanup.
Tenant isolation, completed server-side. The remaining sibling read endpoints (cached summary counts and shadow-cache probes) now enforce the caller’s tenant visibility exactly like the main entity reads — completing the server-side read-gate work started in 2.4.9.
The release also carries the cycle’s dependency refresh, including security fixes.
SHA-256: f411c03e5b3f3e3bd233c167e558d44e01986cfb8084e52e5d1b86b9758d6e2f
Issue Number |
Description |
Details |
|---|---|---|
feature - Topology Studio: Build with AI — natural-language topology generation |
Describe the topology you want in plain language and TrackMe generates a complete draft: aggregates with tenant scopes and filters, pinned entities and dependency edges, laid out top-down and validated server-side before anything reaches the canvas. The draft is applied as one pending change — review it, adjust it, undo it, and nothing is stored until you Save, where the normal version-history flow applies. Build with AI is available from the Topology Studio editor toolbar, from the views index (the view is created and opened in one step), and through the AI Assistant, which proposes the Builder in conversation when a topology would serve the discussion. Tenant scoping is enforced server-side against your visible tenants, and entity resolution honours per-tenant permissions. Generation runs as a dedicated AI Builder agent rather than the chat assistant, making it fast and reliable across all supported AI providers; the Topology Studio chat context also became dramatically lighter, making topology conversations faster on every provider. Requires a configured AI provider; interactive only. A REST surface is available for automation users and documented in the REST API Reference. |
|
feature - Topology Studio: Sparkline KPI display style — 24-hour trend lines on the canvas |
A new entity KPI display style, Sparkline, renders each selected KPI as its label, current value and a 24-hour mini trend line directly on the canvas — the same at-a-glance history as the node inspector’s Metrics (24h) panel, across the whole topology at once. Scalable by design: the complete view’s trend history is fetched by one single batched search per refresh regardless of how many nodes carry the style, so it is safe on wall-of-screens deployments and large canvases; the fast live-status refresh stays search-free and keeps the KPI values current. Available on entity nodes and on expanded-aggregate member nodes through member KPI defaults, with honest degradations: a dashed placeholder when a KPI has too little recorded history, real trend lines in PNG exports, and a stat-card fallback in Topology Alert emails. |
|
feature - Topology Studio: Metrics (24h) sparklines in the aggregate member preview card |
The aggregate member preview card now renders 24-hour metric sparklines for the previewed member, bringing the node inspector’s trend view into the preview itself. |
|
feature - Backup & Restore: portable run bundles — export and import a complete backup run |
A backup run produces one archive per tenant plus a global archive. Backup & Restore can now export a complete run bundle — every archive of a run packaged as one portable artifact — and import such a bundle on a target deployment, restoring the run as a coherent set. Portable-archive workflows are hardened end to end (working-directory-independent compression, bounded conversion output, accurate restore error summaries), and the Backup & Restore actions gain a clearer, accessible layout. Whole-run bundle import runs under a bounded memory envelope, so importing a large run cannot pressure the search head. |
|
feature - Notes: selective clearing of automated notes and bulk notes management |
TrackMe’s automated notes (adaptive-delay summary notes and threshold-lock reconcile notes) accumulate on entities over time, and the only cleanup was Clear all notes — which also deleted user-authored notes. The Notes modal now offers clearing automated notes selectively (all of them, or all except the most recent), and notes can be managed in bulk. User-authored notes are never affected by the automated-notes actions. |
Issue Number |
Description |
Details |
|---|---|---|
change - Alerting: machine-readable marking of AI-generated email content (EU AI Act Art. 50(2)) |
When an alert email embeds AI-generated content (such as the AI status report), the message now carries a machine-readable marking: an |
|
change - AI Assistant: per-response machine-readable AI-generated marker (EU AI Act Art. 50(2)) |
Every AI Assistant chat response now carries a machine-readable “artificially generated” marker, present both in the rendered interface and in the REST payload, extending the Article 50(2) marking convention from email content to interactive chat. |
|
change - Backup & Restore: convert a zstd archive to a portable gzip archive |
An administrator can now upload a zstd-compressed TrackMe backup archive, convert it to a gzip-compressed |
|
change - Dependency maintenance |
Third-party dependencies were refreshed for the 2.4.13 cycle across four consolidated waves, including security-driven updates to |
|
change - Tenant visibility is enforced on the remaining sibling read endpoints |
The server-side tenant-visibility enforcement introduced in 2.4.9 for the main entity reads now also covers the sibling read endpoints: cached per-component summary counts and the shadow-cache probes (single, and bulk with per-scope handling). A caller outside a tenant’s RBAC scope receives the same not-found response as for a nonexistent tenant, and internal system callers are unaffected. This completes the tenant-RBAC read-gate work across the component read surface. |
|
change - FQM collect-job wizard: event-distribution timecharts in the benchmark step |
The benchmark step of the FQM collect-job wizard renders event-distribution timecharts, showing how the events feeding the field-quality analysis distribute over time before the tracker is created. |
|
change - FQM collect-job wizard: retrieved-events metric above the benchmark charts |
The benchmark step reports the number of events retrieved against the configured limit above the distribution charts, so an undersized sample is visible at a glance. |
|
change - Entities table: the number of visible labels per entity is a system-wide setting |
The number of labels shown inline per entity in the entities table is now a system-wide setting (default 4), adjustable from the system settings. |
|
change - Timestamps render in the caller’s Splunk timezone |
Entity-overview timestamps now render in the caller’s own Splunk timezone, and backend-rendered timestamps are suffixed with the server timezone label — removing the ambiguity of unlabelled server-local times. |
|
change - AI providers: refreshed public model suggestions and a new xhigh reasoning-effort level |
The AI provider configuration refreshes its public model suggestions to the current generations (including Grok 4.6, Claude Opus 5, GPT-5.6 and Gemini 3.x) and adds an |
|
change - Email delivery: unified SMTP transport selection and a per-account SSL certificate verification toggle |
All email send paths now select the SMTP transport through one shared decision, removing per-path behaviour differences, and each email delivery account gains an SSL certificate verification toggle for deployments using internal certificate authorities. |
Issue Number |
Description |
Details |
|---|---|---|
bug - FQM: pie chart drilldowns honour the clicked slice |
Clicking a slice of an FQM pie chart always drilled down on the first category regardless of which slice was clicked — on the global-entity chart and on the field-entity charts alike (#3018). Both drilldowns now filter on the clicked slice’s category. |
|
bug - Remote accounts: tokens rotated for accounts that had opted out of rotation |
|
|
bug - Topology Studio: auto-arrange no longer overlaps rows when KPI chips are shown |
The auto-arrange layout now reserves vertical clearance for visible KPI chip stacks, so arranged rows no longer overlap on views showing per-node KPIs — most visibly on auto-created member nodes. |
|
bug - FQM collect-job wizard: simulation failed with a generating search |
Using a generating search type in the CIM collect-job wizard broke the simulation with an HTTP 500. Generating searches now simulate correctly. |
|
bug - FQM: the data-dictionary Test regex search honours the trackers’ summary index(es) |
The data dictionary’s Test regex search queried the default summary index regardless of the index(es) the tenant’s trackers actually write to; it now targets the trackers’ configured summary index(es). |
|
bug - Labels: dangling automatic-rule label identifiers are contained and repairable |
Automatic-label rules could retain references to label identifiers that no longer exist. Batch operations now filter dangling identifiers, and the UI surfaces repair chips to clean the affected rules. |
|
bug - Remote accounts: configuration defaults aligned and backfilled |
Three remote-account defaults had drifted from their declared configuration values and are realigned; the connectivity-check timeout fallback is aligned to 15 seconds; and |
|
bug - Flex Objects: status 3 (unknown) no longer escalates to red, and status messages report the tracker-produced status |
A Flex Objects entity reporting status 3 — the Flex convention for an unknown or unexpected status — was escalated straight to red, and the entity’s status message was overwritten by the derived state instead of reporting what the tracker actually produced. Status 3 now lands orange by default through a new configurable impact score ( |
|
bug - Labels: deleting a label still referenced by an enabled automatic rule is refused |
Deleting a label definition that an enabled automatic-label rule still references silently broke the rule. The deletion is now refused with an explanatory message; disable or retarget the rule first, then delete the label. |
|
bug - Labels: edits could drop existing assignments and automatic-label metadata |
Label edits performed under concurrent write pressure could lose existing label assignments and automatic-label metadata. The write path is now serialised and budget-bounded so concurrent activity can no longer cause assignment loss. |
|
bug - Topology Studio: the AI-describe context now applies per-tenant graph redaction |
The graph context provided to the AI Assistant for Topology Studio conversations did not apply the per-tenant redaction enforced on every other read surface, so a restricted user’s chat context could include tenant content hidden from them in the interface. The AI-describe context now applies the same tenant-visibility redaction as saved views, version previews and portable exports. |
|
bug - Flex Objects: license usage templates no longer double-count rollover summaries |
The Flex Objects license usage tracking templates counted rollover summary events alongside the primary usage events, double-counting usage. The templates now filter license usage events by type. |
Version 2.4.12 - build 1785703548 (03/08/2026)¶
Hint
TrackMe 2.4.12 — Topology Studio opens to Foundation Edition, with critical stability hardening for large logical-group deployments.
Topology Studio is now open to Foundation Edition. The feature was introduced in TrackMe 2.4.9 but was mistakenly restricted to Enterprise and Unlimited customers. Foundation customers can now use the complete authoring experience and manage Topology Alerts. Existing security boundaries and the normal licence read-only state are unchanged.
Critical memory-stability fix for large logical-group deployments. In versions 2.4.6 through 2.4.11, logical-group processing could trigger a repeating cycle of overlapping background refreshes. At scale, this could put severe memory pressure on
splunkdand cause an out-of-memory termination. TrackMe 2.4.12 prevents the cycle and limits duplicate refresh work while retaining automatic updates. Customers with large numbers of logical groups should treat this as a critical upgrade and prioritise deployment of 2.4.12.No external machine-learning application dependency. TrackMe no longer requires the Splunk Machine Learning Toolkit or the Splunk Scientific Python add-on because outlier detection runs on TrackMe’s native engine. Outdated checks for those applications could report missing requirements and interfere with Virtual Tenant creation when they were absent; the checks are now removed.
Incremental outlier baselines. Supported native KV Store models can retain representative historical observations within a configured bound across training cycles. Full retraining remains the default; incremental learning can be inherited from the system setting or selected per model, and switching back to full performs the established full refit.
Median and better guidance for outlier analysis. Median is available as an outlier calculation method, making models less sensitive to occasional volume spikes than an average. The Outliers page now includes an accessible visual explanation of learning, detection, qualification and impact-based scoring, and its settings guidance reflects the shipped defaults.
More expressive and securely shared Topology Studio views. Authors can select a saved link, inspect its source and target, edit its label, choose one-way, bidirectional or hidden arrows, reverse a one-way relationship and decide which relationships carry impact propagation. Bidirectional links carry impact in both directions immediately. The two-step connection workflow is also more prominent and easier to follow. Tenant visibility is enforced consistently when opening saved views, previewing their history and creating or importing portable archives.
More precise aggregates and propagation. An aggregate can optionally be constrained to an exact subset of the entities matching its scope and filter. Generated members, live status, alerts and rendered emails all use the same membership. Red, orange and informational blue states propagate consistently, aggregate-member arrows remain visible, and member KPI choices reflect the generated entity set.
Complete policy and coverage results at scale. Priority, tag and SLA policies based on SPL searches or lookups now evaluate the complete result set instead of stopping at 50,000 rows. Exceptionally large policy sources stop explicitly before partial results can be applied. Host and data-source coverage analysis and expected-entity injection now read the complete tracked inventory, expose duplicate reference rows separately and fail clearly if that complete inventory cannot be loaded.
Median volume KPIs for DSM and DHM. The median five-minute event count is available in Performance Metrics, stateful-alert charts and ML Outliers KPI selection. Existing defaults are unchanged and history starts after upgrade; earlier values are not backfilled.
Cleaner fresh installations. Hybrid tracker creation now tolerates the short configuration-refresh window that can follow creation of a search macro. A deployment with no AI provider or no Virtual Tenant configured also no longer records a misleading error for that normal state.
Dependency maintenance. Third-party JavaScript dependencies were refreshed for the release cycle, with no known vulnerabilities reported by the release audit.
SHA256: caf23ca3a0cc4b60a22f4cf51ff23451c6460f53ea32f62197f8606f4bfc4859
Issue Number |
Description |
Details |
|---|---|---|
feature - Outlier detection supports bounded incremental baseline learning |
Supported native KV Store outlier models can now retain representative history across training cycles without allowing their stored baseline to grow without bound. Full retraining remains the factory default. Administrators can enable incremental learning globally, override it for selected models, see the configured and effective mode in the interface and AI-assisted workflows, and switch back to full training when recent data should replace the retained history. Unsupported model or storage combinations remain safely full-only. |
|
feature - Topology Studio aggregates can target an exact entity subset |
Aggregate scopes and filters remain dynamic by default, but authors can now optionally select the exact matching entities that should participate. The same resolved subset is used by the live canvas, previews, alerts, emailed topology images and automatically generated member nodes, so every surface represents the same topology. Candidate selection respects the user’s tenant visibility. |
|
feature - Interactive topology link authoring and impact controls |
Saved topology links are now first-class authoring objects. Select a link to edit its label, inspect or reverse its stored source and target, choose one-way, bidirectional or hidden arrows, and decide whether it participates when a node propagates impact through selected links. Clearer source/target guidance and synchronised unsaved previews make the relationship easier to understand while editing. |
Issue Number |
Description |
Details |
|---|---|---|
change - Median outlier calculation and an in-product guide to outlier analysis |
Median joins the existing outlier calculation choices, providing a measure of typical activity that is less influenced by occasional spikes than an average. The Outliers page now explains the complete learning, detection, qualification and scoring journey with accessible visual guides, and the settings documentation and examples have been aligned with the defaults actually shipped by TrackMe. |
|
change - DSM and DHM expose median five-minute event volume |
Data Source Monitoring and Data Host Monitoring now calculate and display the median five-minute event count in Performance Metrics, stateful-alert charts and ML Outliers KPI selection. Existing KPI defaults remain unchanged, lookup-specific behavior is preserved and the new history begins after upgrade rather than being backfilled. |
|
change - Dependency maintenance |
Third-party JavaScript dependencies were refreshed for the 2.4.12 cycle. The release validation reported no known vulnerabilities in the JavaScript dependency audit. |
Issue Number |
Description |
Details |
|---|---|---|
bug - Prevent memory exhaustion during large-scale logical-group processing |
In versions 2.4.6 through 2.4.11, logical-group processing could repeatedly schedule overlapping background refreshes. Deployments with many logical groups could experience severe |
|
bug - Topology Studio is now available in Foundation Edition |
Topology Studio was introduced in 2.4.9 but was mistakenly restricted to Enterprise and Unlimited customers. Foundation customers can now create, edit, duplicate, import, customise and share topology views and fully manage Topology Alerts. Capability checks, tenant isolation, per-view access controls and the normal read-only state of an expired licence continue to apply. Tenant visibility is enforced consistently across saved views, version previews and portable exports. |
|
bug - Expanded aggregate-member links retain visible direction |
Automatically generated links now point visibly from an aggregate to each expanded member, and that direction remains when a generated member is pinned. A directionless automatic link previously caused arrowheads to disappear across the entire canvas. User-authored bidirectional and directionless links keep their chosen appearance. |
|
bug - Topology impact propagation carries every non-green state consistently |
Red, orange and informational blue can now propagate through selected topology relationships; only healthy green is excluded. More important red or orange impact can replace an aggregate’s derived blue state, while a protected blue entity remains protected. The inspector preserves and explains the target’s own status alongside the inherited status, and informational blue remains non-alerting. |
|
bug - Bidirectional topology links propagate impact in both directions immediately |
A bidirectional relationship now contributes both propagation paths as soon as it is selected. Either endpoint can repaint the other when its propagation mode and native status permit it; authors no longer need to reverse the link temporarily or save it as a one-way relationship first. One-way and hidden-arrow links retain their stored source-to-target behavior. |
|
bug - Bidirectional topology links cannot be reversed accidentally |
Reversing source and target is now disabled for a bidirectional link, where the visual relationship makes that action misleading even though it would change the stored dependency direction. The link inspector also presents distinct Source and Target cards with a direction-aware connector for one-way, bidirectional and hidden-arrow modes. |
|
bug - Aggregate member KPI choices reflect the generated members |
The member KPI picker now derives its choices from the entities that remain after the aggregate scope, filter, optional exact selection, ordering and expansion limit are applied. It no longer offers KPIs that none of the generated member nodes can provide, and stale choices are cleared while membership inputs change. |
|
bug - Coverage analysis and expected-entity injection support inventories above 50,000 records |
Host and data-source coverage analysis previously compared a complete reference inventory with only the first 50,000 tracked entities on very large deployments, and the related injection workflows inherited the same incomplete view. They now load the complete tracked collection, keep host asset matching consistent between analysis and injection, distinguish unique reference entities from duplicate rows and report an incomplete read instead of presenting incorrect counts. |
|
bug - Search-based policies no longer stop after 50,000 results |
Priority, tag and SLA policies driven by an SPL search now consume the complete search result in both simulation and live application. Exceptionally large sources stop explicitly before partial results can be applied. The interactive field-discovery preview remains intentionally limited for responsiveness. |
|
bug - Lookup-based policies no longer stop after 50,000 rows |
Priority, tag and SLA policies driven by a lookup now consume the complete lookup in both simulation and live application. Exceptionally large sources stop explicitly before partial results can be applied. The small interactive preview remains intentionally limited for responsiveness. |
|
bug - No recurring error when no AI provider is configured |
AI is opt-in, and the absence of an AI provider configuration is a normal unconfigured state. TrackMe now returns an empty provider list without recording recurring error-level messages. Genuine connectivity, permission and configuration failures continue to be reported as errors. |
|
bug - Fresh-install hybrid tracker creation and configuration-state cleanup |
Hybrid tracker creation now retries the short search-configuration refresh window that can occur immediately after its supporting macro is created, instead of treating that temporary state as a permanent failure. TrackMe also removes the obsolete check for external machine-learning applications and treats the absence of a Virtual Tenant configuration as the normal state before the first tenant is created. |
Version 2.4.11 - build 1785321072 (29/07/2026)¶
Hint
TrackMe 2.4.11 — hotfix: AI Advisors fail to start on recent builds due to MCP 2.0.0 publication.
This hotfix release restores the AI Advisors, which fail to start on affected builds. Only the AI layer is impacted — data monitoring, tracking, alerting, notable events and every other TrackMe capability continue to operate normally, and deployments that do not use the AI features see no functional difference.
Which builds are affected: any TrackMe package built on or after 28/07/2026 — this includes the publicly released 2.4.10 build. Builds produced before that date are not affected. On an affected build, every advisor surface fails to start: the interactive AI Advisors, the Flex Objects tracker-generation wizard, the AI Assistant’s advisor actions, and the scheduled advisor batches.
Cause: a third-party library bundled with TrackMe (
mcp, used by the Splunk Agent SDK that powers the advisors) published a new major version on 28/07/2026 which removed part of the API the SDK depends on. TrackMe’s dependency declaration had no upper bound, so builds produced from that date automatically picked the new major version up. The dependency is now pinned to the supported 1.x line, and will only move in step with a Splunk SDK release that supports the new API.Upgrading is enough — no manual cleanup is required. Splunk application upgrades never delete files that the new version no longer ships. An installation that has run an affected build therefore keeps incompatible leftovers from that library, which would continue to break the advisors even after upgrading to a fixed build. TrackMe now detects and removes those leftovers automatically, logging what it removed. This matters in particular for Splunk Cloud, where operators cannot clean the application directory by hand.
SHA256: 0727bf8201ce64ae4c2e85ce01f553b9f74d95b17481320f98aa625d75f61464
Issue Number |
Description |
Details |
|---|---|---|
bug - AI Advisors fail to start on builds produced from 28/07/2026 (including the public 2.4.10 build) |
The |
Version 2.4.10 - build 1785285034 (29/07/2026)¶
Hint
TrackMe 2.4.10 — hotfix: chart images in alert emails on Splunk Cloud 10.x.
This hotfix release addresses a chart-rendering problem affecting Splunk Cloud 10.x only — on-premise deployments and Splunk Cloud 9.x are unaffected.
On Splunk Cloud 10.x, chart images embedded in alert emails were delivered as SVG instead of PNG; because most email clients refuse to render inline SVG, recipients effectively received their alert emails without chart images. The alert text, links and all other content were unaffected — alerts continued to fire and be delivered on time.
For stateful alerts, this is a regression introduced by the Splunk Cloud 10.x platform environment (Python 3.13): chart images worked on Splunk Cloud 9.x and stopped working on 10.x. For Topology Alerts, the embedded topology image was affected as a known issue in the initial release of the feature (Topology Studio shipped in 2.4.9, so there is no prior behaviour to regress from).
The PNG rendering backend is now fully self-contained (it no longer depends on system libraries that minimal Splunk Cloud hosts do not provide) and is resolved deterministically, so chart images render as PNG again on every supported platform.
The release also carries the cycle’s dependency refresh, with a clean security audit.
SHA256: baf84a10d3a5f9ddd5211a3e2f4e7df98aa4f589e65f5be9e3847cb0d496cc88
Issue Number |
Description |
Details |
|---|---|---|
change - Dependency maintenance |
Third-party dependencies were refreshed for the 2.4.10 cycle in a consolidated wave, resolving all outstanding security advisories — the JavaScript dependency audit reports zero vulnerabilities at release. All updates are lockfile-level version bumps with no functional impact. |
Issue Number |
Description |
Details |
|---|---|---|
bug - Splunk Cloud 10.x: chart images in alert emails delivered as SVG instead of PNG |
Affects Splunk Cloud 10.x only — on-premise and Splunk Cloud 9.x are unaffected. Chart images embedded in stateful alert emails (a regression relative to Splunk Cloud 9.x, introduced by the 10.x platform environment) and the topology image embedded in Topology Alert emails (a known issue in the initial 2.4.9 release of the feature) silently fell back from PNG to SVG, which most email clients do not render — so the emails arrived without their chart images. Impact was cosmetic: alerts fired and were delivered normally, and charts remained viewable in the TrackMe UI via the links in each email. Affected environments show |
Version 2.4.9 - build 1785244560 (28/07/2026)¶
Hint
TrackMe 2.4.9 — Topology Studio: the map of your environment becomes yours — live, alerting, AI-powered.
Topology Studio — a major new product feature, the headline of this release. Author your own topology maps from TrackMe entities: a full canvas editor (entities from any tenant and component, live aggregate nodes with filters and auto-expanding members, labels, edges, icons, background images, KPI cards, top-down auto-arrange), shared under per-view RBAC, watched live, consumable full-screen on a wall of screens, deep-linkable, exportable as PNG and as portable archives.
Topology Alerts — smart alerting and correlation on your maps. A state-aware alerting engine (open / update / resolve) correlates everything a topology covers: notable events on every transition, and rich email delivery embedding the server-rendered topology image — same icons as the canvas — with a drilldown link back to the live view (customisable root URL for reverse proxies).
AI-integrated end to end. The AI Assistant understands your topologies and alerts in context — and can generate or modify topologies for you through consented, audited actions. Entity KPIs cover every component, including dynamic per-entity metrics for Flex Objects, FQM and WorkLoad.
Enterprise-grade security. Per-view read/write RBAC with creator guarantees, and server-side per-node tenant isolation on the live-status surface — a node outside your tenant permissions reveals nothing, and the isolation is enforced by mutation-verified CI guards.
Alert Enrichment (new). Enrich your alerts with your own data: a configurable SPL enrichment whose fields are merged into stateful alerts and notable events, so every notification carries the context that matters to you (CMDB attributes, ownership, anything your SPL returns).
The built-in Topology view gets a full enhancement arc. Admin-configurable default and maximum node counts, a resizable and maximizable graph modal that remembers its size, an Availability vs Health display mode, click-a-node entity details (including converging members), and a live summary of the current selection.
A more visual TrackMe. Tracker wizard simulation results, alerting entity overviews and the Tenant Home header now use visual cards, stat strips and actionable tiles instead of dense tables — plus a visual diagram of the DSM/DHM break-by logic.
Faster and safer at scale. The Support Diagnostic is rearchitected to run in a search process, the Virtual Tenants drill-down modals load slim and render windowed, and tenant read endpoints are now gated server-side on the caller’s visible tenant set.
Also in this release: DSM lookup-monitoring refinements, Configuration Guardian fixes, first-class AI agent step budgets, the FLX tracker-name length bound, tolerant non-UTF-8 reference-lookup reads, two security dependency bumps, and a dependency refresh including a Splunk UI toolkit upgrade.
See the new Topology Studio documentation chapter.
SHA256: 40d213f715a4193946299c6df5241231210e3e78aca4d5342ce4af2dcda77f80
Issue Number |
Description |
Details |
|---|---|---|
feature - Topology Studio: user-authored live topology views + Topology Alerts |
A major new product feature — the key announcement of TrackMe 2.4.9. Topology Studio lets you author your own topology maps of the environment from real TrackMe entities — place, connect, share, and watch live. The canvas editor supports entity nodes from any tenant and any of the six components (picked through a cross-tenant searchable picker), live aggregate nodes (multi-tenant scopes plus the Virtual Groups filter grammar, folded to worst state with per-state counts, and optionally auto-populated — expanding their current members as linked nodes), and free-text labels; visuals include 74 selectable node icons plus a deployment-wide catalog of user-uploaded custom icons (any image, normalized automatically), custom background images, stacked per-node KPI displays (up to five per node, each renamable — aggregates apply a default stack to every expanded member), and a hierarchical top-down auto-arrange. A canvas keyword search finds any node by label, entity, tenant, component or aggregate scope — matches light up, Enter cycles and pans to each. Views are shared under per-view RBAC with a read/write split, consumed live (honest refresh countdown, rich node inspector with per-metric sparklines and one-click Entity Overview), full-screen for wall-of-screens displays, deep-linkable, exportable to PNG and as portable archives (graph, background and alert definitions travel together). Topology Alerts turn any view into an alerting object: a state-aware engine (open / update / resolve — no notification spam) with per-alert scheduling, explicit or automatic node selection, notable events on every transition, and opt-in email delivery embedding the server-rendered topology image — the same node icons as the canvas — with a drilldown link back to the live view. Entity KPIs cover every component: fixed catalogs for DSM/DHM/MHM/WLK and dynamic per-entity metrics for Flex Objects, FQM and WorkLoad (hybrid). The rich node inspector’s aggregate mini-map is interactive — adjustable member count, click-to-preview, and one-click jump to an expanded member’s node. The AI Assistant is integrated end to end — a dedicated topology chat context, per-alert AI, and the ability to generate or modify topologies through consented, audited actions. Security is enterprise-grade by design: server-side per-node tenant isolation on the live-status surface, privilege-safe alert evaluation, and an independent security review of the isolation gate before release. |
|
feature - Alert Enrichment: merge your own contextual data into alerts and notables |
A new Alert Enrichment capability lets you attach your own data to TrackMe alerting. Define an SPL enrichment returning the fields you care about — CMDB attributes, service ownership, escalation contacts, anything searchable — and TrackMe merges those fields into stateful alerts and notable events. The enrichment is configured per tenant, applies across every delivery target, and makes each notification self-contained: the responder gets the context with the alert instead of having to look it up. |
Issue Number |
Description |
Details |
|---|---|---|
change - DSM lookups: tracker wizard picker scoped to the selected namespaces |
The lookups picker in the tracker wizard now lists only the lookups belonging to the application namespace(s) selected earlier in the wizard, instead of every lookup on the deployment — making the right lookup easier to find and avoiding accidental cross-namespace selection. |
|
change - Support Diagnostic: rearchitected and resilient at scale |
The global Support Diagnostic is rearchitected to run its collection in a search process rather than a REST handler, which removes the whole class of stalling and timeout problems seen on large environments. Supporting searches run as asynchronous jobs under a true global deadline, searches abandoned by a timeout are cancelled instead of being left running, and the job of a completed run is retained for inspection. |
|
change - Support Diagnostic: tenant anonymisation is now complete and fails safe |
When a diagnostic archive is generated with tenant anonymisation enabled, tenant identifiers are now replaced in the archive manifest ( |
|
change - Backup & Restore: rearchitected — backup and restore jobs run in a search process |
UI-triggered backup and restore jobs now execute inside a splunkd search process (via a new generating command dispatched server-side) instead of background threads in the Backup & Restore REST-handler process — the same rearchitecture applied to the Support Diagnostic in this release, and for the same reason: splunkd recycles handler processes at will, which could silently kill a long backup or restore mid-flight and, in the worst case, turn a very large restore into an endless retry loop that never completed. The job is claimed exclusively (a duplicate dispatch can never double-run), the UI now shows live progress — a per-archive step feed for backups and a per-task feed for restores, with durations and sizes, persisted after completion — and a watchdog transitions jobs that can never finish to an explicit failed state instead of leaving them appearing to run forever. |
|
change - Topology view (built-in): configurable size, resizable modal, new display mode and node details |
The built-in per-component topology view gains a full round of enhancements: administrators can configure the default and maximum number of entity nodes; the graph opens in a resizable and maximizable modal that remembers its size across opens; a new Availability vs Health display mode switches what the node colours represent; clicking a node opens its details (including for converging members, from where the entity overview can be opened directly); and the current selection is summarised live without needing a click. |
|
change - A more visual TrackMe: cards, stat strips and actionable tiles |
Several dense tabular surfaces are replaced by visual, scannable presentations. Tracker wizard simulation results (Feeds hybrid, Flex Objects, FQM and the tenant wizard) now render as topology-style cards with conditional colours and a summary strip, so what a tracker will actually create is obvious before you create it. The alerting entities overview modals gain entity cards and a summary strip (#2669), the tenant entities overview gains actionable header stat tiles that filter the table when clicked, and the Tenant Home header gains a compact actionable stats strip. The DSM/DHM break-by logic is now explained by a visual diagram instead of prose. |
|
change - AI agents: the step budget becomes a first-class input |
AI agent runs now treat the step budget as an explicit, visible input: it is declared upfront, counted down live in the tool results, and enforced by a finalize-gate so the agent lands its conclusion instead of being cut off mid-run. Combined with a soft landing on budget exhaustion across every agent surface and a duplicate-call breaker for the Flex Objects tracker-generation loop, agents no longer fail with a hard step-limit error part-way through their work. |
|
change - Tenant read endpoints enforce tenant visibility server-side |
The tenant read endpoints (tenant listing, single-tenant read and component data loading) are now gated server-side on the caller’s visible tenant set, rather than relying on the interface to filter. Access resolution is centralised in a shared visibility resolver and enforced by dedicated CI guards. |
|
change - Dependency maintenance |
Third-party dependencies were refreshed for the 2.4.9 cycle, including an upgrade of the Splunk UI toolkit (dashboard and visualization components) to the latest releases, and security-driven bumps addressing a critical advisory in |
|
change - Notes: better navigation, search, and bulk clearing in the per-entity Notes modal |
The per-entity Notes modal is easier to work with at volume: notes can be navigated and searched, and bulk clearing removes many notes in one action instead of one by one. |
|
change - Adaptive delay: auto-generated notes expire after 30 days |
Notes generated automatically by the adaptive delay engine now carry a 30-day expiration, so long-lived entities no longer accumulate stale system-generated notes indefinitely. User-authored notes are not affected. |
Issue Number |
Description |
Details |
|---|---|---|
bug - Backup & Restore: ephemeral job, lock and cache collections are no longer captured in the global archive |
The global backup archive included ephemeral job-tracking, lock and cache KV collections. Restoring such an archive into another environment imported the source’s job rows — including stranded “running” entries the automatic purge never removes — plus lock rows that blocked the next acquisition until their staleness timeout, and cache-validity tokens referencing files that do not exist on the target. These collections are now excluded from the global archive, and bulk-restore scope lists can no longer force-restore them. |
|
bug - Backup & Restore: importing a gzip archive no longer requires the zstd binary |
Importing a valid gzip |
|
bug - Scoring: repeat manual-influence and false-positive actions now reflect immediately |
Score actions (manual influence / false positive) taken repeatedly on the same entity did not reflect in the UI after the first one: the score-cache merge deduplicated per score source instead of per entry, so the newest action was silently dropped in favour of the older indexed record. The merge now deduplicates per entry by recency, and repeated actions refresh immediately. |
|
bug - Maintenance KDB: recurring KeyError in the expiration sweep |
The maintenance knowledge base expiration sweep raised a recurring |
|
bug - Robustness: repaired latent errors on rarely-taken code paths |
A systematic static sweep identified latent |
|
bug - FLX: long tracker names overflowed Splunk’s 100-character saved-search limit |
Creating a Flex Object tracker whose derived saved-search name exceeded Splunk’s 100-character limit failed with a gateway timeout instead of a clear message. The derived tracker name is now bounded to fit the limit, and a name that genuinely cannot fit fails fast with an explicit error. |
|
bug - Configuration Guardian: member-drift false positive on multi-search-head-tier Splunk Cloud stacks |
The remote-account member-drift check could raise a false positive on Splunk Cloud stacks that run multiple search-head tiers under a single domain. Member drift is now assessed by cluster membership only, eliminating the false alert. |
|
bug - DSM lookups: data sampling no longer offered or applied to lookup entities |
Data sampling is not meaningful for lookup entities. The Data sampling tab is now hidden for lookups, and the sampling executor skips lookup entities entirely. |
|
bug - Configuration Guardian: run buttons now show a busy state |
The per-check “Run this check” / “Run now” buttons gave no feedback while a check was running. They now show a busy “Running…” state until the check completes. |
|
bug - Coverage gap analysis failed with HTTP 500 on reference lookups containing non-UTF-8 bytes |
Coverage gap analysis (and expected-entity injection) returned an HTTP 500 when the reference lookup it read contained a non-UTF-8 byte. The reader now tolerates such bytes and completes the analysis instead of failing. |
|
bug - Virtual Tenants drill-down modals were sluggish and could exhaust the browser at scale |
Opening a drill-down modal from the Virtual Tenants vignettes rendered every record eagerly with no progress indication, which was slow and could kill the browser tab on very large tenants. These modals now load a slim payload, render progressively in windows, and show a progress bar while loading. |
|
bug - AI Routines: next-run time could be computed in the wrong timezone |
The next-run enrichment shown for AI Routines did not honour the UTC token and could present a next-run time already in the past. The computation now honours UTC and guards against past values. |
|
bug - Virtual Groups: category grouping mismatched on non-ASCII names |
Virtual Group category grouping and rank matching used a case conversion that mis-handled non-ASCII characters, so categories differing only by case could fail to group together. Matching now uses a full case-folding comparison. |
|
bug - Unreadable text on some coloured status pills |
Text on filled status pills could render with insufficient contrast against the pill colour. The text colour is now selected from the actual measured contrast ratio, keeping labels readable on every pill in both themes. |
Version 2.4.8 - build 1784017070 (14/07/2026)¶
Hint
TrackMe 2.4.8 — configuration management, reinvented: the Splunk UCC configuration page is replaced by native TrackMe UIs, and lookups become first-class citizens of DSM.
A brand-new configuration experience. Every configuration surface that used to live on the Splunk-generated (UCC) setup page is now a native TrackMe interface: Email delivery accounts, Remote deployment accounts, S3 export accounts, and a completely redesigned System settings page — docs-style sidebar navigation, built-in documentation for every one of the 122 settings, connectivity tests at your fingertips, insufficient-permissions detection, and the AI Assistant available in context. Faster, clearer, and consistent with the rest of TrackMe.
DSM lookup monitoring, first-class. Alert when a lookup runs empty (configurable minimum record count), see the last-known record count as a KPI tile, and enjoy a fully normalised experience for lookup entities — status messages, charts, overview tabs and alert emails now speak “records and update frequency” instead of feed metrics. Creating lookup trackers is easier too, with dynamic pickers for application namespaces and lookups.
Alerting UX. The alert wizard gains theme-aware, zoomable diagrams of the stateful lifecycle and the legacy alerting architecture, a recipients multi-select with address validation, and resizable full-width command editors.
Built for very large scale. The Virtual Tenants overview and Virtual Group views now load slim entity payloads and fetch details on demand — no more browser-tab exhaustion on very large environments — and a reliability fix ensures background summary/KV updates in search commands can no longer be silently dropped.
Remote accounts. Rotate a deployment’s bearer token on demand with a per-row Rotate token now action.
Flex Objects — richer insight. A new rich Last-metrics charts modal replaces the raw-JSON inspector, converging trackers gain a wider tracked-entities view with colour-coded availability tiles, and the tracker simulation now lists the covered sub-objects — so you can see exactly what a tracker covers before you create it.
And more. Configurable tstats time span for Elastic trackers, explicit Unlock action for DSM/DHM threshold locks, resizable data-preview tables, a licensing safety fix so a transient KV read error can never downgrade a valid license to a Foundation trial, and a batch of fixes.
SHA256: e880b5b4adae5cab780032cd3bd839e06619ff7911c43d29bb5ddb1e0d3ad8ed
Issue Number |
Description |
Details |
|---|---|---|
feature - Configuration: native TrackMe management UIs replace the Splunk UCC configuration page |
The Splunk-generated (UCC) configuration page is retired and replaced by native TrackMe React interfaces, accessible from the Configuration menu: Manage Email delivery accounts, Manage Remote deployment accounts and Manage S3 export accounts provide modern account management with inline connectivity tests, clear validation and secure credential handling; a new System settings page groups all 122 system settings behind a docs-style sidebar navigation, with per-setting documentation modals, drift-proof schema generation, insufficient-permissions detection, and the AI Assistant integrated in context. Every reference and link across the application now points to the native interfaces. |
|
feature - DSM: first-class lookup monitoring, including empty-lookup alerting |
Lookups monitored as DSM entities gain a fully normalised experience. TrackMe can now alert when a lookup has zero records — or fewer than a configurable minimum record count (per-entity setting, with its own impact score weight) — closing the gap where an emptied lookup went unnoticed. The entity overview surfaces the last-known record count as a dedicated KPI tile, status messages and the delay-management UI are reframed for lookup semantics (staleness rather than feed delay/latency), entity charts and the “Overview data source” tab show records and update frequency, and stateful alert emails embed lookup-appropriate charts. The lookups hybrid-tracker wizard adds dynamic pickers that discover application namespaces and lookups and auto-translate the selection into tracker parameters. |
|
feature - Remote accounts: on-demand token rotation |
The Manage Remote deployment accounts interface gains a per-row Rotate token now action (with confirmation) to force the rotation of a deployment’s bearer token on demand, and newly created accounts can be force-rotated in a single call. The rotation flow is fail-safe by construction: the new token is generated and validated against the remote deployment before it is stored, and the previous token is only revoked last. |
Issue Number |
Description |
Details |
|---|---|---|
change - Elastic trackers: configurable tstats time span |
Elastic sources (shared and dedicated) running in tstats mode can now configure the search time span, allowing the tracking behaviour to be tuned to the data profile instead of relying on a fixed window. |
|
change - Alerting: theme-aware, zoomable architecture diagrams |
The static alerting diagrams are replaced by theme-aware, zoomable components: the alert creation wizard now embeds an interactive diagram of the stateful alerting lifecycle, and the legacy alerting architecture is illustrated with a matching zoomable SVG diagram (#2551). Both render crisply in dark and light themes and support click-to-zoom inspection. |
|
change - Stateful alerting: recipients multi-select and resizable command editors |
The alert modal replaces the free-text recipients field with a multi-select accepting one address per entry (with format validation), and the command editors become full-width and vertically resizable for comfortable editing of longer searches. |
|
change - Alerting: email delivery account pre-selected in the alert wizard |
When creating a stateful alert, the wizard now pre-selects the first configured email delivery account instead of leaving the field empty, so email alerting works out of the box with one less step. |
|
change - Configuration Guardian: configurable environment name on email notifications |
Guardian email notifications can now carry a configurable environment name, making it easy to tell at a glance which deployment a Guardian alert email came from. |
|
change - Configuration Guardian: email delivery account pre-selected in the notifications setup |
The Guardian notifications configuration now pre-selects the first configured email delivery account, consistent with the alert wizard. |
|
change - UI: auto-fit and resizable columns in data preview tables |
Data preview tables (lookup previews, search previews, gap-analysis wizards, CMDB integration) now auto-fit their column widths to the content and support manual column resizing — long column headers and values are no longer truncated into unreadable columns. |
|
change - FLX converging trackers: richer tracked-entities modal and simulation |
The converging tracker tracked-entities modal gains a wider layout with colour-coded availability KPI tiles, and the tracker simulation now exposes the list of covered sub-objects (#2580) so you can verify the tracker’s coverage before creating it. |
|
change - FLX: rich “Last metrics” charts modal |
The Flex Object “Last metrics” inspector is replaced by a rich charts modal — the latest tracked metrics are presented as readable visualisations instead of a raw-JSON dump, making it far easier to interpret a Flex Object’s current state at a glance. |
|
change - DSM/DHM: explicit Unlock action for threshold locks |
Entities with locked delay/latency thresholds gain an explicit Unlock action in the UI (and matching AI Assistant awareness), making it straightforward to return an entity to automatic threshold management. |
|
change - Virtual Tenants: scoped tenant pre-selected in Clear operational status |
Launching “Clear operational status” from a tenant’s Operational Status view now pre-selects that tenant instead of defaulting to all tenants, avoiding accidental cross-tenant clears. |
|
change - Virtual Groups: entity filters reject structured payload fields |
The Virtual Group entity filter now rejects structured payload fields (status/SLA JSON messages, dynamic thresholds and similar) which are not meaningful filtering dimensions: the wizard warns as you type and blocks submission, and the API enforces the same rule server-side. |
|
change - Licensing: legacy free-extended tier decommissioned |
The legacy free-extended licensing tier is decommissioned, and NFR (not-for-resale) licenses are now surfaced explicitly in the license information. |
|
change - Dependency maintenance |
Third-party dependencies were refreshed in consolidated maintenance batches as part of the 2.4.8 cycle, and the unused webpack-dev-server development dependency (and its orphaned demo scaffolding) was removed from the UI build toolchain. |
Issue Number |
Description |
Details |
|---|---|---|
bug - Virtual Tenants overview could exhaust the browser at very large scale |
Opening the Virtual Tenants entities overview (or a Virtual Group) on very large environments loaded full entity records for every row and could kill the browser tab. These views now load slim payloads containing only what the tables render, and fetch the complete record on demand (row expansion, entity overview) — dramatically reducing memory usage with no loss of detail. |
|
bug - Search commands: late background updates could be silently dropped |
Background threads started late in the execution of several TrackMe search commands (summary registrations, KV updates) could be silently killed when the search process terminated, occasionally dropping updates. These operations are now performed synchronously by design, and a permanent safeguard prevents the pattern from being reintroduced. |
|
bug - FLX: concurrent hybrid trackers could overwrite each other’s entity fields |
When multiple FLX hybrid trackers updated the same entity concurrently, tracker executions could overwrite entity fields instead of merging them. Field updates are now merged correctly. |
|
bug - DHM: missing “Status reason” card on entities with quoted status messages |
DHM entities whose status message contained quoted content (for example ML outlier messages) showed an empty “Status reason” card — an escaping issue corrupted the message before display. The status reason now renders correctly, self-healing on the next entity view with no migration required. |
|
bug - AI Assistant: light mode honoured and close button always visible |
The AI Assistant panel could render in dark theme while the host page was in light mode, and the panel’s close button could become invisible. The panel now follows the application’s resolved theme on every page, and the header controls are theme-aware and always visible. |
|
bug - Hybrid tracker wizards: the tracker name input no longer fights the user |
Editing a tracker name in the creation wizards could trigger unwanted resets and repeated random-suffix injections while typing. The unique suffix is now applied once at creation only, and the name input behaves as expected. |
|
bug - Elastic sources: shared executor refreshes the UI cache after updates |
The shared Elastic sources executor did not refresh the UI cache after updating entities, leaving tables stale until the next full refresh cycle. The cache is now refreshed at the end of each shared Elastic cycle. |
|
bug - Configuration: default values aligned with shipped configuration |
Several settings declared default values that did not match the shipped configuration defaults, which could surface misleading values in the configuration interfaces. All defaults are now aligned and verified by an automated consistency check. |
|
bug - Licensing: a transient KV read error can no longer downgrade a valid license |
License validation now distinguishes a genuinely empty license store from a transient KV read error: a momentary KV-store blip could previously be read as “no license” and cause a valid subscription to be replaced with a Foundation trial. Errored reads are now treated as “state temporarily unavailable” and never mint a trial. |
|
bug - FLX: splk_queues_filling use case set the entity alias to the host instead of the queue |
The |
|
bug - FLX: library trackers drop spurious prefixes and emit true description arrays |
Corrects two Flex Object library issues where tracker names carried a spurious prefix and entity descriptions were emitted as a single joined string instead of a true array, improving how library-based Flex Objects are named and described. |
Version 2.4.7 - build 1783461509 (08/07/2026)¶
Hint
TrackMe 2.4.7 — AI Routines: your standing instructions to TrackMe, plus a full Configuration Guardian management experience.
AI Routines — describe a monitoring task in plain English, and TrackMe watches for it. Write a sentence like “tell me if 4 or more high-priority feeds turn red within 15 minutes, correlate what they have in common, and add a note to each entity” — or “every morning at 08:00, send me a plain-English digest of the tenant’s health: what is red, what changed since yesterday, and what deserves attention” — TrackMe compiles it into a structured instruction, runs it on the schedule you choose, and delivers the outcome as an email or a Splunk event, with real, audited actions if (and only if) you granted them. Three evaluation strategies put you in control of AI cost: Agentic (the LLM reasons on every cycle), Hybrid (a cheap SPL trigger gates the LLM — zero tokens when nothing is happening), and Deterministic (SPL computes the condition, the LLM formats the outcome). Start from a template or a blank intent, preview the exact workflow before anything is created, and dry-run it with Evaluate. Opt-in by construction, with a kill switch, a creator-roles policy, consent pinned to the exact permissions you approved, per-routine AI provider and timeout, full token-cost visibility and a dedicated activity audit dashboard. See AI Routines.
Configuration Guardian — now a full management experience. A new Check Catalog lets administrators enable/disable and tune every check, snooze alerts, and review severities with clear escalation ladders; a new degraded-tenant check detects tenants whose operations are impaired; and email notifications can be configured on alert lifecycle transitions — so Guardian findings reach you even outside the UI. An Ask-AI panel brings the AI Assistant directly to the Guardian page.
AI Advisors — stability. Advisors now start reliably on OpenAI providers (strict-mode tool schemas), and search-hosted interactive execution gains automatic resume of orphaned runs.
Faster and more resilient at scale. The Virtual Tenants page now loads its cached data in a single batched request (dramatically smaller responses, no more intermittent errors under heavy concurrent search load), and the global Support Diagnostic gains checkpoint/resume resilience with live step-by-step progress — it no longer gets stuck silently on large environments.
Fixes & polish. The AI Assistant now knows bulk actions accept wildcards, refreshed Google Gemini model suggestions, quieter logs on deployments without remote accounts, and a batch of minor hardening fixes from the previous cycle.
SHA256: 9c869f73ca158a1c8eb3fe14dad4dbce97b4696cdddb54893b8653e1167cea2c
Issue Number |
Description |
Details |
|---|---|---|
feature - AI Routines: scheduled natural-language AI tasks that watch, notify and (with consent) act |
Describe a monitoring task in plain English and TrackMe turns it into a standing instruction: compiled by the AI into a structured, reviewable form, executed on your cron schedule, and delivered as an email or a Splunk event — with real, audited actions when you have explicitly granted them. Each routine selects one of three evaluation strategies (Agentic, Hybrid, Deterministic) to control AI cost directly; Hybrid routines cost zero LLM tokens when nothing is happening. Includes a starter-template gallery, a workflow diagram previewing exactly how the routine will run, an Evaluate dry-run with iterative refinement, per-routine AI provider and execution timeout, write permissions scoped by capability family with consent pinned to what you approved, run statistics and per-routine token-cost visibility, and a dedicated activity audit dashboard. Opt-in by construction (inert until the AI Assistant is enabled and a provider is configured) with a system kill switch and a creator-roles policy. Requires Python 3.13 (Splunk 10.2.x+). See AI Routines. |
|
feature - Configuration Guardian: management UI, snooze and per-check tuning |
The Configuration Guardian gains a full management surface under the Configuration menu: a searchable Check Catalog where administrators can enable or disable each check, tune per-check thresholds, and snooze alerts; a reviewed severity model with critical tiers and visible escalation ladders; and an Ask-AI panel to reason about Guardian findings with the AI Assistant directly from the page. |
|
feature - Configuration Guardian: degraded-tenant check and email notifications |
A new native Guardian check detects tenants whose operations are degraded, and administrators can now configure email notifications on Guardian alert lifecycle transitions — so critical configuration findings reach the right people even when nobody is looking at the UI. |
Issue Number |
Description |
Details |
|---|---|---|
change - AI Advisors: search-hosted execution and orphan auto-resume |
Interactive AI Advisor runs now execute search-hosted for reliability, and runs orphaned by an interruption are automatically resumed instead of being lost. |
|
change - Support Diagnostic: checkpoint/resume resilience and live progress |
The global Support Diagnostic is rebuilt around a checkpoint/resume worker with automated retries and a live step-by-step progress view. On large environments it no longer gets stuck silently — progress is always visible, and failures are surfaced instead of hanging. |
|
change - AI Providers: refreshed Google Gemini model suggestions |
The Google Gemini provider suggestions and help text are refreshed for the Gemini 3.x family, including the |
|
change - Dependency maintenance and security updates |
Third-party dependencies were refreshed and two security advisories addressed as part of the 2.4.7 cycle. Routine updates: Security fixes: |
Issue Number |
Description |
Details |
|---|---|---|
bug - AI Advisors failed to start on OpenAI providers |
On OpenAI providers enforcing strict tool schemas, the AI Advisor agent could fail before starting. Tool schemas are now strict-mode safe, so advisors run reliably on OpenAI. |
|
bug - Virtual Tenants page could fail intermittently under heavy search load |
When many concurrent searches saturated the environment, loading the Virtual Tenants page could intermittently fail with server errors. The page now retrieves its cached data in a single batched request per page — dramatically smaller responses and no sensitivity to concurrent-search saturation. |
|
bug - Global Support Diagnostic could fail silently |
The global diagnostic could fail without surfacing any error, log or visibility of what happened. Failures are now surfaced with clear status, and the new checkpoint/resume worker prevents silent stalls. |
|
bug - AI Assistant refused wildcard bulk actions |
The AI Assistant chat was not aware that bulk actions accept |
|
bug - Noisy warning on deployments without remote accounts |
Deployments with no remote accounts configured logged a repeated warning about the remote-accounts configuration on every call. This normal state is no longer reported as a warning. |
|
bug - Batch of minor hardening fixes from the 2.4.6 review cycle |
Eight small fixes deferred from the previous release’s final review, including: the Workload overview “# Errors” card no longer shows an alert border when there are zero errors, the Remote Accounts force-rotation flow refreshes the rotation-logs view and restores keyboard focus, more consistent replica and threshold refresh behaviour, and assorted input-validation and display-fallback corrections (#2399, #2400, #2401, #2402, #2403, #2404, #2405). |
Version 2.4.6 - build 1782921685 (01/07/2026)¶
Hint
TrackMe 2.4.6 — Workload execution-error visibility, replica reliability, and estate-wide bulk actions.
Workload — see why a scheduled search failed. TrackMe now automatically captures and stores the actual execution-error messages of monitored scheduled searches (not just counts, and with no AI required), surfaces them in a dedicated Execution-errors view on the entity, and includes them in stateful-alert notifications — so an operator sees the root-cause error directly in the alert.
Workload — a redesigned Versioning experience. The Versioning metadata tab is rebuilt as a structured, filterable version history: each tracked change is shown as an expandable card with who changed it, when, and what changed, and a colour-coded before/after diff for every affected property — the search itself, but also non-search settings such as the schedule and time range. Summary cards (total versions, versions in range, latest version), a time-range selector, a free-text filter, and an “inspected … ago” freshness indicator make it easy to review exactly how a scheduled search evolved over time.
Full control over your Virtual Tenants landing page. TrackMe users can now organise the Virtual Tenants overview exactly the way they work — drag tenant cards, Virtual Group categories, and the groups within each category into any order (saved globally for all users), and the Administration menu is grouped into clear labelled sections. Together with the role-scoped Saved Views, this rounds out a rich cycle of Virtual Tenants enhancements that let each team land on a page tailored to their needs.
Replica trackers & tenants — a major reliability pass. Replicated entities are no longer re-evaluated locally (which could corrupt their state and cause them to disagree with the source); they now mirror the source state, their table display fields and status are restored, Tenant Home counters refresh immediately after a replica run, and the Manage/Execute replica screens are repaired with clear replica-context messaging.
Target whole families of entities in one action. Bulk operations across the REST API (including acknowledgements, logical groups and ML outliers) now accept
*/?wildcards, so you can act on an entire index, sourcetype family, or naming pattern in a single call instead of listing every entity.More helpful alerts & AI. Stateful-alert notifications now embed Workload error traces, disruption-grace states are labelled correctly, the AI status report stays informational (no un-actionable advisor prompts in one-way emails), and Claude Sonnet 5 is suggested as the default Anthropic model.
SHA256: b37864f49d8130296ceeef35567a12bd5c562430fe01a0445c159306cd15e280
Issue Number |
Description |
Details |
|---|---|---|
feature - Workload: automatic capture & surfacing of scheduled-search execution errors (no AI required) |
TrackMe now automatically stores the actual error messages produced by monitored scheduled searches and presents them in a dedicated Execution-errors view when you open the entity — no AI Advisor needed. The same error traces are also embedded in stateful-alert notifications, so you can see why a scheduled search failed straight from the alert. |
|
feature - Wildcard targeting for bulk actions across the REST API |
Bulk operations now accept |
|
feature - Custom display order for Virtual Tenants and Virtual Groups |
Administrators can now arrange tenant cards, Virtual Group categories, and the groups within a category in a curated global order (drag to reorder), instead of the fixed alphabetical layout. The Virtual Tenants Administration menu is also grouped into labelled sections for easier navigation. |
|
feature - New Flex Object use case: Cribl Logstream memory usage |
A new ready-to-use Flex Object use case monitors Cribl Logstream memory usage, sharing the tracked entity with the existing CPU-usage use case. |
|
feature - Remote Accounts: manual force bearer-token rotation |
The Remote Accounts Overview now offers a manual force token rotation action — for all accounts at once or a single account — so administrators can rotate remote bearer tokens on demand rather than waiting for the automatic schedule. |
Issue Number |
Description |
Details |
|---|---|---|
change - Workload: redesigned Versioning metadata experience |
The Workload Versioning metadata tab is rebuilt from a raw data dump into a structured, filterable version history. Each tracked version is an expandable card showing who made the change, when, which properties changed, and a colour-coded before/after (unified) diff for every affected property — the search SPL and non-search settings alike (schedule, earliest/latest time range, wildcard). The full search definition is always shown, even when the change was on a non-search field. The tab adds summary cards (total versions, versions in the selected range, latest version and its author), a time-range selector (24h / 7d / 30d / 90d / 1y / custom, with a graceful fallback to the full history), a free-text filter across definition/user/version id/diff, an “inspected … ago” freshness indicator, expand/collapse-all, copy version id, and an “Open in Search” pivot. All client-side over the data TrackMe already stores — no extra searches. |
|
change - Flex Objects: automatic default-metric backfill for older trackers |
Flex Object trackers created from the library before default metrics existed now have their default metric backfilled automatically on upgrade, so opening the entity shows a meaningful metric instead of a raw status. A library audit also added the missing default-metric definitions to the shipped use cases. |
|
change - Tenant Home: SLA drilldown opens the Audit SLA view inline |
Clicking the SLA percentage on Tenant Home now opens the Audit SLA view embedded as a modal, keeping you in context instead of navigating away. |
|
change - Prominent “Save pending changes” action on unsaved-changes banners |
The unsaved-changes banners on the ML Outliers models and thresholds screens now include a clear Save pending changes button, so pending edits are easier to commit. |
|
change - AI: Claude Sonnet 5 suggested as the default Anthropic model |
When configuring an Anthropic AI provider, Claude Sonnet 5 is now offered as the suggested default model. |
|
change - AI: support for gpt-5 and o-series reasoning models |
AI provider requests now use the correct token and temperature parameters for OpenAI gpt-5 and o-series reasoning models, so those models work without errors while classic models are unaffected. |
|
change - Flex Objects: retire the Splunk fields-quality use case |
The legacy Splunk fields-quality Flex Object use case has been removed, as its role is now fully covered by the Field Quality Monitoring (FQM) component. |
|
change - Dependency maintenance batch |
A consolidated third-party dependency maintenance batch was applied as part of the 2.4.6 cycle, keeping bundled dependencies current. |
Issue Number |
Description |
Details |
|---|---|---|
bug - Replica tenants: replicated entities could get a corrupted state |
On replica tenants, replicated entities were being re-evaluated locally, which could corrupt their state and make them disagree with the source (for example a replica showing green while the source was red). Replicated entities now trust and mirror the source state, and the shadow view is refreshed immediately after a replica run. |
|
bug - Replica entities: blank table fields and wrong red status |
Replica entities could show blank display fields in the table, and Outliers / Data-sampling could be shown red incorrectly. Display fields are now enriched while keeping the source state. |
|
bug - Replica execution did not refresh Tenant Home counters |
After a replica execution, the Tenant Home donuts and KPI cards stayed at 0 until the next health-tracker cycle. They now refresh immediately once the replica run completes. |
|
bug - Replica Virtual Tenants: Manage/Execute replica screens broken |
The Manage and Execute replica-tracker screens were broken and gave no replica-specific context. They are repaired and now clearly indicate the replica context. |
|
bug - Deleting a replica tracker could fail |
Deleting a replica tracker could fail with a server error when the request did not include the component. The delete now succeeds without it. |
|
bug - Replica wizard listed tenants without the required component |
The replica creation wizard’s source-tenant picker now only lists tenants that actually have the relevant component enabled. |
|
bug - Workload: non-search versioning changes were lost on re-inspection |
Workload versioning changes to non-search properties (schedule, earliest/latest time range, wildcard settings) were dropped from storage when an entity was re-inspected. All versioning differences are now preserved. |
|
bug - Adaptive delay skipped variable-delay-policy tenants |
Adaptive delay never selected entities using a variable delay policy, silently skipping them, and the delay flip-event investigation view could miss variable-delay breaches. Both now handle variable-delay entities correctly. |
|
bug - Adaptive-delay setting ignored when creating DSM/DHM tenants |
The adaptive-delay choice was not honoured during DSM/DHM tenant creation. The setting from the wizard is now applied. |
|
bug - Disruption-grace state mislabelled in flip events |
An entity held in a protective (blue) state by the disruption-queue grace period was mislabelled as logical-group protection in flip events. The state is now labelled correctly. |
|
bug - Stateful alert failed for entities with no chart-window metrics |
The stateful-alert action could fail when an entity had no component metrics in the alert’s chart window. This case is now handled and the alert completes. |
|
bug - AI status report proposed an interactive action inside a one-way email |
The AI status report embedded in stateful-alert emails could suggest running an interactive AI Advisor, which is not actionable in an email. The report now stays informational. |
|
bug - AI Concierge Advisor failed on every tenant |
The AI Concierge Advisor failed for each tenant because it looked up the tenant record by the wrong key. It now resolves the tenant correctly. |
|
bug - Noisy ML warning on empty input |
Native ML training/scoring logged a context-free warning on empty input. The message is demoted and enriched, removing the log noise. |
|
bug - Some changes were slow to appear in the entity table |
Configuration changes (blocklist, lagging-class and logical-group) and several Bulk edit actions now refresh the entity table immediately — the Status, Score and thresholds update at once instead of waiting for the next tracker cycle (so an action no longer looks like it “did not work”). A related logical-group refresh error for components a tenant does not use is also fixed. |
|
bug - Pretty-JSON command did not support array fields |
The |
|
bug - Cribl pipeline percentages could be blank on idle windows |
The Cribl Logstream pipeline use case could produce empty sent/dropped percentages when no events flowed in a window. The percentages are now guarded against division by zero. |
Version 2.4.5 - build 1782421503 (25/06/2026)¶
Hint
TrackMe 2.4.5 — expedited hotfix: AI Advisor on Splunk Cloud, and minor fixes
AI Advisor now starts reliably on Splunk Cloud (the reason for this release): on Splunk Cloud and Splunk hosted LLMs, the AI Advisor fails to start because Splunk’s bundled Python pointed at a certificate file that does not exist in the app’s runtime. The AI Advisor is now immune to this for every AI provider, while still fully verifying its HTTPS connections. The in-app AI Assistant chat was not affected. Customers using AI features on Splunk Cloud are encouraged to upgrade.
AI Assistant panel theme: the AI Assistant side panel no longer follows the operating-system theme instead of the TrackMe theme on some browsers, so it always matches the page.
Cleaner upgrades from 2.3.19: a harmless but misleading migration error that was logged on every cycle after upgrading from 2.3.19 is now resolved, and a few missing default labels are backfilled.
Acknowledgement indicator: enabling or disabling an acknowledgement in bulk now updates the indicator in the Tenant Home table immediately, completing the shadow-records follow-ups from the previous releases.
Dependency maintenance: the cycle’s batched dependency updates.
SHA256: f26f51c4a468338c270ceb2d5e4e64a857c15201211327da04c11a87bf965b16
Issue Number |
Description |
Details |
|---|---|---|
bug - AI Advisor failed to start on some Splunk Cloud search heads |
On some Splunk Cloud search heads, Splunk’s bundled Python advertises a certificate-bundle path that does not exist in TrackMe’s runtime context. The AI Advisor builds its HTTPS clients eagerly and passed that stale path straight to the TLS layer, causing a file not found failure before any advisor could run. The AI Advisor path is now made immune to a stale certificate path for all AI providers, with full HTTPS verification preserved. The AI Assistant chat was never affected. A small diagnostic command was also added to validate the certificate handling directly in a given environment. |
|
bug - AI Assistant panel rendered in the wrong theme on some browsers |
The AI Assistant side panel could render in the wrong theme (for example a light panel on a dark page) on Edge/Windows, because it followed the operating-system colour scheme instead of the TrackMe theme. The panel now consistently follows the application theme. |
|
bug - Misleading migration error after upgrading from 2.3.19 |
Tenants upgraded from 2.3.19 logged a harmless but incorrect schema-migration error on every cycle, and a few default labels were never seeded. The error is resolved and the missing default labels are backfilled automatically on upgrade. |
|
bug - Acknowledgement indicator could appear stale in the Tenant Home table |
Enabling or disabling an acknowledgement in bulk did not update the acknowledgement indicator in the Tenant Home table until the next tracker cycle refreshed it. The indicator now updates immediately, completing the same class of shadow-records fixes delivered in the previous releases. |
Version 2.4.4 - build 1782379508 (25/06/2026)¶
Hint
TrackMe 2.4.4 — Slipstream follow-ups, DHM & MHM reliability fixes, and minor corrections
Shadow records polish: a set of follow-up fixes to the 2.4.3 Slipstream read cache. Notes, entity maintenance and entity details now always reflect the latest state immediately, instead of occasionally showing a stale value until the next tracker cycle.
Silent metric hosts now raise alerts (MHM): a metric host that stopped sending all of its metrics could stay green forever with no alert. TrackMe now re-evaluates fully-silent hosts, so they turn red as expected and SLA and alerting follow.
More robust host coverage gap analysis (DHM): large reference inventories are now read in full, with no silent truncation, and matched more reliably. Hosts are no longer mis-reported as missing on either side.
MHM entity Overview tab restored: the per-entity Overview tab, broken since 2.3.16, works again.
Logical groups protected against accidental member removal: fixed a case where valid logical-group members could be wrongly purged on certain tenants.
Minor fixes: a half-width Workload chart is corrected, automated AI ML model review now also covers FQM and Workload entities, plus documentation and dependency maintenance.
SHA256: 520cce3c65fd78ec1f2cc5da84dfb7ae7e065323390ce051c5238a1e506d39b4
Issue Number |
Description |
Details |
|---|---|---|
change - Automated AI ML Advisor extended to FQM and Workload |
The automated AI ML model review now also covers Field Quality Monitoring and Workload entities, which already create ML outlier models. Automated review stays opt-in and off by default for these components, and the change also clears a harmless error that was logged when a tenant was deleted or disabled. |
|
change - Security and dependency maintenance batch |
A consolidated security and third-party dependency maintenance batch was applied as part of the 2.4.4 cycle, including security-relevant frontend dependency upgrades, keeping bundled dependencies current. |
Issue Number |
Description |
Details |
|---|---|---|
bug - Metric hosts that go fully silent stayed green with no alert (MHM) |
A metric host that stopped sending all of its metrics dropped out of the live monitoring window and stayed frozen in its last green state — no alert was raised and its SLA stayed at 100%. Partial interruptions were already detected; full silence was not. TrackMe now re-evaluates fully-silent hosts from their stored history, so they turn red as expected, SLA degrades and alerts fire, and they recover automatically when metrics resume. |
|
bug - Host coverage gap analysis unreliable on large inventories (DHM) |
When reconciling a large reference inventory against tracked hosts, very large inventories were silently truncated and some hosts were mis-reported as present in only one of the two sides. The full inventory is now read without truncation, and host matching is more robust, so the comparison is accurate even on very large inventories. |
|
bug - MHM entity Overview tab was broken |
The per-entity Overview tab for Metric Host Monitoring referenced a command removed in 2.3.16 and had been broken since. The tab now renders its metric breakdown correctly again. A build-time safeguard was also added to catch this class of broken command reference in the future. |
|
bug - Notes could appear stale in entity tables |
After adding, editing or deleting a note, the change could remain invisible in the entity table until the next tracker cycle refreshed it. Note changes are now reflected immediately. |
|
bug - Entity maintenance state could appear stale in entity tables |
Placing an entity into, or out of, maintenance could remain invisible in the entity table until the next tracker cycle. The maintenance state now updates immediately. |
|
bug - Entity SLA could be shown stale in detail views |
In single-entity detail views, the SLA indicator could display a stale value because it was read from a cached record instead of being recomputed. Detail views now always show the live SLA. |
|
bug - Tenant Home entity Overview modal showed incomplete details |
The entity Overview modal on Tenant Home could open with some detail fields missing because it rendered the lightweight table row. The modal now enriches the row with the full entity record before displaying it. |
|
bug - Workload Overview chart rendered at half width |
The Workload Overview chart could render at half of its available width inside a modal. The chart now measures its container correctly and uses the full width. |
|
bug - Logical-group members could be wrongly purged on some tenants |
On tenants whose component-enablement flags were stored in a particular format, the logical-group housekeeping task could mis-classify valid members as orphans and remove them. The check now interprets those flags consistently, so members are no longer removed by mistake. |
Version 2.4.3 - build 1782214134 (23/06/2026)¶
Hint
TrackMe 2.4.3 — Slipstream: a major performance & scalability initiative, configurable backups & S3 export, Saved Views, and AI advisor evolutions
Slipstream — performance & scalability initiative (the headline of this release): TrackMe now makes dramatically fewer REST round-trips on its hot paths, which is the dominant cost on large standalone and Search Head Cluster deployments. Dozens of redundant or sequential calls previously made by the user interface and the schedulers are now consolidated into a single load, resolved in-process, or removed entirely. At the centre of the initiative is the shadow filesystem cache — a local read cache that serves hot KV-store reads without a network round-trip — which is now enabled by default for every tenant (new tenants, and every qualifying existing tenant at upgrade). The result is a faster, lighter user interface and materially less pressure on the Splunk KV-store proxy layer, with no configuration required.
Saved Views: administrators can curate named, RBAC-scoped subsets of tenants and Virtual Groups, giving each team a focused view of only the tenants relevant to them.
AI advisor evolutions: a dedicated FQM dictionary-generation panel (choose the provider and add scoped instructions without a chat detour), natural-language generation of Flex Object trackers from the AI Assistant, support for the xAI (Grok) reasoning-effort parameter, and protection against AI automation running on tenants owned by nobody.
Configurable SLA calculation window: the SLA percentage time window (previously fixed at 90 days) is now configurable, for deployments where searches cannot run over the full default window.
Configurable backup directory: the backup root location is now configurable from the Backup & Restore settings (with environment-variable support) and falls back safely to the default location — raising a Configuration Guardian alert — if the configured path is ever unusable.
Backup retention managed from the UI: backup retention is now a setting in the Backup & Restore tab instead of being hard-coded in the scheduler search.
Optional S3 export of backups: backup archives can optionally be exported to an S3-compatible object store, with a built-in connectivity test and a fail-open design so a remote issue never blocks local backups.
SHA256: 045ed3670efb4e74259bdf0153d29ee5a6f453007fc4a20cb362368a06a6cb7c
Issue Number |
Description |
Details |
|---|---|---|
feature - Slipstream — REST round-trip reduction & shadow filesystem cache (enabled by default) |
A wide-ranging performance and scalability initiative that reduces the number of REST round-trips TrackMe makes on hot paths — the main constraint on large deployments. Many calls the UI and schedulers used to make individually are now consolidated into a single load, resolved in-process, or eliminated, and the shadow filesystem cache serves hot KV reads locally. Shadow records and the cache are now enabled by default for all tenants (new tenants and, at upgrade, every qualifying existing tenant), with no configuration required. The net effect is a snappier interface and significantly less load on the Splunk KV-store proxy layer. |
|
feature - Saved Views — curated, RBAC-scoped tenant subsets |
Administrators can define named Saved Views — curated subsets of tenants and Virtual Groups scoped by role — so each team lands on a focused view of just the tenants relevant to them instead of the full estate. |
|
feature - Configurable backup directory with safe fallback |
The location where TrackMe stores backup archives is now configurable from the Backup & Restore settings, with environment-variable support. If the configured directory is ever missing or not writable, TrackMe automatically falls back to the default location and raises a Configuration Guardian alert, so backups never silently stop. |
|
feature - Backup retention managed from the UI |
Backup retention (in days) is now managed as a setting in the Backup & Restore tab, rather than being hard-coded in the backup scheduler search. |
|
feature - Optional S3 export of backup archives |
Backup archives can optionally be exported to an S3-compatible object store. The integration includes a connectivity test and is fail-open by design, so an export or connectivity problem never blocks the local backup. |
|
feature - FQM — dedicated AI dictionary-generation panel |
Field Quality Monitoring gains a dedicated panel to generate a CIM-style field dictionary with the help of AI: pick the AI provider and supply scoped instructions directly, without going through the conversational assistant. |
|
feature - AI Assistant — natural-language generation of Flex Object trackers |
The AI Assistant can now turn a plain-language description into a ready-to-create Flex Object tracker: it proposes the search, constraint and KPIs, previews the matched entities, and lets the operator apply it through the existing wizard. |
|
feature - Configurable SLA percentage calculation window |
The time window used to compute SLA percentages — previously fixed at the last 90 days — is now configurable, for deployments where a workload rule or RBAC restriction prevents searches from running over the full default window. |
|
feature - Notes — optional validity period with automatic purge |
Entity and tenant notes can now be given an optional validity period, after which they are purged automatically — useful for time-bound operational annotations that should not linger. |
|
feature - Policies & coverage — richer CMDB lookup matching |
Lookup- and CMDB-based matching used by priority/tags/SLA policies and coverage gap analysis is now more expressive: multiple field mappings can be combined with OR/AND logic, the DHM |
|
feature - Coverage gap analysis — multiple host-column matching |
Host coverage gap analysis can now match against several host columns at once via OR-combined match blocks, so reference data that spreads identifiers across multiple columns is correctly reconciled. |
Issue Number |
Description |
Details |
|---|---|---|
change - Policies — faster, non-blocking simulation on large CMDBs |
Priority/tags/SLA policy simulation and apply no longer block or time out on large lookups: the simulation now runs asynchronously and the lookup matching is indexed, removing the previous slowdown (and nginx 504s) on large CMDBs. The UI also explains that wildcard match mode is significantly slower than exact matching. |
|
change - Bulk edit — lock the threshold in the same operation |
When bulk-editing DSM/DHM lagging policy or variable delay, the threshold can now be locked as part of the same operation (and the bulk selector defaults to Lock), so operators no longer need a second pass to pin their intent. |
|
change - ML Outliers — edit an existing period of exclusion |
An existing ML model period of exclusion can now be edited in place, instead of having to delete and recreate it. |
|
change - Configuration Guardian — Splunk Cloud SHC member self-heal |
For remote Splunk Cloud deployments, Configuration Guardian now detects and self-heals drift in the list of Search Head Cluster members of a remote account, and records an informational notice of the action taken. |
|
change - Per-entity maintenance — inline indicator |
Entities currently under per-entity maintenance now show a small icon next to the entity name, so an operator can see at a glance which entities are in a maintenance window. |
|
change - Virtual Tenants — per-tenant Clear operational status shortcut |
The Virtual Tenants page now offers a per-tenant shortcut to clear operational status, instead of having to open the tenant first. |
|
change - Flex Objects — graphical scope editor for converging trackers |
The converging-tracker edit modal now includes a graphical tenant/component picker and filter editor, making it easier to adjust the scope of a converging tracker without editing raw search syntax. |
|
change - AI providers — xAI (Grok) reasoning effort & refreshed models |
The xAI (Grok) provider now exposes a |
|
change - Audit — sortable tracker runtime table |
The tracker runtime table on the Trackers Performance audit page now has sortable column headers. |
|
change - Audit — show the Result field in the SLA Flip activity modal |
The SLA Flip activity modal now includes the Result field, giving more context on each SLA state change. |
|
change - AI audit dashboards — view full error messages |
Long error messages in the AI advisor audit dashboards are no longer truncated with no way to read them: the full text can now be opened in a modal. |
|
change - Support Diag — include ML outlier models |
Entity-scoped support diagnostics now collect the ML outlier models (rules, data and native model), making it easier to troubleshoot outlier behaviour with TrackMe support. |
|
change - Coverage gap analysis — surface skipped reference rows |
Coverage gap analysis now reports which reference rows were skipped because they were corrupted, instead of silently ignoring them. |
|
change - Health tracker — untracked entities evaluated every cycle |
Detection of untracked entities is promoted so it runs on every health-tracker cycle, surfacing newly untracked entities faster. |
|
change - AI automation — protection on tenants owned by nobody |
Automated AI advisor runs are now guarded against tenants whose owner is nobody (which previously failed with a privileged-execution error), and a persistent banner makes the condition visible so an administrator can reassign ownership. |
|
change - Consolidated security & dependency maintenance batch |
A consolidated security and third-party dependency maintenance batch was applied during the 2.4.3 cycle, keeping bundled frontend and backend dependencies current. |
Issue Number |
Description |
Details |
|---|---|---|
bug - AI status report failed on the Splunk-hosted LLM provider |
AI-generated status reports in stateful alerts could fail with an HTTP 413 error against the Splunk-hosted LLM provider when the prompt exceeded the provider’s 64k-token cap. The prompt is now bounded to stay within the cap, so the report is generated reliably. |
|
bug - Workload — scheduler KPIs reported in the wrong time window |
Workload (WLK) scheduler KPIs were stamped at tracker-run time rather than event time, so delayed or overlapping runs reported their metrics in the wrong window. KPIs are now stamped at event time and land in the correct window. |
|
bug - ML Outliers — could not define a future period of exclusion |
It was not possible to define a period of exclusion in the future, and the rejection message was misleading. Future-dated exclusions are now allowed and the messaging is clear. |
|
bug - DHM — asset field extracted a spurious value for IPv4 hosts |
The DHM |
|
bug - Flex Objects — Modify modal failed for legacy converging trackers |
The converging-tracker Modify modal returned a 404 for legacy trackers that predate the stored KV properties. These trackers are now resolved correctly and can be modified. |
|
bug - Tenant Home — excessive client-side CPU usage |
The Tenant Home page consumed excessive browser CPU due to leaked observers and a full-tree re-render every second. The page now refreshes efficiently, with much lower CPU usage on long-lived sessions. |
|
bug - Virtual Tenants — disruptive auto-refresh of the Entities Overview modal |
The automated refresh of the Entities Overview modal was visually disruptive (full-screen spinner, chart flash, tab reset). The refresh is now seamless and preserves the operator’s place in the modal. |
|
bug - Audit dashboards — missing inline search in dropdown filters |
Dropdown filters on the audit dashboards were missing the inline search box, making long lists hard to navigate. The search box is restored. |
|
bug - Virtual Tenants — spurious error when cancelling a loading modal |
Cancelling a still-loading modal surfaced a spurious “signal is aborted without reason” error. Cancellations are now handled cleanly without a misleading error. |
|
bug - Stateful alerts — broken embedded chart images |
Embedded PNG charts in stateful-alert notification emails could render as broken images after a charting-library update. The dependency is pinned to a compatible version so charts render correctly again. |
|
bug - DSM/DHM — delayed-inspector error on partial responses |
The delayed-data inspector could raise an internal error when an entity information lookup returned a non-200 response. It now handles partial responses gracefully. |
|
bug - UI — modal content flashing on close |
Several management and creation dialogs briefly flashed their content while closing. The dialogs now close cleanly without the flash. |
Version 2.4.2 - build 1781257469 (12/06/2026)¶
Hint
TrackMe 2.4.2 — ML training hotfix, Splunk-hosted LLM hotfix & minor evolutions
ML model training restored: a regression introduced in 2.3.22 left ML outlier model training fully broken across all components — the training search requested lookup output fields that no longer existed, so no model could be trained. This release fixes the upstream search and, as a safety net, now flags a tenant as degraded when a training or monitoring execution fails abnormally instead of failing silently. Customers using ML outlier detection are strongly encouraged to upgrade.
Splunk Cloud-hosted LLM provider fixed for AI Advisors: AI Advisors could not run against the Splunk-hosted LLM provider (SLIM) — the agent provider bridge mistakenly routed to
api.openai.com. Thesplunk_hostedprovider is now correctly wired into the bridge, and the Azure OpenAI provider contract has been repaired on the same path.Screen-adapted AI Assistant: the in-app AI Assistant now exposes context and pre-built questions adapted to the specific screen across the Tenant Home and Virtual Tenants administration modals, instead of a generic context.
Assorted UI & audit fixes: a searchable Permanently Deleted Entities modal, a corrected Trackers-performance deep-dive link, and a fix to the empty runtime-statistics chart for direct trackers.
SHA256: 137a9e47015e6b6f1155e83d011dd820619904dd2f5ea51ab4696ffb53d68e4b
Issue Number |
Description |
Details |
|---|---|---|
change - Tenant Home — screen-adapted AI Assistant context & questions |
The AI Assistant available across the Tenant Home administration modals now presents context and pre-built questions adapted to the active screen (44 AI-wired modals), instead of a generic context. Each modal surfaces suggested questions relevant to what the operator is configuring, making the assistant materially more useful in context. |
|
change - Virtual Tenants — screen-adapted AI Assistant context & questions |
The same screen-adaptation is applied to the Virtual Tenants administration screens: the AI Assistant context and its suggested questions are now tailored to the admin screen in use rather than a generic context. |
|
change - Permanently Deleted Entities modal — search bar |
The Permanently Deleted Entities management modal (Tenant Home) now includes a search bar, so administrators can quickly filter the list of permanently deleted entities instead of scrolling through it. |
|
change - Consolidated security & dependency maintenance batch |
A consolidated security and third-party dependency maintenance batch was applied as part of the 2.4.2 cycle, keeping bundled frontend and backend dependencies current. |
Issue Number |
Description |
Details |
|---|---|---|
bug - ML model training fully broken since 2.3.22 |
A regression introduced in 2.3.22 broke ML outlier model training across all components: the |
|
bug - Bulk Run ML Train / Run ML Monitor stopped mid-list |
When triggering ML training or monitoring in bulk from the UI, the operation could randomly stop part-way through the selection because the background thread was reaped by splunkd. The bulk action now runs as a durable detached search job, so it completes the whole list reliably. |
|
bug - AI Advisors failed with the Splunk-hosted LLM provider (SLIM) |
Running any AI Advisor against the Splunk-hosted LLM provider failed: the agent provider bridge routed requests to |
|
bug - AI Advisors failed with the Azure OpenAI provider |
On the same agent provider bridge, the Azure OpenAI provider contract was never applied (missing |
|
bug - Trackers-performance deep-dive opened a removed dashboard |
The Trackers-performance deep-dive link pointed at a classic dashboard that has been removed, opening a dead view and losing the prefilled context. The link now opens the native React Trackers Performance audit page with its context preserved. |
|
bug - Runtime statistics chart empty for direct trackers |
In the Virtual Tenants operational / scheduler status view, the runtime statistics chart was empty for direct trackers because of a tracker/wrapper metric-name mismatch. The chart now resolves the correct metric name and renders the runtime statistics as expected. |
Version 2.4.1 - build 1781039179 (09/06/2026)¶
Hint
TrackMe 2.4.1 — Threshold Lock, Topology graphs, Coverage gap analysis & audit dashboard rewrite
Unified Threshold Lock (DSM & DHM): a single, safer control replaces the former overlapping override lagging classes / allow adaptive delay / lock options. Locking an entity guarantees the operator’s intent — the pinned threshold (static or variable) is never silently overwritten by automation — and is clearly surfaced in the UI with a lock badge. A safety-net reconcile restores any drift and leaves an audit note explaining what was corrected.
Automatic Label Assignment: tenant admins can now define rules that automatically assign tenant labels to entities based on their lifecycle (discovered, enters alert, recovers) or a custom filter expression — with additive or self-reconciling removal — evaluated by the scheduled decision maker, so labelling no longer has to be done by hand.
Topology graphs for every component: a new built-in topology view shows the relationships between nodes (tenant → groups → entities) as interactive link and network graphs, now available for DSM, DHM, MHM, WLK, FQM and Flex Objects.
Coverage gap analysis (DSM & DHM): a new built-in UI compares TrackMe’s knowledge against a CMDB lookup or a live Splunk query in a few clicks, surfacing what is not covered (hosts, indexes, sourcetypes…) in both directions, each gap downloadable as a CSV.
DHM asset field: each host entity now carries a normalised set of all known identifiers (short name, FQDN, alias…), so lookup-based operations recognise a machine however it is named — used by both Inject Expected Hosts and the coverage gap analysis.
AI Feed Lifecycle Advisor — Data Sampling: the advisor now understands the DSM Data Sampling feature and can assist the generation of custom sampling rules (regex models) directly from sample events, surfaced inside the existing custom-rule wizard.
Adaptive delay: now surfaces its activity directly on entity nodes through automated summary notes, and drops its last dependency on the Splunk Machine Learning Toolkit native ML commands. TrackMe no longer requires the Splunk AI Toolkit nor the Python for Scientific Computing add-on.
Audit dashboards rewrite: all audit dashboard studios have been fully rewritten as native React user interfaces, with assorted UX improvements.
FLX converging trackers: improved visibility of the underlying member entities directly from the metrics inspect screen, plus UI-driven in-place modification of a converging tracker.
SHA256: 013e04a1e0ec459ac1b606e384b91479d3c23932faa672a0fdfee90bc481f280
Issue Number |
Description |
Details |
|---|---|---|
feature - Unified Threshold Lock for DSM & DHM thresholds |
A single Threshold Lock control replaces the former overlapping override lagging classes, allow adaptive delay and lock options on DSM/DHM entities. Locking an entity guarantees the operator’s intent: the pinned threshold — static or variable — is honoured and never silently overwritten by adaptive delay, variable-delay auto-review or lagging-class automation. The lock is clearly surfaced in the UI (a red lock badge on the entity, an explicit Lock & apply / Apply without locking confirmation when editing a threshold), and an independent safety-net reconcile restores any drift on a locked entity and writes an operator note describing what was corrected. A per-tenant master toggle ( |
|
feature - Automatic Label Assignment (rule-driven auto-labels) |
Tenant admins can now define rules that automatically assign tenant labels to entities, configured from Manage Labels → Automated and evaluated by the scheduled decision maker. Each rule fires on an entity lifecycle event — discovered, enters alert, recovers — or when an entity matches a custom filter expression, and can be scoped by priority and a filter DSL. Removal is per-rule: manual (the label is added and kept) or auto (the label is present only while the condition holds and is removed when it clears, touching only the labels that rule owns). The feature is additive and costs nothing for tenants with no rules. |
|
feature - Topology graphs for every monitoring component |
A new built-in topology view shows the relationships between nodes for DSM, DHM, MHM, WLK and FQM, reachable from the Tenant Home header (contextual to the active component). Each component uses a hierarchy that fits its data model (e.g. DSM: tenant → data index → entity; DHM: tenant → host → index → sourcetype). The modal offers link graph and network graph views with per-node status colours, search, All / Down / Up filtering and a member-node cap that keeps every group visible. Data is fetched only when a topology is opened. |
|
feature - Topology graphs for Flex Objects |
Extends the topology view to Flex Objects (converging and use-case trackers), with smarter topology entry points and a more accurate Flex hybrid tracker type so the relationships between Flex nodes are represented faithfully. |
|
feature - DHM Host coverage gap analysis |
A new Host coverage gap analysis tool reconciles a reference inventory (a CMDB lookup, or a live Splunk search via tstats/raw) against the hosts TrackMe actually tracks, and reports the gaps in both directions — hosts present in the reference but not tracked, hosts tracked but absent from the reference, and hosts covered on both sides. Matching is asset-aware (short name ⇄ FQDN), and each set is downloadable as a CSV. Launched from the Tenant Home DHM view. |
|
feature - DSM Feeds coverage gap analysis |
The DSM counterpart of the Host coverage gap analysis. Reconcile a reference (a lookup, or a live Splunk search) against the DSM feeds TrackMe tracks, on a configurable break-by grain (default |
|
feature - DHM asset field & asset-aware host recognition |
Each DHM host entity now carries an asset field — a normalised, deduplicated set of all known identifiers for the endpoint (the tracked object, the bare value, the short hostname extracted from an FQDN, and the alias). This lets TrackMe recognise a machine however it is named: Inject Expected Hosts now matches incoming lookup rows against the asset field (short ⇄ FQDN aware, on by default), avoiding duplicate host entities, and the same normalisation powers asset-aware lookup comparisons across the product. |
|
feature - AI Feed Lifecycle Advisor — Data Sampling awareness & assisted model generation |
The AI Feed Lifecycle Advisor now understands the DSM-only Data Sampling feature: it can read per-entity sampling state and existing rules, so an entity that is orange/red because of a sampling anomaly is diagnosed correctly. It can also assist the generation of custom sampling rules — reasoning over loaded sample events to propose a regex format model (name, regex, type, scope) that the operator reviews and applies directly inside the existing Create Custom Rule wizard. Surfaced naturally through the AI chat bridge and suggested-question chips. |
|
feature - FLX converging trackers — member visibility & in-place modify |
FLX converging trackers gain a searchable Tracked entities view — surfaced both from the per-row menu and directly from the metrics inspect screen — listing every member entity with its state and up/down convergence, an All / Up / Down filter, and a per-row drilldown into each member’s own tenant. A new Modify converging tracker modal also allows editing the scope, member filter, min-green % and orange-as-up settings from the UI, without hand-editing the underlying search and while preserving the entity’s history and models. |
Issue Number |
Description |
Details |
|---|---|---|
change - Audit dashboards rewritten as native React UIs |
All audit dashboard studios have been fully rewritten as native React user interfaces, with assorted UX improvements: Tenants Operational Status (#1904), Trackers Performance (#1906), KVstore collections (#1908), SVC usage (#1910), Data Sampling (#1900), and the adaptive delay threshold audit dashboards unified into a single UI (#1898). |
|
change - SLA compliance reporting rebuilt as a single React-native page |
The SLA compliance reporting overview and its flip drilldown — previously two separate Dashboard Studio views — are now a single native React page. Clicking an object opens its flip activity in an in-place modal (count, over-time chart and transitions table) instead of a new browser tab, keeping context. The existing entry points (Virtual Tenants Open SLA overview and the Tenant Home SLA PCT KPI) are preserved. |
|
change - AI Assistant available in the ML Outliers tenant-scope modal |
The Manage: ML Outliers scope modal now exposes the in-header AI Assistant trigger, consistent with the other Tenant Home admin modals, with context-adapted suggested questions to help configure the priority filter, the filter-expression DSL and the Volume KPI override. |
|
change - Adaptive delay no longer depends on the Splunk Machine Learning Toolkit |
Adaptive delay now uses TrackMe’s native density function in place of the residual MLTK |
|
change - Adaptive delay surfaces its activity through automated summary notes |
When adaptive delay updates an entity’s threshold, it now automatically writes a Markdown summary note on the entity describing the change, so its activity is visible directly on the entity node. Extended to the variable-delay slot path (#1890). |
|
change - AI wizard modes — additional-instructions textarea on the consent card |
The AI wizard consent card now offers an optional pre-launch additional instructions textarea, letting the operator pass extra guidance to the advisor before the run starts. |
Issue Number |
Description |
Details |
|---|---|---|
bug - Adaptive delay never ran for variable-delay entities |
Adaptive delay was unintentionally disabled for variable-delay entities ( |
|
bug - Adaptive delay produced no threshold on the native engine |
Following the move from MLTK to the native density engine, the computed upper bound was always 0, so adaptive delay silently produced no usable threshold. The native computation now returns the correct value. |
|
bug - AI Assistant read several tenant settings from the wrong source |
The AI Assistant’s describe layer read a number of tenant settings (CMDB, delay policy, impact score, monitoring, default priority) from a stale source, so they always appeared at their default values. The values are now read from the authoritative record and reported correctly. |
|
bug - Health tracker re-asserted shadow enablement every cycle |
The health tracker re-applied the shadow-enablement setting on every cycle because it read the value from the wrong source. It now reads the authoritative record and only acts when the setting actually changes. |
|
bug - Tenant Knowledge Objects — Open in manager hid saved searches & alerts |
The Open in manager action could hide saved searches and alerts with an empty owner (rewritten to the current user). Ownership is now preserved so the objects are listed as expected. |
|
bug - Tenant Knowledge Objects — transforms filter returned no rows |
The transforms kind in the Tenant Knowledge Objects filter never returned any rows. The filter now resolves correctly and lists the matching objects. |
|
bug - FQM wizard — AI dictionary generation failed when invoked too early |
Generating the data dictionary with AI in the FQM wizard could fail with an HTTP 400 error when invoked before the prerequisites were ready. The action now waits for the required context and succeeds. |
|
bug - FLX converging tracker wizard — duplicate label |
The FLX converging tracker wizard displayed a duplicate Up/Down entities: label. The redundant label has been removed. |
|
bug - Inconsistent component naming in backend logs |
Backend logs referred to components inconsistently (short form vs the |
Version 2.4.0 - build 1780402698 (02/06/2026)¶
Hint
TrackMe 2.4.0 — AI Agents (TrackMe Agentic, GA)
AI Advisors (GA): six AI agents inspect TrackMe’s monitored entities, propose grounded recommendations, and — in act mode, with consent — apply them through TrackMe’s REST API. ML Advisor (outlier models), Feed Lifecycle (DSM/DHM thresholds), FLX Threshold, FQM (field quality + data dictionary), Component Health (WLK/MHM), and the catalog-driven Concierge.
Inspect by default: every advisor runs read-only first and emits typed recommendations; act mode applies changes and verifies each write. Write tools are absent from the agent in inspect mode.
AI Assistant ↔ Advisor bridge: the chat proposes an advisor as a one-click consent card, launches it inline with the session’s resolved entity/tenant context, and renders the structured result — the chat never calls a write tool directly.
AI Concierge: a catalog-driven generalist grounded in the live REST API; zero static write tools — every action is a consent-card click, with per-action typed confirmation for destructive operations.
AI Agents automation: per-tenant scheduled advisor runs, scoped by priority / freshness filters, with a decommission guard disabled by default.
Audit: two dashboards — Review AI Advisor activity and Review Scheduled AI Advisor activity — plus an
[AI Agent]prefix on every entity write.AI Provider accounts: configure one or more providers — OpenAI, Azure OpenAI, Anthropic, Google Gemini, Mistral, Ollama, Splunk Hosted (SLIM API), xAI — with optional Anthropic prompt caching.
Compatibility: fully opt-in and fully compatible with all supported Splunk releases. The AI Advisors require Splunk 10.2.x and later (Python 3.13.x); the AI Assistant and AI Concierge run on Python 3.9.x and later. TrackMe blocks an advisor on an incompatible release, and the Assistant will not propose one.
Smart Status retired: superseded by the AI Advisors; schema migration
2401removes the legacy Smart Status collection on upgrade.Non-AI fixes: restored shared-library logging traces in the REST request path, KV de-duplication and pagination correctness, an
object_idalias on write endpoints, per-entity maintenance mode, browser-local time display for variable-delay/threshold slots, and a SplunkUI dependency pin.See the new Artificial Intelligence documentation section.
SHA256: 4b203a4e681ae63cd0bd62bfc781bc6f3a427d69c4eb7fdc7d25eb9f350c8bfd
Issue Number |
Description |
Details |
|---|---|---|
feature - AI Advisors (TrackMe Agentic) — six AI agents with inspect / act modes |
Introduces six LLM-powered advisors built on a shared Splunk Agent SDK runtime ( |
|
feature - AI Assistant ↔ Advisor bridge and AI Concierge |
The AI Assistant proposes an advisor as a typed action contract rendered as an inline consent card (Run now / Inspect-only first / Cancel), launches it with the chat session’s resolved entity/tenant context (never LLM-constructed identifiers), shows a live tool-call feed and renders the structured result — the chat never calls a write tool directly. The AI Concierge is a catalog-driven generalist grounded in the live TrackMe REST API with zero static write tools: it proposes structured action contracts that fire only on the user’s Confirm click, with per-action typed confirmation for destructive operations. See The AI Concierge. |
|
feature - AI Agents automation, audit dashboards and AI Provider accounts |
Manage AI Agents automation configures per-tenant scheduled advisor runs (enable each advisor independently, pin a provider, set priority / SLA / tag filters and custom instructions, set operational caps; decommission disabled by default). Manage AI Provider accounts supports OpenAI, Azure OpenAI, Anthropic, Google Gemini, Mistral, Ollama, Splunk Hosted (SLIM API) and xAI, with optional Anthropic prompt caching. Two audit dashboards — Review AI Advisor activity (interactive + automated) and Review Scheduled AI Advisor activity (scheduled-only, with an hour-of-day cadence histogram and a per-tenant × advisor last-run matrix) — record every run to the summary index. See AI Agents automation, Auditing AI activity and Configuring AI Provider accounts. |
|
feature - Per-entity maintenance mode (force BLUE for a window) |
New per-entity maintenance window that forces a single entity into |
|
feature - Variable-delay / FLX variable-threshold slots shown in browser-local time |
Variable-delay slot hours and FLX variable-threshold slot hours now display in the browser’s local timezone (with a UTC-offset annotation) instead of raw UTC. Storage is unchanged — UTC remains canonical in KV; the conversion is render-side only. |
Issue Number |
Description |
Details |
|---|---|---|
change - Smart Status retired — replaced by the AI Advisors (schema migration |
Smart Status is fully removed and superseded by the AI Advisors, which produce richer, more actionable recommendations. Schema migration |
|
change - REST — accept |
Write REST endpoints now accept |
|
change - Splunk Agent SDK integration, Anthropic prompt caching and agent reliability hardening |
Pins |
Issue Number |
Description |
Details |
|---|---|---|
bug - Logging — restore shared-library traces in the REST request path |
After the 2.3.24 logging-hygiene change removed a root-logger redirect from every REST handler, library-level log calls made during a REST request silently vanished (e.g. tenant creation logged only two events, without the per-object creation traces). A new |
|
bug - KV — consistent de-duplication identifier in full-collection read helpers |
Four full-collection KV read helpers tested membership on |
|
bug - KV — byte-cap pagination short-page guard re-applied |
Re-applies the byte-cap pagination short-page guard on |
|
bug - SplunkUI — Outliers time-range picker crash ( |
The TenantHome / Outliers time-range picker crashed with |
Hint
TrackMe 2.3 — Major UI Modernization Release
We are pleased to introduce our fully redesigned user interfaces.
This release represents a major step forward in performance, scalability, and user experience.
With TrackMe 2.3, all of user interfaces are now built on top of Splunk UI native React.
This is a complete and full rewrite of TrackMe main user interfaces, which we are excited to share with you.
Many various improvements and enhancements were implemented to fully support the new interface, and to ensure a smooth transition from the old Splunk stack JS to a modern and native React UI.
Hint
Impact-Based Alerting (IBA), a new scoring-driven alerting model now powering TrackMe.
IBA replaces rigid, hard-coded alerting rules with a flexible and configurable impact scoring system, inspired by security-grade risk-based approaches and adapted to data reliability and observability.
With IBA, TrackMe now: - Aggregates anomaly impact over time instead of reacting to isolated signals - Allows fine-grained tuning of how different anomalies contribute to entity health - Provides full transparency with detailed score breakdowns and traceable score events - Significantly reduces alert noise while preserving operational confidence
The transition is seamless for existing users, requires no manual intervention, and is fully configurable through the UI.
Version 2.3.24 - build 1779386252 (21/05/2026)¶
Hint
TrackMe 2.3.24 — Stabilization: logging hygiene, restored DHM per-host blocklists, FLX self-heal & Outliers continuity
Logging hygiene — schema-upgrade visibility restored: a long-standing root-logger hijack (since 2.3.22) silently redirected the Health Tracker’s schema-upgrade logs into the wrong log file. Health Tracker activity is back where operators expect it, and six previously-unmapped custom-command log files now show up under their proper
trackme:custom_commands:*sourcetypes.DHM per-host blocklists — restored in React UI: the per-host index / sourcetype blocklist editor lost during the 2.3 React migration is back, with wildcard matching, suggestion-driven Multiselects, and shortcut buttons from the DHM Inspect modal.
FLX entities — self-heal for pre-2.3.12 upgrades: entities upgraded from <2.3.12 carried stale top-level keys that broke the
splk_hosts_trackingandcribl_edge_fleet_metricstemplates. Auto-heals on the next tracker cycle — no migration needed.FLX Outliers continuity on inactive entities: the inactive tracker now emits zero-value KPI metrics for inactive entities so the Outliers chart keeps a continuous timeline through inactivity windows.
FLX thresholds UX: shared Configuration Guide across the FLX / FQM / WLK threshold modals. The FLX add form gains a Variable schedule switch so a variable threshold can be created in one step.
DSM merged-mode (``:@all``) remediation now lands: the sourcetype-cap safeguard no longer silently drops new
<index>:@allaggregates, so the documented blocklist + re-cover with one aggregate remediation path works again.Performance — initial threshold seeding: FLX / FQM / WLK trackers’ first-run seeding is now batched into a single round-trip — typical 10-100× speed-up on tenants with hundreds of entities.
AI Provider — discover models on Splunk Hosted: the Discover models button in Manage AI Providers now correctly populates the model selector for the Splunk Hosted (SLIM API) provider.
Security & dependencies: bumps for
wsandwebpack-dev-server(security advisories) plus a bundled Dependabot update.
SHA256: 032852076bcfbda5f7157af439cf04551f5c649b382c5a7a90d65892eb52b3ce
Issue Number |
Description |
Details |
|---|---|---|
feature - DHM per-host index / sourcetype blocklists — restored in React UI with wildcards, Multiselect and immediate apply |
Restores the DHM-only per-host blocklist editor that was lost during the 2.3 React migration. The editor is reachable from the entity Actions → Modify menu, from the bulk-edit Per-host Blocklists category, and from two new shortcut buttons (Manage blocklists, Reset) on the DHM Inspect modal footer (power+ users only). The matcher now supports wildcards ( |
|
feature - FLX thresholds — Configuration Guide and inline variable-schedule mode |
The FLX, FQM and WLK threshold modals now share a richer Configuration Guide with three sub-sections — How thresholds work, Field reference and (FLX only) Variable thresholds — plus an inline impact-score scale showing the green / orange / red bands. The FLX add form gains a Variable schedule switch: when on, the primary button relabels to Configure schedule… and opens the time-slot editor pre-filled with the form’s value / operator / score, so a variable threshold can be created in a single round-trip rather than creating a static threshold and then editing it. The add form is locked while the schedule editor is open so user input between clicks cannot be silently lost. |
|
feature - FLX — Outliers continuity on inactive entities via zero-value KPI emission |
When an FLX use case’s upstream SPL stops returning rows for a known entity, TrackMe correctly flips it to red after |
Issue Number |
Description |
Details |
|---|---|---|
performance - Batch-save initial threshold / drilldown / default-metric seeding on FLX / FQM / WLK tracker first execution |
The first-execution seeding paths on FLX, FQM and WLK trackers (initial threshold records, drilldown records, default-metric records) used per-record query+insert loops, producing O(N) round-trips when seeding tenants with hundreds of entities. The five affected code paths now use a single broad pre-load plus a single |
|
change - Security & dependency bumps |
Two security-relevant Dependabot bumps and one bundled update. |
Issue Number |
Description |
Details |
|---|---|---|
bug - Logging hygiene — Health Tracker schema-upgrade activity silenced from 2.3.22 onward |
Closes a long-standing root-logger-hijack chain that silently redirected the Health Tracker’s schema-upgrade slow-path logs into the wrong log file from 2.3.22 onward — the migration itself ran correctly, but operator-facing activity logs disappeared (~hundreds of |
|
bug - FLX entities — self-heal for pre-2.3.12 upgrades and safer template placeholder |
FLX entities upgraded from a pre-2.3.12 install carried stale top-level fields ( |
|
bug - Manage AI Providers — Discover models leaves the selector empty on Splunk Hosted |
Clicking Discover models on a Splunk Hosted (SLIM API) provider succeeded against the backend — the underlying REST call returned 200 with a non-empty model list — but the model selector dropdown stayed empty and the N model(s) discovered caption never appeared. The frontend mapper was looking for |
|
bug - DSM — sourcetype-cap safeguard silently dropped |
The DSM sourcetype-explosion safeguard silently dropped new merged-mode |
Version 2.3.23 - build 1779189227 (19/05/2026)¶
Hint
TrackMe 2.3.23 — Lookups monitoring, Backup & Restore v3 hardening, SLA correctness and DHM per-host extras
Lookups monitoring (DSM): new
lookupssearch mode in the Hybrid Trackers wizard. CSV files and KVstore collections become first-class DSM entities, with delay-based alerting and volume tracking. Supersedes the previous Elastic-source approach. Requires the dedicatedTA-trackme-lookupmonitoradd-on. See Lookup monitoring.Backup & Restore v3 — hardening at scale: consolidated fixes after SHC field testing of 2.3.22. Stuck SHC-local restores, mis-classified imported archives, parallel schema-upgrade backup storms, disruptive UI delete on a per-archive basis, and host-identifier drift are all fixed; orphan sidecars and run manifests are cleaned up by the retention sweep; the download selector becomes a cascading run → archive picker.
SLA correctness — orange no longer counts as breach: SLA compliance and
percent_slaare now computed against time not in critical (red) state. Warning (orange) is treated as compliant. The same red-only semantics apply to the Tenant Home “in alert” KPI tiles, so tile counts, click-filtered tables and Open in Search now agree on a single definition.DHM per-host extras: new
breakby_extra_fieldsoption to extend the per-host combo grain beyond(index, sourcetype)with extra metadata fields (e.g.source). Useful when a host produces multiple distinct event streams.Variable / adaptive delay — honour existing slots: auto-compute and adaptive delay now refresh thresholds inside an entity’s existing slot layout instead of regenerating it. Adaptive delay can also heal variable-delay entities automatically.
Two new FLX use cases (Splunk infrastructure):
splk_bucket_health_per_index(per-index bucket health viadbinspect) andsplk_parsing_issues_per_component(Splunk indexing-time parsing failures from the three pipeline components). Both ship with default dynamic thresholds and one-click drilldowns.UX polish: AI Assistant empty state links directly to the in-app provider configuration; Blocklist views gain inline search and bulk actions; lag-monitoring modals show a banner when adaptive delay last refreshed the threshold; the AI Assistant icon now appears on the Events format recognition child modals.
Various fixes & hygiene: FQM wizard Benchmark sampling mode honours the sampling ratio on LOCAL tenants; Ops → Parsing issues and Data Parsing Quality panels work again on newer Splunk versions; two high-volume INFO log lines demoted to DEBUG; forward-compat regex cleanup across the licensing handler, the OOTB regex library and the URL validator.
SHA256: 0a81dde6580e1fe631f57dbedce32aa08c8cc1b1061831be34444b2851189187
Issue Number |
Description |
Details |
|---|---|---|
feature - Lookups monitoring as a first-class DSM entity type |
A new |
|
feature - DHM |
DHM hybrid trackers gain an optional |
|
feature - Variable delay & adaptive delay — honour existing slot layout |
The Variable delay threshold modal auto-compute previously regenerated the slot layout from scratch every time, replacing hand-crafted layouts (business-hours / nights / weekends, tenant-customised templates, …) with anonymous |
|
feature - Two new FLX pre-built use cases — Splunk bucket health & parsing issues |
Two new ready-to-use Splunk Flex Objects use cases under the |
Issue Number |
Description |
Details |
|---|---|---|
enhancement - AI Assistant — broader provider examples and direct link to in-app configuration |
On a fresh install with no AI provider configured, the AI Assistant empty state used to mention only one or two example providers and offered no actionable path to set one up. The empty state now lists a broader, more representative set of provider examples (Anthropic, OpenAI, Azure OpenAI, Splunk Hosted, …) and includes a direct link to the in-app Manage AI Providers page, so a fresh install is no longer a dead end. |
|
enhancement - Blocklist views — inline search bar with bulk-action support on the filtered subset |
Blocklist management views gain an inline search bar so operators can narrow down on deployments with hundreds of entries. Bulk actions (e.g. remove from blocklist) now operate on the filtered subset, so an operator can search for a hostname pattern and remove all matching entries in one round-trip rather than scrolling and clicking individually. |
|
enhancement - Lag monitoring & Variable delay modals — banner when the threshold was last refreshed by adaptive delay |
The Lag monitoring policy modal (DSM, DHM) and the Variable delay threshold modal show a new info banner whenever the entity’s delay threshold was last refreshed by the adaptive-delay backend. Operators no longer have to dive into the audit index to tell whether the current threshold was set manually or bumped overnight by adaptive delay. The banner clears immediately when the operator manually overrides the threshold, so it stays honest. Suppressed in bulk-mode modals. |
|
change - Regex hygiene — forward-compatibility cleanup |
Forward-compatibility cleanup of regex patterns across the licensing handler, the out-of-the-box data-sampling regex library (37 patterns audited, 25 updated), and the |
|
change - Logging hygiene — demote two high-volume INFO traces to DEBUG |
Two hot-path log lines that produced large amounts of low-value INFO traffic are now logged at DEBUG, so operators running at the default |
Issue Number |
Description |
Details |
|---|---|---|
bug - Backup & Restore v3 — consolidated hardening for SHC and at-scale deployments |
Consolidated fixes for the v3 backup & restore subsystem after SHC field testing of 2.3.22. (1) SHC-local async restores no longer leave restore jobs stuck in a running state — the job now reliably reaches a terminal status regardless of how Splunk recycles its REST handler subprocesses. (2) Archives exported / imported between TrackMe instances are no longer silently classified as legacy on the target; the 3.0.0 metadata is preserved through registration and imported runs group correctly in the UI. (3) The schema-upgrade safety backup is now serialised through a per-cluster lock, so a release upgrade fires exactly one safety backup instead of N parallel ones racing each other. (4) The Backup & Restore UI no longer blanks the archive table on every per-archive delete and is SHC-aware, so every peer sees every archive regardless of which peer produced it. (5) A host with FQDN ≠ short hostname no longer appears under two different identifiers in the archive list. (+) The download selector becomes a cascading run → archive picker with an inline filter; the retention sweep now cleans up orphan sidecars and run manifests alongside the archive itself. |
|
bug - SLA compliance — warning (orange) was treated as breach time |
SLA compliance and |
|
bug - Tenant Home — “in alert” KPI tiles, click-filtered table and Open in Search now agree on red-only semantics |
The three Tenant Home “in alert” KPI tiles on every component tab (ANY / HIGH / CRITICAL PRIORITY) had a visible inconsistency between the tile count and the click-filtered table: HIGH and CRITICAL tile counts were red-only on the backend but the click-filtered tables included orange, while the ANY PRIORITY tile counted red + orange on both sides. All three tiles, their click-filtered tables, the Open in Search SPL and the toast wording are now red-only and agree on a single count. The donut chart “by state and priority” view keeps orange as its own slice (it is a state breakdown, not an alert filter). Functionally paired with the SLA orange fix above. |
|
bug - FQM hybrid-tracker wizard — Benchmark sampling mode ignored the selected sampling ratio on LOCAL tenants |
In the FQM hybrid-tracker wizard step 7 Collect job strategy, the Benchmark sampling mode button was dispatching the same un-sampled SPL as Head mode on LOCAL-account tenants, ignoring the configured sampling ratio. Both panels returned identical event counts and the Open in Search link showed “No Event Sampling” — actively misleading operators sizing the collect strategy on high-volume datasets. The wizard now passes the sampling ratio as a job-dispatch parameter on the benchmark and forwards it to Open in Search, so both surfaces honour the configured ratio. The tracker created in step 9 was always unaffected. |
|
bug - Events format recognition — AI Assistant icon missing from the custom-rules list and create-rule wizard |
The AI Assistant icon was missing from two child modals of the Data sampling & events format recognition feature — the custom regex rules list and the 7-step create-rule wizard — so operators lost access to the assistant mid-flow. The icon now appears on both child modals when |
|
bug - Ops Parsing issues & Data Parsing Quality — empty panels on newer Splunk versions |
Two TrackMe macros — |
Version 2.3.22 - build 1778523370 (11/05/2026)¶
Hint
TrackMe 2.3.22 — Backup & Restore v3, AI Provider UI, unified AI Assistant UX & Audit AI Assistant
Backup & Restore v3: new multi-archive format — one independent archive per tenant plus one global, per-archive isolation, SHC-aware, with a redesigned restore UI.
AI Provider management UI: dedicated in-product page replaces the UCC tab, with provider-aware forms and on-demand connectivity tests.
AI Assistant — unified UX: compact side-drawer everywhere, horizontal resize, chat history & provider selection persist per page, icon added to all remaining modals and Virtual Tenants admin screens.
Audit AI Assistant: new admin dashboard with per-tenant KPIs, breakdowns and recent-runs / errors / skip-reasons drilldowns; activity also indexed for long-term reporting.
In-page tenant configuration editor: grouped, searchable editor for per-tenant settings, reachable from the 3-dot menu — no more UCC tab round-trip.
Per-tenant username allowlist: server-enforced visibility list to keep under-development tenants hidden from the wider org.
Hide-tenant safety net: confirmation modal with explicit recovery instructions.
DHM ‘merged’ break-by mode and DSM/DHM ‘none’ tstats span: two tracker performance options for large estates.
Bulk edit — Disruption Queue: apply the same grace period to many entities in one round-trip.
Inline search everywhere: long-list dropdowns and multiselects across React views now support type-to-filter; lookup policy modals default to Wildcard match.
Critical bug fixes: AI status report in stateful alerts, tenant SV cache freshness, phantom KV records in bulk-edit, SOAR failover credential corruption, Anthropic Opus 4+ connectivity, several FQM wizard inputs, Outliers simulation time range.
Audit coverage hardening:
update_commentand audit events now consistent across licensing, policy-apply, configuration, maintenance and component-power endpoints.Logging hygiene: noisy INFO perf logs demoted, cross-handler log leaks fixed,
SyntaxWarninglines insplunkd.logcleaned up.Security & dependencies: patched
@babel/plugin-transform-modules-systemjsandfast-uri(both high) plus a Dependabot bundle.
SHA256: ae138f42b2f222a41e3cd46b78a2499baf38305d71af230ec2cd4ff3f144613f
Issue Number |
Description |
Details |
|---|---|---|
feature - Backup & Restore v3 — multi-archive format, SHC support, redesigned UI |
The Backup & Restore subsystem has been redesigned around a new |
|
feature - Dedicated TrackMe AI Provider management UI |
AI LLM provider accounts (Anthropic, OpenAI, Azure OpenAI, Splunk Hosted, …) are now managed from a new in-product page — Manage AI Providers — reachable from the TrackMe navigation. The page replaces the Splunk UCC |
|
feature - Audit AI Assistant — admin dashboard for AI Assistant activity |
A new admin-grade React page — Review AI Assistant activity (nav: Artificial Intelligence → Review AI Assistant activity) — surfaces, per tenant and over a configurable time range, total runs, success / error / skipped rates, total tokens, average duration, and active-tenants count. Breakdown panels split activity by kind (interactive chat vs. stateful-alert status report), by status, by context (which page launched the chat), and by provider · model. Drill-in tables list recent runs (with full per-event detail — kind, context, status, tenant, object, provider, model, user, duration, tokens), recent errors only, and status-report skip-reasons (with |
|
feature - Non-disruptive AI Assistant everywhere (compact side-drawer mode) |
Until now, the AI Assistant opened in two different modes depending on the entry point: a disruptive full-screen view when triggered from a page-level menu (Tenant Home, Virtual Tenants, Maintenance Mode, …) and the more recent non-disruptive side-drawer when triggered from wizards. The compact side-drawer is now the only mode — every entry point opens the assistant as a ~460 px panel on the right while the underlying screen stays visible and interactive, so users keep their place and can cross-reference the page they were working on. |
|
feature - AI Assistant icon on Virtual Tenants admin screens |
The AI Assistant icon (next to the modal × close button) is now present on every Virtual Tenants admin entry point reachable from the page-level Administration menu — Create a tracking tenant welcome modal and the multi-step wizard layout (FeedsDsm / FeedsDhm / FeedsMhm / FLX / FQM / WLK), Create a new replica tenant, Create a virtual group, Scheduler status view, and Operational status view. Users starting a new tenant or virtual group, or reviewing scheduler / ops status, can now ask the assistant questions without leaving the screen. |
|
feature - AI Assistant icon on remaining Tenant Home modals (hybrid trackers & elastic sources) |
Completes the AI Assistant icon rollout across Tenant Home modals. The icon is now present on every hybrid-tracker modal — welcome chooser, manage list, and execute / recent-runs — for all four hybrid-tracker families (Splk Feeds DSM/DHM/MHM, Splk Flx, Splk Fqm, Splk Wlk), and on the Elastic sources welcome / manage / edit / execute modals. Tiny Are you sure? confirmation dialogs deliberately do not get the icon — they are commit points, not exploration surfaces. |
|
feature - AI Assistant — per-page persistence of chat history and provider selection |
Closing the AI Assistant panel with the × button used to discard the entire conversation, the selected provider, and any in-progress input text. Reopening the panel returned to a blank welcome screen even when the user had not navigated away. The conversation now persists for as long as the page is loaded — previous questions and answers remain visible after close/reopen, the provider selection sticks, and any in-progress input is preserved. The conversation is reset only when the user explicitly clicks the Clear conversation trash icon, or on full page reload / navigation. State is keyed by context (tenant + component + entity for entity panels, context-type + tenant for feature panels), so switching contexts cleanly starts a fresh conversation. |
|
feature - In-page Virtual Tenant configuration editor |
A new Configure tenant entry on the per-tenant 3-dot menu opens a polished, grouped, searchable editor for the ~105 per-tenant configuration fields that were previously only reachable via the ungrouped Splunk UCC |
|
feature - Per-tenant Splunk username visibility allowlist |
Administrators can now restrict a Virtual Tenant’s visibility to a curated list of Splunk usernames, on top of the existing role-based RBAC. The allowlist is configured from a new 3-dot menu entry with a Multiselect picker and is stored as |
|
feature - DHM — ‘merged’ break-by mode |
DHM (Data Hosts Monitoring) gains the merged break-by mode that DSM has supported for some time. In standard mode (today’s behaviour) DHM breaks entity discovery by |
|
feature - DSM / DHM — ‘none’ tstats root time span mode |
Hybrid trackers in tstats mode have so far always bucketed the root |
|
feature - Bulk edit — Disruption Queue as a new action category |
The Tenant Home Bulk edit entities modal exposes a new Disruption Queue category with a single action — Update minimal disruption period — that opens the existing single-entity disruption modal in bulk mode. Operators pick a value on the slider (0–48 h in 5-minute steps), optionally add an update comment, and the same |
Issue Number |
Description |
Details |
|---|---|---|
enhancement - “Hide this tenant” — confirmation modal with explicit undo guidance |
Clicking Personal preferences → Hide this tenant on a Virtual Tenant card (or in the Tenant Overview modal’s actions menu) used to hide the tenant immediately with no confirmation and no explanation, which led to accidental hides being hard to recover from. A small confirmation modal now appears, states clearly that this is a per-user cookie preference (not visible to other users), and explains the exact recovery path: enable Settings → Virtual Tenants visibility → True, then click Personal preferences → Unhide this tenant on the tenant’s kebab menu. The unhide flow is unchanged. |
|
enhancement - AI Assistant side-drawer — horizontal resize |
The non-disruptive AI Assistant side-drawer used to render at a fixed |
|
enhancement - AI Assistant icon in modal headers — no more gap, no more tooltip flash |
Two small but visible UX issues in the AI Assistant icon when injected into Splunk |
|
enhancement - Inline search on index dropdowns in Virtual Tenants creation wizards |
The four index dropdowns rendered in the Indexes & RBAC step of the Virtual Tenants creation wizard (Summary, Audit, Metric, Notable) — also reused by the DSM, DHM, and MHM feeds wizards — now expose an inline search box, so users on Splunk deployments with many indexes can type-to-filter instead of scrolling. Built on the existing Splunk UI |
|
enhancement - Inline search on bulk edit Category and Action dropdowns |
The Tenant Home Bulk edit entities modal’s Category (~16 options including the new Disruption Queue) and Action (dynamic per category) selects now support type-to-filter. Existing icons, placeholders, and selection behaviour are unchanged. |
|
enhancement - Inline search across long-list dropdowns and multiselects |
Follow-up sweep that adds the Splunk UI |
|
enhancement - Default lookup match mode to “Wildcard” in policy creation modals |
In the three Tenant Home lookup-based policy wizards (Priority, SLA, Tags), the Match mode dropdown in Step 2 — Field mappings now defaults to Wildcard (supports *, ?) instead of Exact (case-insensitive). In practice, lookup-based policies mostly map CMDB-style fields (index, hostname, sourcetype) where wildcard matching is what most users actually pick. Editing an existing policy is unaffected — the previously saved match mode is loaded as before. |
|
enhancement - Bulk edit — clarify when permanent deletion is required |
Users frequently confuse temporary and permanent deletion in the Tenant Home Bulk edit entities modal (category Enablement and Deletion). A small inline informational banner now appears when the user selects Delete Permanently, explaining the rule of thumb: permanent deletion is needed only when the entities are still actively producing data (it blocklists them so TrackMe does not auto-recreate them), while temporary deletion is sufficient for decommissioned entities whose underlying data stream is gone. Reaching for permanent deletion as a default leaves stale blocklist entries behind and makes future re-onboarding noisier. |
|
enhancement - ‘Open in search’ action for lookup_definitions in Tenant Knowledge Objects |
In the Tenant Knowledge Objects modal (Virtual Tenants → tenant card → Knowledge objects), rows of type |
|
enhancement - Reduce INFO-level perf logging from KV-collection helpers |
The four KV-collection read helpers in |
|
enhancement - Logging hygiene — fix cross-handler log “leaks” + honour per-tenant loglevel in custom commands |
Cross-handler “logging leaks” — REST handler log lines bleeding into a sibling handler’s rotating log file because of root-logger contamination — have been a recurring source of noise. A targeted audit found 5 hard leak sites in 2 REST handlers (now fixed by using the handler’s own logger consistently), plus 4 custom commands ( |
|
enhancement - Silence recurring SyntaxWarning: invalid escape sequence ‘\s’ in splunkd.log |
|
|
change - Security & dependency upgrades |
Patched two high-severity advisories — |
Issue Number |
Description |
Details |
|---|---|---|
bug - AI status report silently fails in stateful alert action |
When the |
|
bug - Score-mutation endpoints did not refresh tenant component summary cache |
Three score-mutation REST endpoints — Set false positive, Manual influence scoring (both on entity records), and Set false positive on outlier scores — wrote the score event and score cache entry but did not refresh the per-component |
|
bug - Inject expected entities admin handler did not refresh tenant component summary cache |
Same family as #1350. The |
|
bug - Bulk-edit endpoints could silently insert phantom KV records |
The shared bulk-edit helper |
|
bug - SOAR Automation Broker failover could corrupt asset credentials |
The |
|
bug - Audit: write REST endpoints with missing or partial update_comment / trackme_audit_event coverage |
A precise inventory of write REST endpoints whose audit emission was missing or did not honour the caller’s |
|
bug - Anthropic Claude Opus 4+ — connectivity test fails with HTTP 400 ( |
Configuring an Anthropic provider with model |
|
bug - Wrong sourcetype shown in ‘ML Monitor Update Progress’ modal |
Clicking Run ML monitor update now from the 3-dots menu in the entity Outliers view used to open an ML Monitor Update Progress modal whose Action Progress Events panel searched the wrong sourcetype ( |
|
bug - Outliers simulation — time range picker inherits from the main Outliers view |
When opening the Outliers management modal from an entity’s Outliers anomaly detection tab, the simulation block’s time range picker used to be hard-coded to Last 24 hours regardless of what time range was active in the parent Outliers view. Operators commonly switched the parent view to Last 7 days / Last 30 days and then had to re-select the same range in the simulation, every single time. The simulation time range now initialises from the parent Outliers view at modal open (one-shot — the simulation remains independently adjustable once open), so the simulation observation window matches what the user was just inspecting. |
|
bug - FQM wizard — cannot clear the index destination input field |
In the FQM Create a new collect job for CIM/non-CIM wizard (step 8 — Collect job main settings), the Index destination for this collect job? input would snap back to |
|
bug - FQM wizard — ‘Fields summary’ panel collapsed by default in ‘create or re-use a dictionary’ mode |
In the FQM Create a new collect job for CIM/non-CIM (create or re-use a dictionary) wizard, step 4 Dictionary configuration, the Fields summary panel was collapsed by default — which is misleading because clicking Load Fields Summary inside that panel is a mandatory step when creating a new data dictionary (without it the simulation cannot run). The panel is now expanded by default; users can still collapse it manually. |
|
bug - FQM wizard — summary index input shows empty but silently submits default |
Same FQM CIM/non-CIM wizard, the Summary index input could be cleared by the user and would display as empty, but the review pane and the submit handler both fell back to |
|
bug - splk-fqm — ZeroDivisionError in trackmefieldsquality when no fields are evaluated |
The |
Version 2.3.21 - build 1777411258 (28/04/2026)¶
Hint
TrackMe 2.3.21 — Hotfix for Tenant Home lag policy modal regression
Hotfix — DSM/DHM Lag monitoring policy modal no longer clobbers in-progress edits: A regression introduced in 2.3.20 made per-entity lag policy overrides effectively unreachable from the UI on Tenant Home. Sliders for delay/latency impact-score weights and text fields for maximal latency / maximal delay reverted to the persisted/inherited values within seconds of editing, so whatever value happened to be reasserted at the moment Apply lagging policy was clicked was what got persisted. The latent defect dates back to the modals’ creation in November 2025 but only surfaced once the 2.3.20 adaptive auto-refresh feature started re-rendering the parent on a tight cadence while the modal was open. This hotfix is strongly recommended for every customer running 2.3.20.
Configuration Guardian — bearer-token expiry now reads the JWT itself: The
remote_account_token_expiring_sooncheck no longer derives token expiry from TrackMe-side scheduling signals (KVmtimeandtoken_rotation_frequency). It now decodes the bearer token’s JWTexpclaim directly, eliminating false-positivecritical“Remote account token expired” alerts on accounts whose underlying token still has weeks of validity.Entity tables — label tooltips now surface label descriptions: Hovering a label chip in the Virtual Tenants and Tenant Home entity tables now shows the configured
label_descriptionalongside the label name, so the meaning of a label (e.g. “ML is generating seasonal patterns”, “Issue acknowledged, no immediate action needed”) is visible at glance without opening the Manage Labels modal.
SHA256: 1d77fc233828d5fa4fe05e9d045fdc03be6184f14edc220a50d36d50bc22f9fb
Issue Number |
Description |
Details |
|---|---|---|
enhancement - Show label description on hover in entity tables |
Labels rendered in the Labels column of the entity tables on Virtual Tenants and Tenant Home (FLX, DSM, DHM, MHM, FQM, WLK) used to show only the label name in their hover tooltip. Each label can carry a meaningful |
Issue Number |
Description |
Details |
|---|---|---|
bug - DSM/DHM Lag monitoring policy modal: form fields revert during edit (regression in 2.3.20) |
Fixed a regression in 2.3.20 where the Lag monitoring policy modal (DSM and DHM) silently reverted any user input — sliders for delay/latency impact-score weights and text fields for maximal latency / maximal delay — within seconds of editing, making per-entity overrides effectively unreachable from the UI. The “Apply lagging policy” button could still be clicked, but whatever value happened to be reasserted at that moment was what got persisted. Root cause: a |
|
bug - Configuration Guardian: bearer-token expiry check fired false-positive |
Fixed the Configuration Guardian |
Version 2.3.20 - build 1777282739 (27/04/2026)¶
Hint
TrackMe 2.3.20 — Configuration Guardian P0 wave, AI Assistant everywhere, adaptive Tenant Home & stateful alert performance
Configuration Guardian — six P0 checks, severity tiers, audit trail & AI Assistant integration: A new framework surfaces silent misconfigurations directly in the Virtual Tenants UI. This release ships the full P0 wave of six checks covering the most common “silently degrades TrackMe” conditions: insufficient tenant-owner capabilities, declared tenant indexes that don’t exist, remote-account tokens approaching expiry, the per-tenant health tracker not executing, remote-account connectivity failures, AI provider unreachable, and stale backup archives. Alerts come with two severity tiers (warning and critical), structured remediation guidance, and a full audit trail in the
trackme_auditindex. The AI Assistant on Virtual Tenants and Tenant Home is now Guardian-aware: it sees every active alert with parsed metadata and recommended actions, and is steered by a built-in playbook to act as an active guide rather than a passive reporter.AI Assistant — non-disruptive side panel everywhere: Building on the hybrid tracker wizard integration, the compact AI Assistant side panel is now available across every Tenant Home configuration screen — policies (priority, tags, SLA, metric, monitoring time), lagging classes, blocklists, logical groups, CMDB integration, data sampling, default and variable delay, replica trackers, FLX utilities, outliers, FQM dictionary, ops queues, parsing issues, and more. Users get ambient AI assistance without ever leaving the screen they are working on.
Tenant Home — adaptive auto-refresh and preserved navigation state: The Tenant Home page used to auto-refresh on a hardcoded 5-minute interval, which was either too frequent for small tenants or actively harmful for large ones (a refresh would fire while the user was still reading the previous result). The cadence now scales automatically with the observed table load duration, between a 5-minute floor and a 30-minute ceiling, with a visible “Next refresh in MM:SS” countdown. Manual refresh resets the countdown so consecutive refreshes don’t double-load. As a separate quality-of-life fix, the group-by dropdown, quick filter dropdown, and group expand/collapse state now survive tab switches within the same tenant page session, matching how the search box already worked.
AI providers — enable/disable without deletion: Administrators can now disable a configured AI provider (Configuration → AI Provider) instead of having to delete it. Disabled providers disappear from the AI Assistant chat selector, are skipped by stateful alert AI status reports, and are excluded from the Guardian
ai_provider_unreachableprobe (the prior alert is also self-cleared). The admin connectivity test endpoint still works against disabled providers so admins can troubleshoot before re-enabling.Stateful alert performance — significant speedups on high-throughput deployments: Several performance improvements to the stateful alert helper and
trackmestatefulcommand, with substantial runtime gains on production deployments:tenant_idx_resolutionis now cached per tenant within a single invocation (saves ~3s per event); chart storage usesbatch_saveinstead of one REST call per chart (was ~14-16s per event with ~10 charts, now near-instant); object-state validation can run in-process instead of via a per-entity REST call toload_component_data(opt-in, safe fallback); and thetrackmestatefulSPL pre-resolves the active-incident key list in Python instead of running a per-cycle subsearch.Splunk Hosted LLM — auto-resolve model_name to model_id: The
splunk_hostedprovider transparently accepts both the human-friendlymodel_name(e.g.gpt-oss-20b) and themodel_idexpected by the SLIM API. Customers unfamiliar with Splunk’s internal model ID convention no longer hit opaque 404s. The mapping is cached.Backup & Restore — gateway-timeout-proof Create backup: The Create backup action now dispatches a Splunk search job instead of keeping a long-lived browser REST connection. Large backup runs on production deployments no longer hit reverse-proxy or load-balancer 502/504s even when the backup itself completes successfully backend-side. The UI also gains copy-to-clipboard buttons for every SPL and cURL snippet in the Documentation & examples modal.
Scheduler skip detection — alert-aware: Scheduler completeness and “skipping searches” detection now captures alert firings in addition to regular tracker searches. The Scheduler Review modal routes its row actions appropriately per row type.
UI polish & consistency: Slider for Min green % in the converging tracker wizard, translated Splunk query in the CMDB lookup modal, near-full-width AI Assistant responses, other group members listed directly in the Logical Groups association panel, accurate HIGH PRIORITY ENTITIES IN ALERT header counter (no longer counts disabled tenants/components), and Virtual Tenant wizard index/role dropdowns no longer truncated at 30 entries.
Support Diagnostic — robustness for large environments: The Generate diag feature shipped in 2.3.19 is hardened for busy customer environments where a Global run could time out before completing. The backend timeout is raised to 60 minutes, the worker emits a heartbeat so long steps don’t get misclassified as dead, and the UI poll matches the new ceiling. When something does fail mid-collection, a new Partial failures card lists the failed steps and the user still receives a partial archive instead of losing the entire run. The page also now correctly follows the user’s Splunk light/dark theme.
Various bug fixes: Notes and labels audit events are now correctly surfaced in the entity Audit changes tab; disabled tenant overview no longer loops requests; the Ops Status modal’s Run: Clear Tenant Status button works again; SLA tracker scheduling follows SLA policies (copy-paste bug); clipboard fallback surfaces real copy failures; variable delay auto-compute works again; MHM lagging class overrides are applied (and the Manage: lagging classes menu entry is renamed back); leftover stanza keys no longer pollute splunkd.log on Splunk 9.x.
SHA256: 933c725146bf6e94900dc1c875fac560472dbfb479f839741a78d660c47d4b27
Issue Number |
Description |
Details |
|---|---|---|
feature - Configuration Guardian framework with full P0 wave of checks |
Configuration Guardian is a new framework that surfaces silent misconfigurations directly in the Virtual Tenants UI. When a problem is detected, administrators see a toast with a clear title, explanation, and remediation steps — yellow for warnings, red for critical — plus a Dismiss alert action to clear it while fixing the root cause. If the condition persists, the alert reappears on the next check cycle. Every state transition (created, updated, cleared, dismissed) is recorded in the
The AI Assistant on Virtual Tenants and Tenant Home is fully Guardian-aware: it sees every active alert with parsed metadata and recommended actions, knows what each check means and how to remediate it, and is steered by a built-in playbook to act as an active guide rather than a passive reporter. A dedicated read endpoint ( |
|
feature - AI Assistant side panel extended to all Tenant Home configuration screens |
Following the introduction of the non-disruptive AI Assistant side panel in the hybrid tracker wizards (#1166), the same compact panel is now available across every configuration / management screen reachable from Tenant Home. This covers all the policy editors (priority, tags, SLA, metric policies, monitoring time), lagging classes, blocklists, logical groups, impact score, default and variable delay templates, CMDB integration, data sampling, replica tracker creation and management, FLX utilities / drilldown searches / default metrics, outliers, FQM dictionary, ops queues, parsing issues, and permanently deleted entities. Wherever you are configuring TrackMe, an AI icon in the screen header opens the assistant on the right while the configuration screen stays visible and interactive on the left. The panel is visible only when the AI Assistant is enabled system-wide. |
|
feature - Non-disruptive AI Assistant panel in hybrid tracker wizards |
The TrackMe AI Assistant can now be opened directly from any of the six hybrid tracker creation wizards (DSM, DHM, MHM, FLX, FQM, WLK). It slides in as a compact side panel on the right, while the wizard stays fully visible and interactive on the left. This means you can ask questions like “what does this field mean?” or “help me build this SPL” without losing your place in the wizard. A new AI icon button in the wizard header opens the panel; it is visible only when the AI Assistant is enabled system-wide. The panel reuses the same AI context and provider selector as the AI Assistant opened from Tenant Home. |
|
feature - Auto-resolve Splunk Hosted LLM |
Configuring the Splunk Hosted LLM provider is now more forgiving. The provider accepts both the friendly model name (e.g. |
Issue Number |
Description |
Details |
|---|---|---|
enhancement - Tenant Home: manual refresh resets the adaptive auto-refresh countdown |
Follow-up to the adaptive auto-refresh enhancement (#1223). When auto-refresh is enabled, clicking the manual refresh button now resets the countdown to the next automatic refresh — so consecutive manual + automatic refreshes don’t double-load the page. If the manual refresh fails or auto-refresh is disabled, the countdown is left untouched. |
|
enhancement - Tenant Home: adaptive auto-refresh based on observed table load duration |
The Tenant Home page used to auto-refresh on a hardcoded 5-minute interval. On large-scale tenants where the main entities table can take 60-120s to load, that meant the next refresh would fire while the user was still reading the previous result; on small tenants it was unnecessarily frequent. The cadence now scales automatically with the most recent observed table load duration on the active tab, between a 5-minute floor and a 30-minute ceiling. A small “Next refresh in MM:SS · cadence Nm” label appears under Last updated with a tooltip explaining the source. A concurrency guard prevents stacked loads if a refresh is still running when the timer fires (or if the user spam-clicks the manual refresh button). Switching tabs resets the observed duration so a slow DSM reading doesn’t penalise a fast FQM tab. The existing auto-refresh on/off toggle (cookie) still controls the whole feature. |
|
enhancement - Tenant Home: preserve dropdown selections and group expand/collapse across tab navigation |
On the Tenant Home page, navigating between tabs (e.g. Data source monitoring → Tracking Alerts → back) preserved the search input but reset the group-by dropdown, the quick filter dropdown, and the per-group expand/collapse state. The behaviour was asymmetric and surprising — users naturally expected all the table controls to behave like the search box. All three pieces of state now survive tab navigation within the same tenant page session, exactly like the search input. State is reset only on a full page refresh or when navigating to a different tenant. |
|
enhancement - AI provider: allow administrators to disable a configured provider |
The AI provider configuration screen (Configuration → AI Provider) now exposes an |
|
enhancement - Logical Groups modal shows other members of the current group |
When you open the Logical Groups modal on an entity that belongs to a group, the association panel now lists the other members of that group directly — no more scrolling down and visually matching the group name in the overview table. If the entity is the only member, a clear “This entity is the only member of this group.” message is shown instead. Small but useful quality-of-life improvement for operators investigating grouped entities. |
|
enhancement - Converging tracker wizard: use Slider for Min green % |
In the Flex Objects converging tracker creation wizard, Min green % is now a slider with a live value readout instead of a plain numeric input. This matches the style already used elsewhere for 0-100 integer fields (like Impact score in the Outliers model modal) for a more consistent and touch-friendly experience. The default value stays at 100. |
|
enhancement - Scheduler skip detection: alert firings now captured end-to-end |
Scheduler completeness metrics, skipping-searches detection, and the Scheduler Review modal used to only cover regular tracker saved searches — alert firings were silently ignored because of how their saved-search names are formatted. Alerts are now fully captured everywhere: KPIs, dashboards, and API responses all include them. The Scheduler Review & Investigate (past 24 hours) modal also recognises alert rows and routes its row actions accordingly — for example, Open saved search on an alert now opens the Splunk Saved Searches manager filtered correctly (so alerts owned by any user appear), and the audit drill-down targets modular-alert logs. Drill-downs that don’t apply to alerts (logs inspector, performance deep dive) are hidden on those rows. |
|
enhancement - Backup & Restore: Create backup no longer hits gateway timeouts |
On large production deployments, clicking Create backup could return a 502/504 gateway timeout after a few minutes — even when the backup itself had completed successfully on the backend. The cause was a long-lived browser HTTP request being killed by an upstream reverse proxy or load balancer. The UI now runs the backup through a Splunk search job instead, so the browser only exchanges short polling requests with Splunk while the work happens server-side. The user experience is unchanged, but the operation now completes reliably regardless of backup duration or network topology. |
|
enhancement - Backup & Restore: Copy buttons on Documentation & examples modal |
Every SPL and cURL snippet in the Backup & Restore Documentation & examples modal now has a one-click Copy button underneath it, matching the pattern already in place on the REST API Reference page. No more manual text selection on long multi-line commands. |
|
enhancement - CMDB lookup modal: show translated Splunk query |
The CMDB lookup modal now shows the actual CMDB search that was executed (e.g. |
|
enhancement - AI Assistant: allow near full width for LLM responses |
Assistant message bubbles in the AI Assistant chat panel now stretch to near-full panel width, so responses containing markdown tables or structured output are no longer squeezed into a narrow column that forces awkward wrapping. User messages keep their existing right-aligned, content-sized bubble. |
Issue Number |
Description |
Details |
|---|---|---|
performance - Stateful alerts: in-process object-state validation (opt-in) |
In the stateful alert helper, |
|
performance - |
The search that feeds the stateful alert pipeline used to pull every |
|
performance - Stateful alerts: cache |
In |
|
performance - Stateful alerts: batch chart storage via |
In the stateful alert helper, charts attached to incidents were stored in the chart KV collection one at a time — one HTTP roundtrip per chart inside a loop. With ~10 charts per event this cost ~14-16 seconds on average (p95 ~22s) per event in production. Charts are now persisted in a single |
Issue Number |
Description |
Details |
|---|---|---|
bug - Support Diagnostic: timeouts on large environments, partial-success archive, light-theme rendering |
On large customer environments (many active tenants, busy |
|
bug - Splunk < 10.x: silence |
On Splunk < 10.x, splunkd logged |
|
bug - Remove leftover |
A stanza key from the decommissioned CIM monitoring component was left behind in |
|
bug - Virtual Tenants header: HIGH PRIORITY ENTITIES IN ALERT counter no longer counts disabled tenants/components |
On the Virtual Tenants page, the HIGH PRIORITY ENTITIES IN ALERT counter at the top of the screen could show a value that did not match the sum of the per-tenant card badges — typically because the header summed in stale priority counts from disabled tenants or disabled components. The header aggregation now skips tenants whose status is |
|
bug - Virtual Tenant wizard: index & role dropdowns no longer truncated at 30 entries |
In the Create a new Virtual Tenant wizard (Step 4 — Indexes & RBAC), the Summary / Audit / Metric / Notable index dropdowns and the Admin / Power / Readonly role pickers silently omitted entries when the search head had more than 30 indexes or 30 roles — Splunk’s REST defaults to |
|
bug - MHM: lagging class overrides applied + screen renamed back to Manage: lagging classes |
Two related MHM regressions are fixed. First, MHM per-metric-category lagging class overrides were silently never applied — the loader hit a benign exception that fell back to defaults on every cycle, so customer overrides had no effect since the feature was introduced. The loader now reads the collection correctly and overrides take effect again. Second, the Tenant Home kebab menu entry for MHM had been renamed to Manage: metric policies, which made the screen undiscoverable for users looking for “lagging classes” (and inconsistent with the DSM/DHM equivalents). The entry is renamed back to Manage: lagging classes so terminology is uniform across DSM, DHM and MHM. |
|
bug - Virtual Tenants: disabled tenant overview loops requests and stacks Splunk Service Unavailable toasts |
Opening the Virtual Tenants Entities Overview modal on a disabled tenant caused the UI to fire repeated backend requests that failed with HTTP 500, stacking “Splunk Service Unavailable” toasts on screen. No requests should be issued for a disabled tenant. The modal now correctly short-circuits on disabled tenants and simply shows the existing “This tenant is currently disabled” placeholder. |
|
bug - Virtual Tenants: Run: Clear Tenant Status button no longer opens the modal from Ops Status |
In the Virtual Tenants Tenants Operational health statuses modal, clicking the Run: Clear Tenant Status button closed the parent modal but the expected Clear Virtual Tenant Operational Status modal never appeared. The modal now opens as expected. |
|
bug - Notes: add / delete / clone actions now appear in the entity Audit changes tab |
Adding, deleting, or cloning a note on an entity was generating audit events, but they were invisible in the entity’s Audit changes tab because of an internal classification mismatch. Note changes on an entity are now recorded and displayed consistently with other entity-level actions (priority, tags, SLA, labels). For clone operations, one audit event is recorded per target entity so the addition is traceable on each. |
|
bug - Clipboard fallback shows a success notification even when the copy fails |
In Backup & Restore and the REST API Reference pages, the Copy buttons use a browser fallback when the modern clipboard API is unavailable. The fallback did not verify the copy actually succeeded, so users could see a “Copied!” confirmation when nothing had been copied. Failed copies are now surfaced as an error notification instead. |
|
bug - SLA tracker scheduling driven by tags policies instead of SLA policies |
Due to a copy-paste error in the tracker health routine, SLA tracker scheduling was driven by whether tags policies existed on the tenant instead of whether SLA policies existed. Tenants with SLA policies but no tags policies could see their SLA tracker saved searches incorrectly disabled, while tenants with tags policies but no SLA policies could see the SLA tracker incorrectly scheduled. SLA tracker scheduling now correctly follows SLA policy presence. |
|
bug - Labels: assign / remove actions now appear in the entity Audit changes tab |
Assigning or removing labels on an entity (introduced in v2.3.19) was generating audit events, but they were invisible in the entity’s Audit changes tab because of an internal classification mismatch — same pattern as the notes fix above. Label changes on an entity are now recorded and displayed consistently with other entity-level actions. Cascade removal via Delete label also emits per-entity audit events so the removal is traceable on every affected entity. |
|
bug - Variable delay auto-compute feature not working |
Clicking Auto-compute thresholds in the Variable delay threshold modal (DSM/DHM) returned an HTTP 500 error and the feature was unusable. A secondary silent issue was also identified where hourly thresholds could have been computed over an incomplete dataset. Both issues are fixed, and a defensive guard has been added to the shared search helper so this class of bug cannot reoccur on other callers. |
Version 2.3.19 - build 1776258970 (15/04/2026)¶
Hint
TrackMe 2.3.19 — Entity Labels, CMDB Integration, Variable Delay, Splunk Cloud AI & Support Diagnostics
Entity Labels — lifecycle visibility at a glance: Introducing a lightweight, color-coded labeling system for entities. Labels give teams instant visibility into the lifecycle stage and operational context of every tracked entity — directly in the entity tables, in stateful and notable alert events, and through Virtual Groups that can aggregate entities by label across tenants.
CMDB integration improvements: Stateful and notable alert actions now automatically enrich events with CMDB data at alert time. A new simplified configuration screen replaces the complex UCC-based setup, and CMDB icons now appear correctly in Virtual Groups tables.
Entity Notes enhancements: Notes are now visible as a first-class column in entity tables with a new clone-to-entities action for bulk operations.
Variable delay management improvements: Timezone notice banners in all variable delay and threshold editors, plus fully customizable per-tenant slot templates.
Policy tracker scheduling: SLA, Tags, and Priority policy trackers now default to a 12-hour cadence instead of every 15 minutes, cutting scheduled-search load for these jobs while policy content remains applied; cron remains adjustable per tenant if you need a faster refresh.
Support — generate diagnostics: A self-service Support - generate diags experience (nav under API & tooling and Audit & troubleshoot) lets admins produce a timestamped
.tgzfor TrackMe support — entity-scoped or global, async job + polling + secure download, optional tenant anonymisation with a separate mapping for support, and RBAC viatrackmepoweroperations.AI Assistant — realtime entity context: Entity-level AI chat now loads the same decision-maker view as
/trackme/v2/describe/entity(viaload_component_data), so labels, scores, smart status, and other joined fields match the UI instead of a raw KV snapshot.Splunk Cloud — splunk_hosted LLM (SLIM): The Splunk-hosted AI provider now sends the
request_idheader required by the SLIM gateway on Splunk Cloud, resolving HTTP 400Request ID not present in headerfailures so model discovery, in-app AI Assistant chat, and AI status content in stateful alerts work again for customers usingsplunk_hosted.Various bug fixes and improvements: SLA ranking corrections, REST handler hardening, Cribl use case updates, multiple Virtual Groups fixes, quieter routine logging from the
trackmestatefulcommand, KV index transforms for unquoted keys, consistent status messaging when impact score is raised manually without anomalies, and ML outliers simulation with auto-correction disabled when training volume is below the native fit minimum.
SHA256: f444af4de9043a196ddbd54a65e24cab2cfc70796a7e55b5e36077db9754a3be
Issue Number |
Description |
Details |
|---|---|---|
feature - GitHub-style entity labels for lifecycle visibility |
TrackMe now supports entity labels — lightweight, color-coded tags that give teams instant visibility into the lifecycle stage and operational context of every tracked entity. Labels are fully managed per tenant and can be freely defined to match your operational vocabulary (e.g. |
|
feature - Entity notes: table column, shared modal, clone-to-entities |
Notes have been elevated from a hidden detail to a first-class column in the entity tables. A new Notes column shows the note count per entity, and clicking it opens a shared notes modal that works consistently across entity overview, table rows, and bulk operations. A new clone-to-entities action lets operators push a note to multiple entities at once — useful for documenting a shared incident, a maintenance window, or an operational decision that affects a group of data sources or hosts. |
|
feature - CMDB integration in stateful and notable alert actions |
Stateful and notable alert actions now automatically perform a CMDB lookup at alert time, enriching the event with ownership, criticality, contact information, and any other fields defined in your CMDB lookup. Alert recipients and downstream automation receive full operational context without additional manual configuration. |
|
feature - Simplified CMDB integration configuration screen |
A new “Manage: CMDB integration” modal is accessible from the tenant-home Features menu for all six component types (DSM, DHM, MHM, FLX, FQM, WLK). It replaces the previous UCC-buried configuration with a guided experience: enable/disable toggle, local or remote account selector (via a new |
|
feature - Virtual Groups category sub-grouping |
Virtual Groups can now be organized into categories for better visual structure in the Virtual Tenants dashboard. Groups sharing the same |
|
feature - Inject expected sources/hosts via one-shot action wizard |
A new Inject Expected wizard lets operators declare data sources (DSM) or hosts (DHM) that should exist in a tenant, triggering immediate entity creation rather than waiting for the next discovery cycle. This is particularly useful for onboarding new data feeds where you want proactive alerting from day one, re-creating previously deleted entities, or pre-populating a tenant before a migration. The wizard supports optional recurring operations for use cases where periodic re-injection is needed. |
|
feature - Variable delay / threshold editors: Splunk server time disclosure banner |
Variable delay and variable threshold slots are evaluated by the decision maker using the Splunk server’s local clock, which may differ from the browser timezone of the admin configuring them. A live Timezone notice banner now appears in every variable delay and threshold editor, showing both the server clock and the browser clock in real time with the signed offset, so administrators always know which time frame their slot definitions apply to. |
|
feature - Per-tenant customizable variable delay slot templates |
The “Quick templates” presets in the variable delay slot editors (business hours, weekday/weekend, three-tier) were previously hardcoded and identical for every tenant. Administrators can now customize templates per tenant — override factory defaults, create entirely new templates, or reset overrides individually or in bulk. A new “Manage templates” modal is accessible from the existing default delay configuration screen. Custom templates persist across editing sessions and are automatically saved when configured during tenant creation. |
|
feature - Support diagnostic archive (UI + REST API) |
Operators with the |
Issue Number |
Description |
Details |
|---|---|---|
enhancement - Include labels field in stateful and notable alert events |
The |
|
enhancement - Tenant-scoped error logging |
All tenant-related error responses and log messages now consistently include the |
|
enhancement - SLA, Tags, and Priority policy trackers: default schedule 15 minutes → 12 hours |
For each component (DSM, DHM, MHM, FLX, FQM, WLK), the per-tenant scheduled searches |
|
enhancement - Stateful alert helper: structured performance timing in logs |
The modular alert helper |
|
enhancement - |
The |
Issue Number |
Description |
Details |
|---|---|---|
bug - SLA classes ranking is inverted |
The default SLA classes had inverted ranking — platinum was ranked lowest (1) while gold was ranked highest (3), with thresholds also assigned backwards. New installations now receive correct defaults: platinum = rank 3 with the strictest threshold (4h), gold = rank 2 (24h), silver = rank 1 with the most lenient threshold (48h). SLA class dropdowns are now sorted by rank descending (most important first). Existing installations with customized SLA classes are unaffected. |
|
bug - REST handlers describe-flag parser truthiness bug |
The inline |
|
bug - Cribl Logstream pipeline FLX use case broken after dimension rename |
The OOTB |
|
bug - Virtual Groups REST handlers missing explicit port |
Virtual Groups REST handlers were omitting the explicit port in |
|
bug - Missing CMDB icon in Virtual Groups entities table |
The CMDB icon was missing from the actions column in Virtual Groups entity tables, even when CMDB was enabled on the underlying tenants. Fixed by supporting per-tenant CMDB lookup resolution in the Virtual Groups overview, so each entity’s CMDB availability is determined by its source tenant’s configuration. |
|
bug - Manual impact score: empty |
Raising impact score via manually influence scoring could move an entity to orange or red while leaving |
|
bug - KV indexed transforms: unquoted |
The indexed-field transforms |
|
bug - REST API autodocs missing endpoints |
|
|
bug - Virtual Group modals use group_id instead of entity tenant_id |
Virtual Group overview modals were using the Virtual Group’s |
|
bug - DHM entity overview pie charts fail on empty data |
The “Stats per index” and “Stats per sourcetype” pie charts in the DHM entity overview crashed when the entity had no index or sourcetype data. Now renders gracefully with an empty state. |
|
bug - Report creation retry logic does not detect HTTP 409 Conflict |
The retry logic in |
|
bug - DSM/DHM wizards cannot clear duration inputs |
Duration inputs in Virtual Tenants DSM/DHM wizards could not be cleared once set, and human-readable pattern support ( |
|
bug - AI Assistant Ollama behind reverse proxy returns HTTP 401 |
Ollama endpoints fronted by a reverse proxy requiring Bearer token authentication returned HTTP 401. The Ollama provider now honors the configured bearer token for all requests. |
|
bug - AI Assistant entity context uses |
|
|
bug - AI Assistant |
Splunk Cloud’s SLIM gateway rejects requests without a |
|
bug - ML outliers simulation N/A when auto-correction is disabled and training data is insufficient |
With |
|
bug - Stateful alert tags field produces malformed list |
Stateful alert events produced a malformed list when an entity had multiple tags. Tags are now properly serialized as a clean multi-value field, the |
Version 2.3.18 - build 1774997466 (01/04/2026)¶
Hint
TrackMe 2.3.18 — Virtual Groups, Policy Enhancements & Performance Optimizations
Virtual Groups — cross-tenant aggregation views: This release introduces Virtual Groups, a powerful new feature for the Virtual Tenants UI. Virtual Groups are read-only cards that aggregate entities from multiple tenants and components into a single unified view, displayed alongside regular tenant cards. Combined with the recently introduced priority and tags policies — both lookup-based and search-based — and a new lightweight entity filter DSL, Virtual Groups enable a high level of flexibility in representing and monitoring key entities across tenants. A full creation wizard, RBAC-controlled visibility, and simulation mode make it easy to define, preview, and manage groups.
Key performance optimizations: The FLX converging tracker has been re-engineered with direct REST calls and parallel execution, delivering up to 6-10x faster execution and eliminating excessive skip rates. The WLK metadata tracker received connection caching and batch KV loading optimizations for similar ~6-10x performance gains at large scale.
Various bug fixes and improvements: Multiple fixes across DHM policies, table rendering, input sanitization, and policy simulation improve reliability and usability across the platform.
SHA256: 2af279cb984a4d89e7cc2361060ae2929cbbe7d2118fb1006a706c64bef5f72b
Issue Number |
Description |
Details |
|---|---|---|
feature - Virtual Groups — cross-tenant aggregation views |
Virtual Groups are read-only aggregation cards displayed in the Virtual Tenants grid alongside real tenant cards. They allow users to select multiple tenants and components, then view all associated entities grouped by component family in a unified overview — providing cross-tenant visibility without creating new monitoring infrastructure. A 7-step creation wizard guides through group identity, tenant/component selection, priority filtering, additional entity filters via a lightweight DSL (supporting field=value matching with glob wildcards, AND/OR logic, and parentheses), RBAC role assignment, simulation preview, and final review. Virtual Group cards display entity count badges and priority indicators, and clicking a card opens a full overview modal with per-component donut charts and a complete entity table with all standard table features. |
|
feature - Monitoring Time Policy in bulk edit menu |
Monitoring Time Policy is now available as a bulk action category in the bulk edit menu for all six component types (DSM, DHM, MHM, FLX, FQM, WLK). Users can select multiple entities and apply a built-in policy (e.g. “Business days, all hours”) or configure custom day/hour combinations — applied to all selected entities in a single operation. The existing |
|
feature - Cribl LogStream pack traffic monitoring use case |
A new pre-built Flex Objects use case |
Issue Number |
Description |
Details |
|---|---|---|
enhancement - FLX converging tracker optimization via direct REST calls |
The FLX converging tracker ( |
|
enhancement - WLK metadata tracker optimization with connection caching and batch KV loading |
The WLK metadata tracker ( |
|
enhancement - Policy simulation spinner animation and execution time display |
Policy simulation buttons in Tags, Priority, and SLA policy modals now display a |
Issue Number |
Description |
Details |
|---|---|---|
bug - Table cells render |
Fixed entity table cells rendering the literal string |
|
bug - Sanitize non-printable control characters from |
Fixed an issue where non-printable control characters (e.g. |
|
bug - DHM policies: missing fields and broken multi-value matching |
Fixed two inconsistencies in the DHM policy system affecting priority, tags, and SLA policies. First, the |
|
bug - DHM: prevent |
Fixed the “Stats per index” and “Stats per sourcetype” pie charts in the DHM entity overview failing with a malformed |
|
bug - Tags policies simulation parameter mismatch |
Fixed the “Run policy simulation” button in the Tags Policies editor failing with |
|
bug - Incorrect |
Fixed a misleading error log in the health tracker’s |
|
bug - Cribl LogStream use case normalization |
Fixed the |
|
bug - Health tracker mlmodels-management task accesses collections for disabled tenants |
Fixed the general health tracker’s |
|
bug - Health tracker missing circuit breaker for disabled tenants |
Fixed the health tracker ( |
|
bug - Elastic source dedicated mode tstats span too granular |
Fixed the tstats search generated for dedicated elastic source trackers using |
|
bug - Policy wizard preview misses conditionally-populated fields |
Fixed the policy wizard SPL preview extracting available fields only from the first result row. When a search uses conditional logic (e.g. |
|
bug - Tags field missing from stateful alert and notable events |
Fixed the |
|
bug - Policy simulation rejects conditionally-populated fields as missing |
Fixed policy simulation endpoints validating field presence using only the first result row, causing |
|
bug - SLA search-based policy simulation broken |
Fixed the SLA search-based policy simulation always failing with |
Version 2.3.17 - build 1774424737 (25/03/2026)¶
SHA256: 3a6a82c329f447d06a9a7869a7de7249fecaf5e581ed9e544ee8c9c054272600
Issue Number |
Description |
Details |
|---|---|---|
feature - Replica tracker Execute/Manage/Create modals in Tenant Home |
Full replica tracker modal support is now available from the Tenant Home Actions menu for replica tenants. The Execute modal allows selecting and running replica trackers with real-time execution monitoring via an events panel. The Manage modal provides a table view with search and filtering, multi-select deletion with confirmation, and direct links to orchestrator and replicator logs. The Create wizard offers a 4-step guided flow — select source tenant, define constraint, simulate results, and confirm creation — with an option to immediately run the new tracker on success. |
|
feature - Add ‘Open in Search’ action for Scheduler Review and Ops Health Statuses tables |
A new “Open in Search” menu item is available in the gear/cog dropdown of the Scheduler Review & Investigate and Operational Health Statuses modals. The action opens the underlying SPL query directly in the Splunk Search view with proper time range parameters (earliest/latest), allowing administrators to inspect and troubleshoot scheduler and operational health data in their native search context. |
Issue Number |
Description |
Details |
|---|---|---|
enhancement - Health tracker performance optimization and shadow copy management |
The health tracker received significant performance improvements. A tier-based task frequency model (Tier 1–4) reclassifies housekeeping tasks by criticality — from every-cycle (Tier 1) to daily (Tier 4) — drastically reducing per-cycle compute overhead on large deployments. License checks now use a global shared KV cache with a 24-hour TTL (immediately invalidated on any license mutation), eliminating redundant per-tenant REST calls. Saved search loading is batched into a single call per cycle instead of per-report REST roundtrips. The untracked entities safety net is moved from Tier 1 to Tier 2 with a short-circuit pre-check that skips the expensive SPL pipeline when no stale entities exist. Additionally, a new |
Issue Number |
Description |
Details |
|---|---|---|
bug - Failure to load a single tenant in Virtual Tenants affects all other tenants |
Fixed the Virtual Tenants page failing to load entirely when a single tenant had a missing |
|
bug - Replica tenant Actions menu shows hybrid/elastic tracker options instead of replica tracker options |
Fixed the Tenant Home Actions menu incorrectly displaying hybrid tracker, elastic source, and feature options for replica tenants. Replica tenants now correctly show replica tracker options (Execute, Manage, Create) with proper admin permission checks. |
|
bug - Virtual Tenant creation fails with IndexError in slow or busy environments |
Fixed Virtual Tenant creation failing with an |
Version 2.3.16 - build 1774013895 (20/03/2026)¶
Hint
TrackMe 2.3.16 — High-Scale Performance, Cost Optimization & Platform Resilience
Scaling TrackMe to new heights: This release is dedicated to pushing TrackMe’s scalability boundaries with deep performance optimizations across all monitoring components. Key concepts — including hybrid trackers and the health tracker — have been re-factored to drastically reduce processing and compute costs, especially at high scale. All components (DSM, DHM, MHM, FLX) received extensive enhancements validated against scenarios with up to 100,000 entities in a single tenant.
Shadow copy KVstore collections — a new scalability paradigm: TrackMe introduces a new concept of pre-computed, enriched entity snapshots stored in dedicated KVstore collections. The UI and backend automatically leverage shadow copies for near-instant table rendering, replacing expensive per-entity REST calls with efficient
| inputlookupoperations. With progressive loading and configurable page sizes, the UI now scales smoothly to multi-hundreds of thousands of entities.DHM & hybrid tracker refactoring for extreme scale: The Data Host Monitoring pipeline has been completely refactored with asynchronous data loading and optimized JSON parsing. DHM trackers are now capable of handling several tens of thousands of hosts per tracker, making enterprise-scale host monitoring practical and cost-effective.
Health tracker deep optimization: The health tracker now implements task frequency tiering, batch KVstore operations, and parallel processing — significantly reducing its compute footprint and enabling faster health assessment cycles across large deployments.
DSM sourcetype explosion safeguard: A new protective mechanism prevents runaway sourcetype discovery from overwhelming TrackMe and the Splunk environment. Administrators can configure a cap on sourcetypes per index, ensuring unexpected data patterns do not degrade performance or generate unmanageable entity volumes.
Blocklist, entity management & UI enhancements: The blocklist interface has been expanded with custom categories, wildcard UX improvements, match type display, and a new simulation mode. New pagination options and a clickable degraded badge further improve the day-to-day operational experience.
SHA256: ef9e84f24c6d7316b5baa1b5d75ff44cbdf46f7f860c1886262a5d4a869fccc7
Issue Number |
Description |
Details |
|---|---|---|
feature - Shadow copy KVstore collections for instant UI loading at scale |
TrackMe introduces shadow copy KVstore collections — pre-computed, enriched entity snapshots that are automatically maintained by hybrid trackers and the health tracker. The UI loads entity tables via efficient |
|
feature - Progressive shadow loading with configurable page size |
Shadow collections support progressive loading with configurable batch sizes ranging from 5,000 to 50,000 records (default 25,000). Administrators can tune the page size via Configuration > User Interfaces to balance memory usage and rendering speed based on their environment. |
|
feature - DSM sourcetype explosion safeguard |
A new configurable safeguard caps the number of sourcetypes tracked per index in Data Source Monitoring. When the cap is reached, TrackMe alerts administrators and prevents further sourcetype discovery for the affected index. This protects the environment from scenarios where unexpected data patterns cause an explosion of sourcetypes, leading to excessive entity creation and processing overhead. |
|
feature - DHM pipeline refactoring with async loading and optimized parsing |
The Data Host Monitoring pipeline has been completely refactored with asynchronous component data loading and optimized JSON fast parsing. These changes enable DHM trackers to efficiently handle tens of thousands of hosts per tracker, making enterprise-scale host monitoring practical and cost-effective. |
|
feature - Health tracker deep optimization with tiered frequency, batch operations, and parallel processing |
The health tracker has been deeply optimized with task frequency tiering, batch KVstore operations, and parallel processing. These improvements significantly reduce compute costs and accelerate health assessment cycles, especially in deployments with large numbers of tenants and entities. |
|
feature - Unified MHM pipeline and deprecated command cleanup |
The Metric Host Monitoring pipeline has been streamlined with a unified processing approach and removal of deprecated commands, improving performance and maintainability. |
|
feature - FLX preloaded mode for high-cardinality scaling |
Flex Objects tracking now extends preloaded mode to |
|
feature - Comprehensive blocklist management improvements with simulation mode |
The blocklist management interface has been significantly enhanced with expanded fields, custom categories, improved wildcard UX, match type display, and a new simulation mode. The simulation feature allows administrators to preview which entities would be blocked before applying changes, reducing the risk of unintended entity suppression. |
|
feature - Cribl Edge fleet monitoring use cases |
Two new pre-built Flex Objects use cases are available under a new Cribl Edge category for monitoring fleet node health. The first use case queries the Cribl Edge API via the TA-trackme-cribl add-on for rich fleet visibility including node health, input/output status, and heartbeat tracking. The second uses Cribl Edge internal metrics indexed in Splunk for node availability monitoring with built-in disruption queue grace periods. |
|
feature - Remote Splunk deployment support for priority, SLA, and tags policies |
Priority, SLA, and Tags policies now support remote Splunk deployments. A new Splunk deployment selector in the policy creation and editing modals allows lookup-based and search-based policies to target remote Splunk accounts with automatic connectivity validation. The schema migration automatically adds the new |
|
feature - Immediate score visibility via KV store cache |
False positive and manual score influence changes are now immediately reflected in the UI via a dedicated KV store score cache, eliminating the delay previously experienced while waiting for the next tracker cycle to update entity status. |
|
feature - Degraded badge clickable on tenant cards to open OpsStatus modal |
The degraded status badge displayed on Virtual Tenant cards is now clickable and opens the OpsStatus modal directly with the corresponding tenant pre-selected, providing quick access to operational status details. |
Issue Number |
Description |
Details |
|---|---|---|
enhancement - Shadow record patching after score and priority changes |
Shadow records are now immediately updated after false positive, manual score influence, outlier reset, and priority changes, ensuring the UI reflects the latest entity state without waiting for the next full shadow refresh cycle. |
|
enhancement - Shadow write requester logging for improved observability |
Shadow write log entries now include the requester identity (hybrid tracker report name, health tracker, or REST handler), improving observability and troubleshooting of shadow collection updates. |
|
change - Shadow write restricted to admin-only endpoint |
Shadow collection writes are now restricted to a dedicated admin-only endpoint, preventing frontend-triggered shadow writes and ensuring shadow updates only occur through authorised backend processes. |
|
enhancement - Improved bulk deletion performance with backend batching |
Bulk entity deletion now uses batched KVstore operations on the backend combined with a fire-and-forget frontend pattern, significantly reducing the time and resource consumption of large-scale entity removal operations. |
|
enhancement - Bulk delete actions with fire-and-forget pattern |
Bulk delete operations now use a fire-and-forget pattern where the frontend triggers the operation and continues without blocking, while the backend processes deletions asynchronously with batched audit event posting and shadow cleanup. |
|
enhancement - Bulk support for variable delay disable endpoint |
The variable delay disable endpoint now supports bulk operations, reducing the number of API calls required when managing variable delay settings across multiple entities. |
|
enhancement - Progressive backoff and batched search for delay inspection |
The delayed entity inspector now implements progressive backoff (escalating 1x–4x multiplier for entities with consecutive empty inspections) and batched entity searches that combine multiple entities into a single tstats query, significantly reducing search load on the Splunk infrastructure while maintaining timely delay detection. |
|
enhancement - Proxy restricted index searches through REST API |
Searches against restricted indexes ( |
|
enhancement - Elastic sources shared edit capabilities |
Elastic Sources now support shared editing with a dedicated modal, improved explanation of shared versus dedicated reports, and a fix for the dedicated report link. These changes make it easier for teams to collaboratively manage elastic source configurations. |
|
enhancement - FLX Object description in entity header |
Flex Objects entity headers now display the Object description field with truncation support, providing better context about each entity directly in the entity overview. |
|
change - Eliminate temporary saved search from FLX/WLK benchmark tests |
The FLX and WLK burn test (benchmark) process has been refactored to avoid creating temporary saved searches during tracker creation, reducing search artefacts and cleanup overhead. |
|
enhancement - Extended pagination options with 100 and 1,000 entities per page |
New pagination options for 100 and 1,000 entities per page are now available, with 100 set as the new default. These options complement the shadow copy architecture to deliver smooth navigation across large entity volumes. |
|
enhancement - Cribl Edge fleet API monitoring improvements |
The Cribl Edge fleet monitoring use case has been further refined with improved API integration and enhanced data handling for fleet-level observability. |
|
enhancement - SPL Search Editor in elastic sources shared modal |
The elastic sources shared edit modal now uses the SPL Search Editor component for an improved search editing experience with syntax highlighting and validation. |
|
enhancement - Improved readability of FQM wizard default thresholds and simulation table |
The Data Quality Monitoring (FQM) wizard has been significantly improved for readability and usability. The simulation results table has been streamlined from 16 to 12 columns with human-readable headers, and a new per-row inspect button opens a detailed modal with quality summary, metadata, field values, and a copy-to-JSON option. Visual separators now clearly distinguish the fields and global entity sections in the default thresholds step, and stale data is automatically cleared when re-opening the wizard. |
Issue Number |
Description |
Details |
|---|---|---|
bug - FLX decision maker fails to promote orange entities to red when score threshold is met |
Fixed a bug where the FLX decision maker’s |
|
bug - Broken first chart in stateful alert email notifications on Splunk Cloud |
Fixed chart rendering in stateful alert email notifications on Splunk Cloud deployments. The email structure now uses RFC 2387-compliant multipart formatting to ensure inline charts render correctly across mail clients. |
|
bug - Misleading HTTP 500 error returned for expired sessions |
Fixed the REST API returning HTTP 500 errors instead of the correct HTTP 401 status when a user session has expired. Authentication-specific exceptions are now properly detected, logged at warning level instead of error (as this is a transient condition), and returned with a clear user-facing message. |
|
bug - Health tracker status output missing on some cycles |
Fixed the health tracker not emitting its runtime status metric on every cycle, which could cause gaps in tracker health monitoring and observability. |
|
bug - Health tracker early return in tenant index settings check |
Fixed an early return statement in the health tracker’s |
|
bug - FLX wizard not pre-populating configuration fields |
Fixed the FLX tracker creation wizard not pre-populating the |
|
bug - MessageBar notifications ignoring light theme preference |
Fixed MessageBar notification components not respecting the user’s light theme preference, causing visual inconsistency in light-themed environments. |
|
bug - SearchJob.create() calls blocked by Splunk Workload Management |
Fixed |
|
bug - WLK default thresholds using duplicate skipped percentage field |
Fixed WLK default thresholds incorrectly using the |
|
bug - WLK default thresholds fixup applied via schema migration |
Added a schema migration step to automatically correct WLK default threshold configurations affected by the duplicate field issue, ensuring existing deployments are fixed upon upgrade. |
|
bug - Shadow records not written for small entity counts |
Fixed shadow records not being written when the entity count was below the shadow threshold, ensuring consistent shadow collection behaviour regardless of entity volume. |
|
bug - Shadow collection not cleared when no records to write |
Fixed the shadow collection not being properly cleared when a tracker cycle produces no records to write, preventing stale shadow data from persisting. |
|
bug - Shadow refresh executor using incorrect thread type |
Fixed the shadow refresh executor using daemon threads, which could be terminated prematurely during shutdown before writes complete. Shadow refresh threads are now non-daemon to ensure data integrity. |
|
bug - Virtual Tenant creation triggers health tracker failure and orphan account cleanup |
Fixed health tracker execution failures during Virtual Tenant creation caused by the saved search not being ready immediately after creation. The immediate execution has been removed — the health tracker now naturally runs within its scheduled 5-minute cycle, allowing all knowledge objects to be fully initialised. Additionally, a new orphan account cleanup task automatically detects and removes stale vtenant configuration stanzas that no longer have a matching KVstore record. |
|
bug - Variable delay threshold — cannot clear duration input values |
Fixed an issue where duration input fields in the variable delay configuration could not be fully cleared using Backspace. The last digit would snap back immediately, preventing users from typing a new value. Input fields now allow free-form editing while focused. |
|
bug - Scheduler Execution Over Time chart empty for hybrid trackers in Ops Status modal |
Fixed the Scheduler Execution Over Time chart showing no data for hybrid trackers in the OpsStatus modal. The query was using the |
|
bug - Scheduled tenant trackers missing run_time metrics in yielded events |
Fixed multiple scheduled tenant trackers (Delayed Entities Inspector, Priority Policies, SLA Policies, Tags Policies) not including |
|
bug - Wrong default earliest/latest time in MHM wizard step |
Fixed the MHM (Metric Host Monitoring) component in the Virtual Tenant creation wizard using incorrect default time values ( |
|
bug - Virtual Tenants component tab switcher in Entities Overview modal does not switch content |
Fixed the component tab switcher in the Virtual Tenants Entities Overview modal not changing the displayed data when switching between components (e.g., DSM to DHM). The tabs visually highlighted but the charts and entity table remained stuck on the first component. |
|
bug - Tag input fields lack clear Enter validation feedback |
Fixed user confusion with tag input fields across the application where there was no clear indication that pressing Enter is required to validate and add a tag. A new dynamic hint message now appears when text has been typed but not yet confirmed, providing clear guidance across entity tag editing, bulk edit, and tag policy modals. |
Version 2.3.15 - build 1773055841 (09/03/2026)¶
Hint
TrackMe 2.3.15 — Native Outliers Engine, Workload Refinements & Enhanced Policies
Native ML density function engine: TrackMe now implements its own outlier detection engine, fully independent from the Splunk AI Toolkit. Models are stored and managed in KVstore collections instead of file-based storage, delivering significant improvements in performance, flexibility, and operational simplicity — particularly in Search Head Cluster (SHC) environments where file-based models caused excessive replication activity between cluster members. This change also addresses regressions introduced by recent Splunk AI Toolkit updates. Note: Upon upgrading, TrackMe automatically resets the model training dates. Existing outlier models will not be available until they are re-trained, either automatically by the scheduled training process or manually through the UI.
Workload (WLK) threshold management overhaul: WLK components received a major refinement with per-anomaly threshold configuration, providing granular control over how individual anomaly types contribute to entity health. Several regressions affecting anomaly detection accuracy have also been resolved.
Search-based (SPL) policies: Priority, Tags, and SLA policies now support a new search-based policy type, allowing administrators to define policies using Splunk SPL queries. This enables seamless integration with source tenants and external data, making it easy to maintain and synchronise governance rules across environments.
React UI refinements: Toast notifications have been deprecated in favour of Splunk UI Toolkit’s MessageBar component, delivering a more consistent and polished notification experience throughout the application.
SHA256: 627f7ebb79559c91b6eae398b8b9d7094a39f43f4e3b8536279aea7b7355d5e2
Issue Number |
Description |
Details |
|---|---|---|
feature - Native TrackMe ML density function engine with KVstore model management |
TrackMe now provides its own built-in outlier detection engine, removing the dependency on the Splunk AI Toolkit. Outlier models are stored and managed in KVstore collections, replacing the file-based approach used by the toolkit. This delivers better performance, easier management, and eliminates replication overhead in Search Head Cluster environments. |
|
feature - Search-based (SPL) policy type for priority, tags, and SLA policies |
A new search-based policy type is available for priority, tags, and SLA policies. Administrators can define policies using Splunk SPL queries, enabling integration with source tenants and external data sources for centralised governance management across environments. |
|
feature - WLK flexible threshold configuration with per-anomaly management |
Workload (WLK) components now support flexible, per-anomaly threshold configuration, giving administrators granular control over how each anomaly type is evaluated and scored. Out-of-monitoring-time removal and skipped percentage fixes are also included. |
|
feature - Continuous impact score metrics generation |
Impact score metrics are now generated continuously, providing a complete time-series view of entity health scoring for improved observability and trend analysis. |
|
feature - Impact score over time chart in Score Definition modal |
A new chart in the Score Definition modal visualises impact score trends over time, making it easier to understand how entity health evolves and to identify patterns. |
|
feature - Outliers training cooldown after score events |
After an outlier score event is generated, a cooldown period now prevents immediate model retraining, preserving the model state so that administrators can investigate the anomaly before the model adapts. |
Issue Number |
Description |
Details |
|---|---|---|
enhancement - Migrate toast notifications to MessageBar |
Toast notifications throughout the application have been replaced with Splunk UI Toolkit’s MessageBar component, providing a more consistent and integrated notification experience. |
|
enhancement - Improved entity name visibility in High Priority Entities Overview |
Entity names in the High Priority Entities Overview modal are now displayed with improved visibility, making it easier to identify entities at a glance. |
|
enhancement - Pre-populate secret fields when editing UCC configuration accounts |
When editing existing UCC configuration accounts, secret fields are now pre-populated, reducing friction during account management and configuration updates. |
|
enhancement - Icons in bulk edit category dropdown |
The bulk edit category dropdown now includes descriptive icons for each category, improving usability and visual navigation. |
|
enhancement - Prompt to enable lagging class override when modifying entity-level thresholds |
When modifying entity-level thresholds, the UI now prompts users to enable the lagging class override if applicable, ensuring threshold changes take effect as expected. |
|
change - Default delay policy to variable with Business hours template for DSM/DHM |
New DSM and DHM tenants now default to a variable delay policy with a built-in Business Hours template, providing more realistic monitoring thresholds out of the box. |
|
change - Lagging classes default to Priority level with Variable delay mode |
Lagging class defaults have been updated to use Priority-level matching with Variable delay mode, aligning with the enhanced threshold management introduced in recent releases. |
|
change - Remove Windows OS-specific library dependencies |
Removed Windows-specific library dependencies from the application package, reducing package size and simplifying deployment. |
|
change - Workload table Anomaly Reason column uses filtering instead of sorting |
The Anomaly Reason column in WLK workload tables now uses filtering instead of sorting, making it easier to focus on specific anomaly types. |
|
change - Backup & Restore minor layout enhancements |
Minor layout improvements to the Backup & Restore interface for better readability and consistency. |
Issue Number |
Description |
Details |
|---|---|---|
bug - Monitoring time policy not honoured — entities turn red outside monitoring window |
Fixed entities turning red instead of remaining capped at orange when outside their configured monitoring time window. The impact-based scoring system was overriding the monitoring time cap by re-promoting entities to red when their score exceeded the threshold. All monitoring components (DSM, DHM, MHM, FLX, WLK) now correctly enforce monitoring time policies after scoring. Additionally, MHM now supports monitoring time policies for the first time. |
|
bug - Misleading “Splunk Service Unavailable” error during Virtual Tenant creation on reverse proxy timeout |
Fixed the UI incorrectly displaying a “Splunk Service Unavailable” error banner when a reverse proxy timeout (504) occurs during Virtual Tenant creation. The backend operation completes successfully in the background, and the wizard already shows the correct “Background operation” notification — but the global error handler was also triggering a misleading error. The global handler now correctly excludes tenant creation API calls. |
|
bug - WLK decision maker fails to detect several anomaly types |
Fixed a regression introduced in v2.3.6 where the WLK decision maker failed to detect errors, skipping, orphan, and delayed anomalies, potentially causing missed alerts for affected entities. |
|
bug - Duplicate and missing status messages for outlier-driven anomalies |
Fixed duplicate or missing status messages being displayed for outlier-driven anomalies, ensuring accurate and consistent anomaly reporting. |
|
bug - Hybrid tracker records re-created in loop after saved searches are deleted |
Fixed an issue where hybrid tracker records were continuously re-created after their corresponding saved searches had been deleted, causing unnecessary processing. |
|
bug - Schema version upgrade fails when upgrading from pre-2.0.9 directly to 2.3.14+ |
Fixed a schema migration failure that could occur when upgrading from very old TrackMe versions (pre-2.0.9) directly to 2.3.14 or later. |
|
bug - Outliers model stores numeric values as strings |
Fixed outlier model dictionaries storing numeric values as strings instead of proper numeric types, which could affect model accuracy and calculations. |
|
bug - Missing keys in conf spec files cause btool check warnings |
Fixed missing key definitions in configuration spec files that caused invalid key warnings during Splunk btool checks. |
|
bug - Date columns sort by string instead of epoch time in entity overview tables |
Fixed date columns in entity overview tables sorting alphabetically by string value instead of chronologically by epoch time. |
|
bug - Scoring metrics contain null taskName dimension |
Fixed scoring metrics containing null taskName dimensions caused by a Python 3.12 LogRecord attribute change. |
|
bug - Regex-based policy modal width inconsistent with other policy modes |
Fixed the regex-based policy modal having inconsistent width compared to lookup and search policy modes. |
|
bug - ESLint errors in React views |
Fixed ESLint errors in React view components to ensure code quality and consistency. |
|
bug - Pin packaging dependency for Python 3.7 compatibility |
Pinned the packaging library version to maintain compatibility with Python 3.7 environments (Splunk 9.2.x). |
|
bug - AI status report missing in SHC environments |
Fixed the AI status report being unavailable in Search Head Cluster environments due to the trackme_ai_provider configuration not being replicated across cluster members. |
Version 2.3.14 - build 1772407097 (02/03/2026)¶
Hint
TrackMe 2.3.14 — Policies Management & Lookup-Driven Workflows
Major policies management enhancement: This release introduces a significant step forward in how TrackMe manages entity governance at scale. Priority, SLA, and Tags policies now all support lookup-based matching alongside traditional regex-based rules, enabling seamless integration with external CMDB, asset inventories, and any structured data source available as a Splunk lookup (CSV or KVstore). Through a guided wizard, users can map lookup fields to entity attributes, configure value translations, and simulate policy results before applying — providing full visibility and control over policy outcomes. Regex policies are also enhanced with the ability to match against any entity field, not just the entity name. See Managing priority via policy, Tags, and Using SLA alerting to build a 2-tier monitoring system.
Several bug fixes address outlier scoring accuracy, lagging class matching with variable delay policies, and AI Assistant navigation.
SHA256: ce78970b699219a985268e4e195f186ca9b02764c508deefbc5312929429641a
Issue Number |
Description |
Details |
|---|---|---|
feature - Lookup-based priority policies for CMDB-driven priority management |
Priority policies now support lookup-based matching, enabling administrators to leverage existing Splunk lookups (CSV or KVstore) — such as CMDB or asset inventory data — to automatically assign priority levels to entities based on field matching. A guided wizard walks users through lookup selection, field mapping, priority assignment, and optional value translations (e.g. mapping external tier labels to TrackMe priority levels). Both exact and wildcard match modes are supported. Regex policies are also enhanced with configurable match fields, allowing patterns to match against any entity field (alias, index, sourcetype, etc.) instead of only the entity name. Both policy types coexist with highest-priority-wins conflict resolution, and a built-in simulation mode previews matched entities before applying. See Managing priority via policy. |
|
feature - Lookup-based policies extended to SLA and Tags |
Following the same approach introduced for priority policies, SLA policies and Tags policies now also support lookup-based matching. SLA policies can assign SLA classes (gold, silver, platinum, etc.) from a Splunk lookup with configurable field mappings and value translations, using highest-SLA-rank-wins conflict resolution. Tags policies can assign tags from a lookup field with configurable separators, merging contributions from all matching rows and across all matching policies (regex and lookup combined). Both support exact and wildcard match modes, and include a simulation mode to preview matched entities and tag distribution before applying. See Tags and Using SLA alerting to build a 2-tier monitoring system. |
Issue Number |
Description |
Details |
|---|---|---|
enhancement - Bulk edit: show priority management info banner on category selection |
The bulk edit priority management info banner — which indicates entities managed by policy or externally — now appears immediately when selecting the Priority Management category, rather than waiting for a specific action to be chosen. This aligns with the pattern established for lagging class banners and provides earlier visibility into policy-governed entities. |
|
enhancement - Shared validation utility for variable delay and lagging class time slots |
Consolidated the duplicated time slot validation logic between variable delay and lagging class handlers into a shared utility, improving maintainability and ensuring consistent validation behaviour across both features. |
Issue Number |
Description |
Details |
|---|---|---|
bug - Outliers impact scoring generated when model confidence is low |
Fixed outlier detection generating impact score events even when the ML model confidence is low (insufficient historical data). This could result in inflated and misleading outlier impact scores in the UI while the confidence banner clearly indicated insufficient data for reliable predictions. Scoring events are now correctly suppressed until the model has accumulated enough historical metrics. |
|
bug - AI Assistant “Execute in Search” opens in wrong app namespace |
Fixed the AI Assistant’s “Execute in Search” button opening SPL queries in the |
|
bug - Missing “Critical” and “Pending” priorities in tenant creation wizard |
Fixed the tenant creation wizard’s default priority dropdown only offering Low, Medium, and High options. The Critical and Pending priority levels — which are valid backend values — were missing from all six creation wizards (FLX, FQM, WLK, DHM, DSM, MHM). The dropdown now includes all five priority levels. |
|
bug - Lagging class matching broken when tenant uses variable delay policy |
Fixed lagging class matching being completely bypassed for tenants configured with a variable delay policy. All entities in such tenants showed no lagging class match regardless of configuration. The automatic coupling between variable delay and the lagging class override flag has been removed — lagging classes now correctly evaluate and apply alongside entity-level variable delay settings, and the override flag is purely user-controlled. |
Version 2.3.13 - build 1772196565 (27/02/2026)¶
Hint
TrackMe 2.3.13 — Lagging Classes Redesign & Reliability Improvements
Lagging Classes Redesign for DSM and DHM: Major redesign of the lagging classes framework introducing per-component collections (DSM and DHM), variable delay threshold support within lagging classes, and a modernised management UI. Lagging classes can now define either a static delay override or a full variable delay schedule with named time slots — bringing the same time-aware threshold flexibility introduced in 2.3.12 at the entity level, directly into lagging class policies. The matching engine has been hardened with full-match semantics for regex patterns and priority-based evaluation. See Lagging classes.
Several bug fixes address Splunk URL generation, schema migration resilience, startup modal behaviour, and KVStore record integrity.
SHA256: 20c8af75cd9be91a74f8754bea7d7b3f5282660a42234170ab60d75a57d72c80
Issue Number |
Description |
Details |
|---|---|---|
enhancement - Warn user when outliers confidence configuration changed since last training |
When the minimum days for confidence setting is changed after a model has been trained, the UI now displays a warning advising the user to retrain the model to reflect the updated confidence parameters. |
|
enhancement - AI Assistant: show response time for AI answers |
Added a response time indicator below each AI Assistant answer (e.g. “responded in 2.3s”), providing helpful feedback about AI response performance. |
|
enhancement - AI Assistant: improved latency investigation searches |
Simplified the latency investigation searches provided by the AI Assistant for DSM and DHM entities, making them more readable and easier to customise. |
Issue Number |
Description |
Details |
|---|---|---|
bug - Splunk URL generation regression with multi-segment path prefixes |
Fixed a regression where UI-generated URLs could produce broken links when TrackMe is deployed behind a multi-segment path prefix, causing missing locale or prefix path segments. |
|
bug - Regex mode uses prefix matching unlike other modes |
Fixed an inconsistency in lagging class pattern matching where regex mode performed prefix matching instead of full-string matching. A regex pattern like |
|
bug - Startup modal dialog opening logic |
Fixed startup modal dialogs appearing when not appropriate. The licensing update modal no longer appears for environments with an active paid license, and modal sequencing has been improved to prevent multiple dialogs from opening simultaneously. |
|
bug - DSM/DHM records written to KVStore without tenant_id field |
Fixed a bug where DSM and DHM entities could be persisted without a |
Version 2.3.12 - build 1772017884 (25/02/2026)¶
Hint
TrackMe 2.3.12 — Variable Thresholds at Scale & AI Assistant Maturity
AI Assistant from A to Z: The AI Assistant reaches full maturity with refinements and enhanced capabilities. New anonymisation options protect sensitive data (entity names, index names) when sending context to AI providers. Stateful alert actions now integrate the AI Status Report directly in email notifications, delivering AI-generated entity summaries tailored to the incident lifecycle (opened, updated, closed). See AI Assistant.
Variable Delay Thresholds for DSM and DHM: A long-requested feature that gives TrackMe full flexibility to dynamically adapt how data sources and hosts delays are evaluated at scale. Define time-aware thresholds that change based on business days, hours, weekends, and quiet periods — tighter thresholds during active periods, relaxed thresholds during nights and weekends. Benefits all customers from Foundation to Enterprise and Unlimited. See Variable delay.
Variable Thresholds in Flex Objects: Similarly to feeds tracking, Flex Objects now support variable thresholds — Enterprise-scale flexibility for any KPI according to business rules. Define time slots with different threshold values per metric, enabling context-aware monitoring that adapts to your operational calendar.
SHA256: 12f90414b657782c1a49268eca54e47a05ed515f48a3f2a8ac2e02e39f628604
Issue Number |
Description |
Details |
|---|---|---|
feature - Variable delay thresholds for DSM and DHM |
Introduced variable delay thresholds for splk-dsm and splk-dhm components, enabling time-aware delay monitoring. The delay threshold for an entity can now change dynamically based on the day of the week and hour of the day. Define named time slots (e.g. business hours, weekends) each with its own threshold value — tighter during active periods, relaxed during nights and weekends. Supports auto-computation from historical metrics, auto-review when data patterns shift, template presets (business hours, weekday/weekend, three-tier), tenant-level defaults, per-entity configuration, and bulk operations. Mutually exclusive with adaptive delay. See Variable delay. |
|
feature - Variable thresholds in Flex Objects |
Introduced variable thresholds for Flex Objects (splk-flx), providing Enterprise-scale flexibility for threshold-based monitoring. Define time slots with different threshold values per KPI according to business rules — adapt monitoring sensitivity based on day of week, hour of day, weekends, and operational calendars. Enables context-aware Flex Object monitoring that aligns with your organisation’s activity patterns. |
|
feature - AI Status Report in stateful alert email notifications |
Stateful alerts can now include an AI-generated entity status report in email notifications. When enabled, each email notification embeds a concise, actionable summary generated by the configured AI provider, tailored to the incident lifecycle stage (opened: what went wrong and where to investigate; updated: whether the situation has changed; closed: confirmation of recovery). Uses the same AI provider configuration — no additional setup required. Fail-open behaviour ensures emails are never blocked by AI unavailability. Additionally, a new |
|
feature - AI Assistant anonymisation capabilities |
Added configurable anonymisation options for the AI Assistant to protect sensitive data when sending entity context to AI providers. Anonymize entity names for AI: When enabled, entity names (object and alias fields) are anonymized using SHA256 hashing; the AI is guided to use object_id references instead. Anonymize index names for AI: When enabled, Splunk index names are anonymized in DSM, DHM, and MHM entity context. Both options are configurable in Configuration > General. See AI Assistant. |
|
feature - Add Splunk Hosted LLM (SLIM API) as AI provider |
Added |
|
feature - AI Assistant chat UX enhancements |
Enhanced the AI Assistant chat experience across all AI Assistant panels. Adds a resizable input area with a drag handle, fenced code block detection and rendering with SPL syntax highlighting, a Copy to clipboard button on all code blocks, and an Execute in Search button on SPL code blocks that opens the query directly in Splunk Search. User messages now render as plain text for clarity, and suggested question buttons use a modern ghost/outline style. See AI Assistant. |
Issue Number |
Description |
Details |
|---|---|---|
enhancement - Describe API endpoints use realtime decision maker view instead of KVstore records |
Changed the AI describe endpoints to query the realtime decision maker view for live entity state rather than relying on KVstore records. This ensures that AI responses reflect the current entity conditions as computed by the decision maker, instead of potentially stale KVstore data. Applies to all describe endpoints across DSM, DHM, MHM, FLX, and FQM components. |
|
enhancement - Preserve search pattern across tab switches in Tenant Home UI |
The search bar pattern in Tenant Home is now preserved on a per-component basis when switching between tabs (DSM, DHM, MHM, FQM, FLX, WLK). Patterns persist until the user performs a full page refresh or manually clears the search input, eliminating the need to re-enter the filter each time a tab is switched. |
|
enhancement - Virtual Tenants UI: add tenant multiselect filter in Scheduler and Operation Status views |
Added a tenant multiselect dropdown filter to the Scheduler Review and Operation Status pages. Users can now filter tracker jobs and operational data by one or more selected tenants. The filter enforces mutual exclusivity between the “All Tenants” option and individual tenant selections, and defaults to showing all tenants when no filter is applied. |
|
enhancement - Preserve cross-package user preferences in tenant-home and trackme-ai-assistant |
Fixed a critical issue where toggling dark/light mode from the Tenant Home or AI Assistant pages destructively overwrote Virtual Tenants user preferences. All UI pages now correctly preserve existing preferences (column visibility, widths, ordering, hidden tenants, auto-refresh settings) when updating the colour scheme, instead of replacing them. |
|
change - Increase default Outliers minimal number of days for confidence from 7 to 30 days |
Increased the default value of |
|
enhancement - Improve readability and SPL syntax highlighting in hybrid tracker wizard search input |
Improved readability of SPL search input zones across all hybrid tracker wizard creation flows, drilldown search modals, and stateful alert configuration. All SPL input fields now feature an Edit / SPL Preview toggle: Edit mode provides a larger monospace font for improved readability, while SPL Preview mode renders the query with full SPL syntax highlighting. Supports both light and dark mode themes. Applied consistently across all DSM, DHM, MHM, FQM, FLX, WLK, and Elastic Sources wizards, as well as drilldown search and alert configuration modals. |
|
change - Reduce right image size in FLX converging panel info |
Fixed the diagram image on the right side of the FLX converging wizard panel info being displayed at the same size as the screenshot on the left, making it look oversized and degraded. The diagram is now properly constrained and scaled to maintain visual clarity alongside the screenshot. |
Issue Number |
Description |
Details |
|---|---|---|
bug - High priority entities count discrepancy between header badge and modal list |
Fixed a mismatch where the header badge count for high priority entities did not match the number of entities shown in the High Priority Entities Overview modal. When disabling a component, stale priority counts were left behind in the tenant summary, inflating the header badge total beyond the actual entities displayed in the modal. The modal now correctly filters to enabled entities only, and disabling a component properly cleans up all associated summary and statistics data. |
|
bug - Some backends are not honouring system-level splunkd timeout in backend REST calls |
Fixed several backend handlers that had a hardcoded 120-second timeout in their REST calls instead of respecting the system-level |
|
bug - Splunk root URI auto-detection may include /app suffix causing double /app in drilldown links |
Fixed the Splunk root URI auto-detection logic which incorrectly included |
|
bug - Stateful alert: premature incident closure when entity is red due to manual score influence (empty anomaly_reason) |
Fixed premature incident closure in the stateful alert helper when an entity remains in a red state due to manual score influence but has an empty |
Version 2.3.11 - build 1771520654 (19/02/2026)¶
Hint
TrackMe 2.3.11 — AI Assistant Everywhere & Reliability Improvements
This release extends the AI Assistant to all TrackMe UI pages, making context-aware AI guidance available across the entire product — from entity investigation to REST API reference, backup management, maintenance windows, bank holidays, and license management. Each page automatically provides its own structured context to the AI, enabling precise, data-driven answers without manual explanation. See AI Assistant.
Python 3.13 compatibility: Fixed Data Sampling regex failures on Splunk environments running Python 3.13, where global inline flags are now enforced at position 0.
User preferences integrity: Fixed a critical bug where toggling dark/light mode from secondary UI packages silently destroyed all user preferences (column visibility, widths, ordering, hidden tenants) stored by the Tenant Home and Virtual Tenants packages.
Codebase cleanup: Fully decommissioned the deprecated identity cards feature and removed unused KVstore collections, eliminating dead endpoints and reducing codebase complexity.
Several additional fixes address restore reliability, Logs Inspector performance, component metrics generation, Flex Converging error handling, and logging verbosity.
SHA256: bf58a5de087059f771b0decb23c1e7ecba4ea50a4eb6c795c4b44d66c33b3ead
Issue Number |
Description |
Details |
|---|---|---|
feature - AI Assistant extended to all TrackMe UI pages |
Extended the TrackMe AI Assistant from entity-level investigation to a product-wide feature available across all major TrackMe UI pages. The AI Assistant button is now available in the top-right header of: REST API Reference (helps navigate the API catalogue with curl and SPL |
Issue Number |
Description |
Details |
|---|---|---|
enhancement - Virtual Tenants: add clear button to tenant search bar |
Added a clear (✕) button inside the tenant search bar input field in the Virtual Tenants UI. When a search string is entered to filter tenants by id, alias, or description, a small cross icon now appears on the right side of the input. Clicking it clears the search field and resets the filtered tenant list in a single click, instead of requiring users to manually select and delete the text. |
|
enhancement - Flex Converging: graceful handling when tenant/component no longer exists |
Improved the |
|
change - Decommission deprecated identity cards REST endpoints and macros |
Fully decommissioned the deprecated identity cards feature, which was deprecated in version 2.0.87 and replaced by the notes feature. Removed all REST endpoint handler files ( |
|
change - Decommission deprecated KVstore collections |
Removed the deprecated and unused KVstore collections |
Issue Number |
Description |
Details |
|---|---|---|
bug - Data Sampling: PatternError with Python 3.13 due to global regex flags not at the start of the expression |
Fixed a bug where Data Sampling execution failed with a |
|
bug - Restore: saved searches and alerts fail when |
Fixed a bug where restore operations failed with |
|
bug - User preferences cookie overwrite destroys cross-package preferences |
Fixed a critical bug where toggling dark/light mode from any of the 8 secondary React UI packages (Backup & Restore, License, Maintenance KDB, Maintenance Mode, Bank Holidays, REST API Reference, Logs Inspector, Remote Accounts Overview) silently destroyed all user preferences stored by the Tenant Home and Virtual Tenants packages. All 10 React UI packages share the same |
|
bug - Components Register: runtime metrics not generated on first tracker execution |
Fixed a bug where runtime metrics ( |
|
bug - Logs Inspector UI: implement pagination for the events table to prevent browser freezing |
Fixed a performance issue in the Logs Inspector UI (TrackMe > Logs Inspector) where the events table loaded up to 10,000 events without any pagination, rendering all rows in the DOM at once. This caused significant browser performance degradation and potential freezing, especially with large volumes of logging events over extended time ranges. The fix adds pagination controls on top of the events table, limiting the number of rows displayed per page to ensure a responsive and smooth user experience. |
|
fix - Prevent large logging from |
Fixed excessive log verbosity in |
|
fix - Stateful Alert: skip email account settings retrieval for localhost pseudo account |
Fixed a bug where |
Version 2.3.10 - build 1771340984 (17/02/2026)¶
SHA256: 31e2cf8c25447ef7f4e2694beadeac67ba89fb30580d4cabdf6bffe2ac2daaf8
Issue Number |
Description |
Details |
|---|---|---|
enhancement - Allow configuring the splunkd timeout for local REST API calls and SDK connections |
Introduced a configurable |
Issue Number |
Description |
Details |
|---|---|---|
bug - Outliers: Missing audit events for bulk rules update and per-entity ML model operations |
Fixed multiple issues with missing or incorrect audit events in Outliers-related operations. Bulk rules update: the |
|
bug - Schema upgrade fails with [Errno 97] Address family not supported by protocol on IPv6-disabled systems |
Fixed a bug where the schema upgrade task failed with |
|
bug - Flex Objects wizard: Missing impact score slider in Outliers Metrics (ML) definition |
Fixed a bug where the Flex Objects creation wizard was missing an impact score slider in the Outliers Metrics (ML) section. While the Default Thresholds section already included an impact score slider per threshold rule, the Outliers section did not have this equivalent control, preventing users from setting a custom impact score for each metric’s outlier detection. The fix adds a |
Version 2.3.9 - build 1771243524 (16/02/2026)¶
Hint
TrackMe 2.3.9 — Introducing the In-App AI Assistant & Reliability Improvements
This release marks a landmark evolution for TrackMe with the introduction of the In-App AI Assistant, bringing AI-powered entity investigation and contextual guidance directly into the Splunk interface.
AI Assistant: A fully integrated, context-aware AI chat assistant that analyses entity health, interprets ML Outliers results, suggests investigation steps, and provides threshold tuning advice — all within the entity investigation panel. Entirely opt-in, no data is sent to any external service until an administrator explicitly configures a provider. Provider-agnostic, it supports OpenAI, Azure OpenAI, Anthropic Claude, Google Gemini, Mistral AI, Ollama, and any OpenAI-compatible endpoint — giving organisations full control, including the option to use self-hosted open-source LLMs for complete data sovereignty. See AI Assistant.
Python 3.13 compatibility: Critical fixes for Splunk 10.2+ / 11.x environments, addressing SVG-to-PNG chart conversion in Stateful Alerting and SOAR integration module loading.
Data integrity: Fixed a persistent field handler bug where custom per-entity impact score weights and other user-configured values could be silently overwritten during tracker conflict updates.
UI refinements: Improved Outliers detection disabled-state visibility, threshold simulation accuracy, React chart stability, and refreshed all Splunk UI React dependency packages to their latest versions with measurable bundle size reductions.
Several additional enhancements address global license usage monitoring use cases and default groupby consistency.
Important
Introducing the TrackMe AI Assistant — AI-Powered Entity Investigation
The TrackMe AI Assistant is a context-aware, provider-agnostic AI chat interface embedded directly into the entity investigation workflow. This is a pivotal capability that positions TrackMe at the forefront of the Splunk ecosystem, bridging the gap between data observability and intelligent, AI-driven operations.
Why it matters:
Instant contextual analysis: When a user opens the AI Assistant from any entity, TrackMe automatically collects the full structured description of the entity — health state, scoring breakdown, metrics, thresholds, ML Outliers results, investigation SPL searches, and more — and injects it into the LLM context. The AI provides specific, data-driven answers without the user having to describe the situation manually.
Actionable investigation guidance: The assistant suggests concrete investigation steps, explains anomaly scoring, interprets ML model outputs, and provides entity-type-specific threshold tuning advice — turning complex observability data into clear next actions.
Opt-in only: No AI functionality is active and no data leaves your environment until an administrator explicitly configures a provider. The feature is completely inert without a configured provider.
Full provider flexibility: Administrators can configure one or multiple LLM providers simultaneously — cloud-based (OpenAI, Azure OpenAI, Anthropic, Google Gemini, Mistral AI) or fully self-hosted (Ollama) for environments with strict data governance requirements. Users can switch between providers from the chat panel to compare results or optimise costs.
Data sovereignty: Organisations with strict data privacy or regulatory requirements can connect TrackMe to their own LLM infrastructure — self-hosted open-source models via Ollama, private corporate deployments via any OpenAI-compatible endpoint, or region-specific cloud deployments. The choice is entirely yours.
Enterprise-grade security: RBAC-enforced entity context reads, encrypted API key storage, system-level credential isolation, and configurable concurrency limits ensure the AI Assistant operates within your organisation’s security boundaries.
Streaming experience: Real-time token streaming with Markdown rendering, syntax-highlighted SPL code blocks, and conversation context within sessions provide a modern, responsive chat experience.
For full configuration and usage details, see the AI Assistant documentation.
SHA256: 3e3d9ba1b2c759697e21d4aa6001d285dd5264d9e1da7c8ba2e5b5b4fcc80504
Issue Number |
Description |
Details |
|---|---|---|
feature - In-App AI Assistant for entity investigation |
Introduced the TrackMe AI Assistant, an integrated, context-aware AI chat assistant accessible from any entity investigation panel across all entity types (DSM, DHM, MHM, FLX, FQM, WLK). The assistant automatically collects the full structured entity description (health state, scoring breakdown, metrics, thresholds, ML Outliers results, investigation SPL searches, and threshold tuning guidance) and passes it to the configured LLM provider as context. Supports two entry points: the AI Assistant button in the entity panel header and the Ask AI option in the entity three-dot actions menu. Features include five suggested starter questions, free-form conversational input with session context, real-time token streaming, Markdown rendering with syntax-highlighted SPL code blocks, multi-provider switching, and automatic job cancellation on panel close. The assistant is provider-agnostic with support for OpenAI, Azure OpenAI, Anthropic Claude, Google Gemini, Mistral AI, Ollama (self-hosted), and any OpenAI-compatible API endpoint. Security features include user-level RBAC enforcement for entity context reads, system-level credential isolation, encrypted API key storage via Splunk |
Issue Number |
Description |
Details |
|---|---|---|
enhancement - Add Global License Usage Monitoring Use Cases |
Added new FlexLog use cases for monitoring global Splunk License usage at the environment level. |
|
enhancement - Default GroupBy Behavior Consistency - Handle |
Improved the default groupby behavior in the Tenant Home UI so that setting the keyword |
|
change - Splunk UI - Refresh All React Dependency Packages to Latest Versions |
Refreshed all Splunk UI React dependency packages to their latest compatible versions for release 2.3.9. Notable updates include |
Issue Number |
Description |
Details |
|---|---|---|
bug - Stateful Alerting - SVG to PNG Chart Conversion Fails Under Python 3.13 (Splunk 10.2+) |
Fixed an issue where stateful alert email chart images failed to render as PNG when Splunk runs Python 3.13 (introduced in Splunk 10.2+ via |
|
bug - Email Delivery Configuration Fails Validation When Email Security Is Set to None |
Fixed a bug where setting the Email security field to |
|
bug - dsm/dhm - Custom Per-Entity Impact Score Weights Not Persisting Reliably |
Fixed a critical bug in the persistent field handler ( |
|
bug - dsm/dhm - Threshold Simulation Returns Incomplete Search Results |
Fixed an issue where the DSM/DHM threshold simulation screen returned incomplete search results when simulating latency and delay thresholds against entity historical data. The React simulation modal ( |
|
bug - Outliers Anomaly Detection UI Does Not Indicate When Outliers Detection Is Disabled at the Entity Level |
Fixed a UX inconsistency where navigating to the “Outliers anomaly detection” tab for an entity with disabled outliers detection showed no indication of the disabled state — charts were empty and the “Manage outliers detection” button remained accessible but non-functional. The fix adds a clear informational message when outliers detection is disabled, offers a direct option to re-enable it, prevents loading of outliers stats/charts when detection is disabled, and hides the “Manage outliers detection” button and related configuration controls. |
|
bug - Intermittent React Crash on Chart Rendering When Navigating Back From Fullscreen Slider |
Fixed an intermittent React crash ( |
|
bug - Persistent Field Conflict-Update Overwrites Entity Values With None When KV Store Field Is Missing |
Fixed a follow-up issue to #1531 where the persistent field handler’s conflict-update path unconditionally overwrote entity field values with |
|
bug - SOAR Integration Python 3.13 Compatibility Fix |
Fixed an issue where SOAR-related endpoints ( |
Version 2.3.8 - build 1770827560 (11/02/2026)¶
Hint
TrackMe 2.3.8 — Performance, UI Modernization & New Capabilities
This release delivers significant performance optimizations, new UI capabilities, AI-ready REST API endpoints, and important bug fixes.
Performance: Major improvements eliminate redundant REST loopback calls and subsearch macro overhead, significantly reducing latency and search slot consumption across all UI operations.
New React UIs: The Logs Inspector and Splunk Remote Accounts Status Overview dashboards have been fully migrated from XML to native React, providing richer visualizations and consistent theming.
AI Agent Integration: New REST API endpoints under
/trackme/v2/describeprovide comprehensive, structured entity descriptions designed for AI agent consumption, enabling automated investigation and triage.Flex Objects: A new graphical configuration panel for tracker options simplifies hybrid tracker creation, and a critical fix resolves stuck
status_not_metanomalies.Bulk Actions & UX: Improved bulk action feedback, new search capabilities in hybrid tracker management, and enhanced column sorting across Virtual Tenants UI.
Several additional bug fixes address stateful alerting, global notes consistency, Bank Holidays Admin, and maintenance routines for disabled tenants.
SHA256: 8d44f23482f8707755c830b553e5e1c9e43285669b33c5e5b0eb50f8cb9bbb3b
Issue Number |
Description |
Details |
|---|---|---|
feature - Flex Objects (splk-flx) - Graphical Tracker Options UI for Hybrid Tracker Creation |
Added a graphical configuration panel in the Flex Objects hybrid tracker creation wizard (Step 4 - “Test and Review”) that allows users to visually define tracker options instead of manually writing |
|
feature - Replace Logs Inspector Dashboard with Native React UI |
Replaced the existing XML-based logs inspector dashboard ( |
|
feature - Entity Description REST API Endpoints for AI Agent Integration |
Introduced new REST API endpoints under |
|
feature - Migrate Splunk Remote Accounts Status Overview to React Native UI |
Replaced the existing XML dashboard “TrackMe - Splunk Remote Accounts Status Overview” with a native React UI built on the Splunk UI toolkit. The new React page preserves all existing functionality with tab-based navigation: Overview Statuses (connected/failing accounts, donut chart, detailed tables), Token Rotation Statuses (color-coded status table), and Token Rotation Logs (events viewer for past 30 days). Includes status filter dropdown, Show Detailed Config toggle, dedicated refresh button, and full dark/light mode support consistent with TrackMe UI preferences. |
Issue Number |
Description |
Details |
|---|---|---|
enhancement - Search Functionality for Hybrid Tracker Management |
Added a powerful search capability to all hybrid tracker management screens, making it easier to find and manage trackers. All hybrid tracker management modals now include a search bar that allows you to filter trackers in real-time. Simply type in the search box to instantly filter the tracker list. |
|
enhancement - TrackMe Health Tracker - SLA Breaches Events Generation Optimization |
Optimized the SLA breaches events generation task to improve performance for tenants who have disabled SLA breaches events generation. The |
|
enhancement - Bulk Actions - Bulk Period Exclusion for Outliers Detection |
Added a powerful bulk action that allows you to add exclusion periods to multiple entities and their ML models simultaneously, streamlining the management of Machine Learning Outlier Detection exclusion periods. A new bulk action “Add a period of exclusions” is now available in the Outliers Detection Actions category. This action allows you to select multiple entities and apply the same exclusion period to all of them and their corresponding ML models in a single operation. |
|
enhancement - StateFul Alerting - Optional Email Security (SSL/TLS) for Email Delivery Accounts |
Made email security (SSL/TLS) optional for email delivery accounts, giving you more flexibility when configuring email delivery gateways. The email security field in email delivery account configuration is now optional, allowing you to configure email delivery without SSL or TLS encryption when needed. |
|
enhancement - Bulk Actions - Improved User Experience for Bulk Actions Impact Scoring |
Improved the user experience for bulk actions that process entities in the background, providing immediate feedback so you can continue working without waiting. When you trigger bulk actions for “Set as false positive” or “Manually influence the score”, you’ll now receive immediate feedback that the action is running in the background. The system shows an immediate notification (toast message), closes the modal immediately so you can continue working, processes entities sequentially in the background without blocking your workflow, and notifies you with a summary when all processing is finished. This enhancement applies to the following bulk actions in the Impact Score category: “Set as false positive”, “Manually influence the score”, and “Set outliers as false positive” (Outliers Detection Actions). |
|
enhancement - Virtual Tenants UI - Column Sorting Enhancement |
Added column sorting functionality for numerical columns in the Virtual Tenants UI, making it easier to analyze and compare data in the Scheduler Review and Operational Health Status views. Numerical columns in the Virtual Tenants UI tables now support sorting with visual indicators (up/down arrows), matching the sorting functionality available in the Entity Overview table. |
|
enhancement - Central KVcollection Mode Configuration |
Added support for configurable modes for querying KVstore collections, allowing administrators to optimize performance based on their environment and requirements. A new configuration parameter |
|
enhancement - Tenant-Level Global Note Override |
Virtual Tenants can now override the system-wide global note and link with tenant-specific values, allowing different tenants to display different global documentation while maintaining the flexibility to fall back to system-wide defaults. Each Virtual Tenant can now configure its own “Global note” and “Global link” in the tenant settings. If a tenant doesn’t configure tenant-level values, it automatically uses the system-wide global note/link (if configured). The system follows this priority order: 1) Tenant-level global note/link (if configured), 2) System-wide global note/link (if configured), 3) No global note (if neither is configured). |
|
enhancement - Flex Objects (splk-flx) - default_threshold Documentation Improvement |
Improved the documentation for the |
|
enhancement - Performance - Eliminate Subsearch Macro Overhead in React UI Search Queries |
Eliminated subsearch macro overhead in React UI search queries by directly embedding index names into search queries instead of using macros (e.g., |
|
change - Trial License Request - Add Company Name and Email Contact Fields |
Added two new required fields to the trial license request form: Company Name to identify the organization requesting the trial, and Email Contact to enable follow-up communication. Both pieces of information are attached as a note to the generated trial license key via the Cryptolens API, enabling better tracking and support during the trial period. |
|
enhancement - Performance - Eliminate Redundant REST Loopback Calls in load_component_data Endpoint |
Replaced 3 separate HTTP roundtrips and service connections with direct conf reads using a single shared system-level SDK connection in the |
|
enhancement - Enhance Splunk License Usage per Index Use Cases (Cloud & Enterprise) |
Enhanced the built-in FlexLog use cases for Splunk License usage per index monitoring ( |
|
enhancement - ML Outliers Management Modal - Convert to Full-Screen Slider |
Converted the ML Outliers simulation and management screen ( |
|
enhancement - Flex Objects (splk-flx) - Generate Periodic Summary Events for Inactive FLX Entities |
When a Flex (FLX) entity becomes inactive and transitions to red, the inactive entities inspector now generates periodic |
Issue Number |
Description |
Details |
|---|---|---|
bug - StateFul Alerting - Fix for log_warn AttributeError in Stateful Alert Helper |
Fixed a critical bug where the |
|
bug - Global Notes Now Available Across All Components |
Fixed an issue where global notes configured in the TrackMe Configuration page were only appearing in the DSM (Data Sources Monitoring) component, despite the configuration UI indicating they should apply to “all entities”. Global notes and links are now correctly displayed across all TrackMe components: DSM (Data Sources Monitoring), DHM (Data Hosts Monitoring), FQM (Fields Quality Monitoring), FLX (Flex Objects Tracking), WLK (Workload Monitoring), and MHM (Metrics Hosts Monitoring). |
|
bug - General Health Manager - Stateful Records Maintenance Routines Skip Disabled Tenants |
Fixed an issue where the general health manager maintenance routines for stateful records did not check if a tenant is disabled before attempting to operate on their KVstore collections, causing errors for disabled tenants. The root cause was that maintenance loops iterate over all tenants including disabled ones. The following tasks in |
|
bug - Flex Objects (splk-flx) - status_not_met Can Remain Stuck in KVstore Preventing Entity Recovery |
Fixed an issue where the |
|
bug - Bank Holidays Admin - Helper Function Naming Collision Causes REST API Errors |
Fixed a bug where a helper function in the Bank Holidays Admin REST handler had a naming collision with the REST routing pattern, causing API errors. The REST framework routes requests by constructing function names from |
|
bug - Hide Impact Score Sliders When Related Features Are Disabled at Tenant Level |
Fixed an issue where the Manage Impact Score Configuration modal in the Tenant Home UI showed all impact score sliders regardless of whether the related features were enabled at the tenant level. The Outliers - Default Impact Score slider is now hidden when Machine Learning is disabled for the tenant, and the DSM - Data Sampling Anomaly slider is now hidden when Data Sampling is disabled for the tenant. Previously, adjusting these scores had no effect when the corresponding feature was off, which was confusing for users. |
|
bug - Flex Objects (splk-flx) - Burn Test Benchmark 3-Dots Menu Button Expands to Full Width |
Fixed a minor visual glitch where the 3-dots menu button (MoreVertical kebab menu) in the Flex Objects hybrid tracker creation wizard burn test benchmark results header bar would expand to the full container width instead of staying fixed at its icon size. Added explicit size constraints ( |
Version 2.3.7 - build 1769984652 (01/02/2026)¶
Hint
Hotfix Release - Logical Group Health Calculation Fix
This hotfix release addresses a critical issue with logical group health percentage calculations and entity protection.
Fixed an issue where logical groups were not correctly calculating health percentages and protecting entities when the group remained healthy.
This fix ensures accurate health percentage calculations for logical groups and correct entity state display (blue when protected by healthy group).
SHA256: 8df79010be52a457a8db49d38b130c17f1761669ce3b698e026134b3e2a47b65
Issue Number |
Description |
Details |
|---|---|---|
bug - Logical Groups - Logical groups are not correctly calculating health percentages and protecting entities when the group remained healthy |
Fixed an issue where logical groups with multiple members sometimes showed incorrect health percentages, causing false alerts even when the group was actually healthy. Improved handling of logical group member lists to ensure accurate percentage calculations regardless of how the data is stored. Logical group protection is now correctly applied after all state evaluations, ensuring entities are properly protected when the group remains healthy. Entities that should be protected by a healthy logical group (shown as blue) were incorrectly remaining red, especially when entities became unhealthy due to impact scores. This fix affects all entities that are members of logical groups, ensuring accurate health percentage calculations, correct entity state display, and accurate logical group status messages. |
|
enhancement - improves the reliability and resilience of the TrackMe Health Tracker by implementing automatic retry logic for transient connection errors when communicating with the Splunk REST API |
Improved the reliability and resilience of the TrackMe Health Tracker by implementing automatic retry logic for transient connection errors when communicating with the Splunk REST API. The Health Tracker now automatically retries failed connections to Splunkd with exponential backoff, reducing false failure reports caused by temporary network issues or Splunkd service interruptions. Key improvements include faster error detection (reduced timeout from 10 minutes to 1 minute), better error handling and logging, and improved connection stability. |
|
bug - Virtual Tenants UI Bug Fix for “Open in search all skipping events” |
Fixed an issue where the “Open in search all skipping events” button in the Virtual Tenants Scheduler Review modal was using an incorrect search query. The button now correctly searches for TrackMe scheduler events with proper status normalization. The search query now correctly targets the scheduler sourcetype instead of splunkd, includes proper filtering for TrackMe app events, and normalizes status values for consistent reporting (completed, skipped, deferred). |
|
enhancement - Table Sort Arrow Indicators |
Enhanced the visual feedback for sortable columns in the Virtual Tenants entity overview and Tenants UI entity tables. Sort arrows now clearly indicate the current sort direction: ↑ (Up arrow) for ascending order, ↓ (Down arrow) for descending order, and ↑↓ (Double arrow) for sortable but not currently active columns. This makes it easier to understand which column is currently sorted and in which direction, improving the overall user experience when working with entity tables. |
|
enhancement - SOAR Integration Error Handling Improvements |
Significant improvements to error handling and reliability for the SOAR (Splunk SOAR) integration in TrackMe. The integration now includes automatic retry logic with exponential backoff for failed requests, making it more resilient to transient network issues, API timeouts, and temporary SOAR service unavailability. All SOAR API requests now have timeout protection (60 seconds by default), preventing requests from hanging indefinitely. When automation brokers are temporarily offline, the system now skips affected assets with a warning instead of failing the entire operation, with automatic retry on the next run when brokers become available. Error messages now include more context (endpoint, server, request details) making it easier to diagnose issues. The integration now validates SOAR API responses before processing them, preventing errors from malformed or unexpected response formats. |
Version 2.3.6 - build 1769529938 (27/01/2025)¶
Hint
TrackMe 2.3 — Major UI Modernization Release
We are pleased to introduce our fully redesigned user interfaces.
This release represents a major step forward in performance, scalability, and user experience.
With TrackMe 2.3, all of user interfaces are now built on top of Splunk UI native React.
This is a complete and full rewrite of TrackMe main user interfaces, which we are excited to share with you.
Many various improvements and enhancements were implemented to fully support the new interface, and to ensure a smooth transition from the old Splunk stack JS to a modern and native React UI.
Hint
Impact-Based Alerting (IBA), a new scoring-driven alerting model now powering TrackMe.
IBA replaces rigid, hard-coded alerting rules with a flexible and configurable impact scoring system, inspired by security-grade risk-based approaches and adapted to data reliability and observability.
With IBA, TrackMe now: - Aggregates anomaly impact over time instead of reacting to isolated signals - Allows fine-grained tuning of how different anomalies contribute to entity health - Provides full transparency with detailed score breakdowns and traceable score events - Significantly reduces alert noise while preserving operational confidence
The transition is seamless for existing users, requires no manual intervention, and is fully configurable through the UI.
SHA256: 56a4143e40392b4767f9405837f0e1ab4ee53ce2cede21551ef56e5321757f1d
Issue Number |
Description |
Details |
|---|---|---|
bug - Tenant Home UI - Impact Score Configuration Update Fix when the tenant has deprecated parameters |
Fixed an issue where Impact Score Configuration updates failed with the error “Argument ‘data_sampling_set_state’ is not supported by this handler” for tenants with deprecated configuration fields. The update endpoint now automatically filters out deprecated fields before updating tenant configurations. |
|
bug - Impact Score Weight Zero Now Properly Handles Entity Status |
Fixed an issue where entities with impact score weights configured to 0 incorrectly remained red instead of being green. The decision maker process now consistently checks score components when total_score == 0, correctly setting entity status to green when all components have a score of 0. |
|
bug - Bulk threshold updates for Flex Objects (FLX) and Flex Query Manager (FQM) entities were failing |
Fixed bulk threshold updates for FLX and FQM entities that were failing with “The component is required” error. The API payload structure now correctly includes the component identifier and properly formats threshold fields according to backend requirements. |
|
bug - Flex Objects/Fields Quality (splk-flx/fqm) - thresholds created through the FLX and FQM threshold management screens were not functioning correctly |
Fixed an issue where thresholds created through the FLX and FQM threshold management screens were not functioning correctly due to incorrect metric name formatting in API calls. |
|
bug/enhancement - Tags Bulk Edit Improvements |
Fixed 404 errors for bulk editing tags for FLX, FQM, WLK, DHM, and MHM components that were incorrectly calling the DSM-specific endpoint. All components now use their correct endpoints and provide clearer, more flexible tag management options. |
|
bug - Stateful Alert Email Account Retrieval Bug |
Fixed an issue where stateful alerts configured with “ingest_only” delivery mode (or other non-email modes) would fail during initialization when attempting to retrieve email account settings. The alert initialization now only retrieves email account settings when email delivery is actually enabled, and continues with other delivery types if email account retrieval fails. |
|
bug - Flex Objects - Converging Tracker Status Recovery Issue |
Fixed a bug where converging FLX trackers would not recover from red (alerting) state back to green state, even when the percentage of availability (pct_availability) reached 100% and all underlying entities were healthy. |
|
bug - Remove misleading warning when a brand-new entity is first discovered before its KVstore entry exists |
Fixed misleading warning when a brand-new entity is first discovered before its KVstore entry exists. When a record has no KVstore entry and record_is_new is true, the system now logs a debug message and skips the rejected-record check, avoiding unnecessary warnings for new entities. |
|
bug - Fix Schedule Configuration Display for Stateful Alerts |
Fixed an issue where the Schedule Configuration section (containing Cron Schedule, Suppress fields, Suppress period, and Day time filtering) was incorrectly displayed in the “Various” step when creating stateful alerts. Stateful alerts now correctly hide this section as they use a fixed, non-configurable schedule (*/5 * * * *). |
|
bug - Virtual Tenants UI - Resolved intermittent flash when opening the Virtual Tenant creation wizard |
Resolved an intermittent flash when opening the Virtual Tenant creation wizard by preventing immediate close on the initial click. |
|
bug - Fields Quality (fqm) - Quality Tracker Creation Fails for Remote Targets |
Fixed an issue where creating a new quality tracker using sampling mode with a remote target would fail. The “Benchmark sampling mode” button was incorrectly disabled for remote targets, and tracker creation would fail with an API error stating that collect_limiter must be greater than 0. The application incorrectly assumed that sampling mode was not supported for remote targets, even though sampling mode is fully supported. |
|
bug - Standardized Splunk URL generation in Virtual Tenants and Tenant Home UI to prevent malformed search links |
Fixed “Open in Search” links in the FQM wizard and standardized Splunk URL generation in Virtual Tenants and Tenant Home UI to prevent malformed search links. Some “Open in Search” actions were opening URLs directly without using Splunk.util.make_url, resulting in URLs missing the /splunk/<locale> base. Added shared helpers for Splunk Web URL generation and updated components to use consistent URL construction. |
|
bug - dhm/mhm - Reset Action for DHM and MHM |
Restored the reset functionality for Data Host Monitoring (DHM) and Monitor Host Monitoring (MHM) entities. The reset action allows you to reset entity metrics and monitoring state, clearing accumulated metrics and historical data, and re-evaluating the entity from scratch. This is particularly useful when an entity has been reporting incorrect sourcetypes or data, or when you need to clear stale metrics and start fresh. |
|
bug - Fields Quality (fqm) - Fields Quality Monitoring Dictionary Management Fixes |
Fixed checkbox focus styling in the Fields Quality Monitoring dictionary management table. Checkboxes displayed an incorrect focus outline that was wider than expected, creating visual inconsistency. Updated checkbox focus behavior to match the standard pattern used throughout TrackMe. Also fixed the “Add new field” dropdown functionality - the “Allow unknown” and “Allow missing/null” dropdowns were not functioning correctly and did not apply default values when adding new fields to dictionaries. Corrected the dropdown implementation to use proper Splunk UI components and ensured default values (“No” for both options) are correctly applied when adding new fields. |
Issue Number |
Description |
Details |
|---|---|---|
enhancement - Enhanced Bulk Edit Actions for Outliers Detection Rules |
Expanded bulk edit functionality for Outliers Detection Rules, allowing you to update all configuration settings in bulk operations. This enhancement brings full parity between bulk edit and individual model settings, making it much easier to manage outlier detection rules across multiple entities. |
|
enhancement - Update Maintenance Period Feature |
Added ability to update (extend or reduce) the maintenance period directly from the Maintenance Mode UI without needing to disable and re-enable maintenance mode. The feature automatically updates both the maintenance mode status and the associated knowledge database record. |
|
enhancement/feature - Entity Actions and Search Enhancements |
Improved entity actions menu with clearer labeling: the “Open” action has been renamed to “Open entity” with a new icon to better indicate it opens the entity detail view. For DSM and DHM components, a new “Open in search” action is now available directly in the actions menu, allowing users to quickly open the entity’s search query in Splunk Search. |
|
enhancement - Time Range Picker Persistence |
The time range picker in entity modal views now remembers your selection as you navigate between different entities. Your chosen time range for each tab is preserved throughout your session until you reload the page, eliminating the need to manually adjust the time range for each entity you view. |
|
enhancement - FLX Entity Overview - “ALL” Option Enhancement |
Added a convenient “ALL” option to the entity selection dropdown in the FLX component’s entity overview modal. This allows you to quickly view metrics for all available entities without manually selecting each one individually. Selecting this option displays charts and statistics for all entities that match your selected metrics and pre-filter criteria. |
|
enhancement - Non-Disruptive Refresh for Overview Tabs |
Improved user experience when refreshing data in the Overview entity modal for FLX and FQM components. Components now remain visible during refresh operations, eliminating the disruptive full-page spinner that previously appeared. Only individual loading indicators update during refresh, providing a smoother, less disruptive experience. |
|
enhancement - Flex Objects - Multiple Default Metrics Support for Flex Objects |
TrackMe now supports defining multiple default metrics for a single Flex Object tracker. You can select multiple default metrics for each tracker using a multi-select dropdown, allowing you to preset multiple metrics in the metric selector when viewing entities managed by a tracker. The default metrics management interface displays one row per tracker with all associated metrics shown in a multi-select component, making it easier to manage configurations for multiple trackers. |
|
enhancement - Flex Objects (flx) - Threshold Management UI Improvements |
Enhanced the threshold management interface for FLX and FQM components to make it easier to understand and configure thresholds. These improvements address user feedback about UI complexity and provide clearer, more intuitive threshold configuration. |
|
enhancement - Configurable Auto-Refresh Interval for Action Progress Events |
Introduced a configurable auto-refresh interval for action progress event logs. Administrators can now adjust the refresh rate (5-300 seconds) based on their system’s performance characteristics. The default value is 15 seconds (less aggressive than the previous hardcoded 5 seconds). Polling behavior remains identical to the previous implementation - only the interval value is now configurable. |
|
enhancement - Benchmark Race Condition Fix |
Fixed benchmark (burn test) execution failures in large Search Head Cluster (SHC) environments. After creating temporary reports for burn tests, the system now waits longer before executing them to account for knowledge object propagation delays in large/complex SHC environments, preventing “Unable to find saved search” errors. |
|
enhancement - TrackMe health_tracker - Performance Optimization - unclosed_stateful_incidents Task |
Optimized the unclosed_stateful_incidents health tracker task to eliminate an N+1 query performance issue. The task now uses batch fetching to retrieve data objects grouped by component, reducing the number of KVstore queries from thousands to just a few per execution. This dramatically reduces execution time for environments with large numbers of entities. |
|
feature - Auto-retry with Backoff for splunkremotesearch |
TrackMe now includes automatic retry logic with exponential backoff for remote search connectivity checks. When splunkremotesearch encounters a timeout during connectivity checks, it will automatically retry the connection with exponential backoff before giving up. This helps handle transient network connectivity issues in busy environments, reducing false failures due to temporary network conditions, particularly useful in large-scale deployments where network connectivity can be temporarily affected by high load or network congestion. |
|
enhancement - TrackMe Health Tracker - Performance Optimization for SLA Breach Events Generation |
Optimized the SLA breach events generation task (gen_sla_breaches_events) with significant performance improvements. The task now uses batch operations to retrieve notification records instead of individual queries, dramatically reducing the number of database queries, especially when processing many breached SLA objects. Tasks that previously took minutes can now complete in seconds. |
Version 2.3.5 - build 1768473196 (15/01/2025)¶
Hint
TrackMe 2.3 — Major UI Modernization Release
We are pleased to introduce our fully redesigned user interfaces.
This release represents a major step forward in performance, scalability, and user experience.
With TrackMe 2.3, all of user interfaces are now built on top of Splunk UI native React.
This is a complete and full rewrite of TrackMe main user interfaces, which we are excited to share with you.
Many various improvements and enhancements were implemented to fully support the new interface, and to ensure a smooth transition from the old Splunk stack JS to a modern and native React UI.
Hint
The highlight of this release is the introduction of Impact-Based Alerting (IBA), a new scoring-driven alerting model now powering TrackMe.
IBA replaces rigid, hard-coded alerting rules with a flexible and configurable impact scoring system, inspired by security-grade risk-based approaches and adapted to data reliability and observability.
With IBA, TrackMe now: - Aggregates anomaly impact over time instead of reacting to isolated signals - Allows fine-grained tuning of how different anomalies contribute to entity health - Provides full transparency with detailed score breakdowns and traceable score events - Significantly reduces alert noise while preserving operational confidence
The transition is seamless for existing users, requires no manual intervention, and is fully configurable through the UI.
SHA256: d2484bb1cdb13245b3a07097c899274bba1f09688c55b92771c9245b37b5b0d0
Issue Number |
Description |
Details |
|---|---|---|
bug - ML Outliers Detection - DSM and DHM Components KPI Metrics Dropdown |
Fixed an issue where the KPI metric dropdown was empty when adding Machine Learning models for outliers detection in the Data Source Monitoring (DSM) component. |
|
bug - Flex Objects/Fields Quality (flx/fqm) - HTTP 500: records_list must be a list of records when trying to update a threshold record |
Trying to update existing threshold records through the UI fails with HTTP error 500. |
|
bug - Fix typos, mispells or non ideal English sentences in alert action labels |
Fixed various typos or spelling issues in alert actions. |
|
bug - Fix: Error Panel Not Clearing After Service Recovery |
When the Splunk service becomes unavailable or returns an error response, the application correctly detects and displays an error panel. However, once the service recovers and requests start succeeding again, the error panel remains visible even though the issue has been resolved. |
|
bug - Fix Data Sampling default in DSM tenant creation wizard |
The option “Enable Data Sampling” should be configurable in the tenant advanced options at the stage of the creation wizard. |
|
bug - Fix: FLX Component Cartouche Text Overflow Issue |
Fixed a UI bug where long group names in the FLX component cartouche could overflow and overlap with adjacent items. The fix ensures text wraps properly across multiple lines when needed. |
|
bug - Flex Objects library - syntax error in UC splk_detect_drop_events_count_absolute |
There is a syntax error in the UC splk_detect_drop_events_count_absolute |
|
bug - Fix missing threshold lines in Performance Metrics charts for DSM and DHM |
Fixed a bug where threshold-based performance metric charts were not displaying threshold lines. The search queries for latency and delay metrics with threshold options now correctly include threshold values from entity records (data_max_lag_allowed and data_max_delay_allowed). Additionally, removed unnecessary timechart parameters that were not needed for these queries. |
|
bug - Virtual Tenants UI - wrong default tstats root time span values in Virtual Tenants UI and partial support of advanced options |
The Virtual Tenants UI hybrid tracker creation wizards for DSM and DHM now properly honor all user selections and use consistent default values matching the Tenant Home UI. |
|
bug - Data Sources monitoring (dsm) - Fixed incorrect entity naming convention in merged mode for delayed inspector |
Fixed a bug where entities with an incorrect naming convention (@all without colon) were being created when the delayed inspector processed offline entities in merged mode. The fix ensures that existing entities using the legacy :all convention continue to use that convention, while new entities correctly use the :@all convention. This maintains full backward compatibility and prevents data integrity issues. |
|
bug - Improved ML Outliers User Experience - Removed Confusing Error Messages for Empty States |
Fixed an issue where an error toast message was incorrectly displayed when accessing the ML Outliers Anomaly Detection section for entities that don’t have any ML models defined yet. This is a normal scenario when ML models haven’t been created for an entity, and the UI now correctly displays the empty state message without showing an error. Actual errors (such as network failures or server errors) will still display error messages as expected, ensuring users are properly notified of real issues. |
|
bug - Virtual Tenants/Tenants Home - Auto-Refresh Pre-Selection |
Fixed auto-refresh setting not showing current value in Settings panel. The auto-refresh setting in the Settings panel (available in both Virtual Tenants and Tenant Home UIs) now correctly displays the current value when the panel is opened. Previously, neither “Enabled” nor “Disabled” was highlighted, even when a preference was set. The setting now properly shows the user’s saved preference (if set), system default value (if no user preference exists), or defaults to “Disabled” (if neither exists). |
|
bug - Stateful alerting - Add Missing UI for Priority Level Selection in Active Commands |
The priority level filtering feature for active commands was already implemented in the backend but was missing from the UI. This release adds the missing UI component, allowing users to configure priority filtering for command execution, matching the existing email notification priority feature. |
Issue Number |
Description |
Details |
|---|---|---|
feature - TrackMe transition to impact score basis anlysis |
TrackMe introduces Impact Scoring, a major milestone that makes alerting smarter, tunable, and far more actionable. Administrators can fine-tune impact per tenant/component/anomaly through a rich UI, reduce false positives with one-click suppression, and keep full transparency with a clear score breakdown and score events traceability. |
|
change - remove remaining artefacts of icons_state_mode |
There are some remaining artefacts of the option icons_state_mode, which is decomissioned since TrackMe 2.3.x. |
|
enhancement - Updates all Outliers management related logic to work out with the object_id rather than object as a convention |
Historically, all TrackMe related commands and logics dealing with Outliers detection management rely on the object value rather than its unique identifier, which can eventually be less robust when facing complex object string structures. These changes prevent any issue at this level. |
|
enhancement - Flex Objects / Fields Quality (flx/fqm) - Enhanced Threshold Management with Dynamic Metric Selection and Improved Change Tracking |
The threshold management screens for FLX and FQM entities have been significantly improved with a better user experience. Users can now select metrics from a searchable dropdown instead of typing them manually, receive clear notifications when they have unsaved changes, and get immediate feedback through toast notifications. The modal has also been widened to provide more space for viewing and editing thresholds. Additionally, critical bugs preventing threshold updates have been fixed. |
|
enhancement - bulk edit for lagging policies - allow human time patterns similarly to per entity edit |
This enhancement allows bulk edit to accept and automatically translate human based time patterns, in the same way we do in the per entity edit screen. |
|
enhancement - Virtual Tenants / Tenant Home UI - match color code for the right hande side pie charts with their respective label |
For UI consistency purposes, we should match the color scheme with their associated label |
|
change - decomission red on outliers and red on sampling following the scoring implementation |
With the implementation of configurable impact scoring, entity status (green, orange, red, blue) is now determined by aggregated impact scores from various anomaly types. Users can control the score attributed to outliers and data sampling anomalies through the impact scoring configuration. Therefore, Red on Outliers and Red on Sampling options are now decomissionned. |
|
enhancement - ML Train and ML Monitor Now Support Sequential Bulk Processing |
The ML Train and ML Monitor API endpoints have been updated to accept lists of entities and process them sequentially instead of concurrently. This change provides better resource management and prevents resource contention when processing multiple entities. |
|
feature - Enhanced Table Customization |
Users can now resize table columns by dragging column borders and reorder columns via drag-and-drop in the “Show/Hide Columns” menu. All preferences are automatically saved per tenant and component for a personalized experience. |
|
enhancement - Enhanced Tag Grouping in Entity Tables |
We’ve improved how entities are grouped by tags in the entity overview tables. Entities with multiple tags now appear in each individual tag group, making it easier to discover and organize entities by their tags. |
|
enhancement - Flex Objects (flx) - handle the epochtime conversion of the Tracker Runtime into human readable format |
The cartouche shows the Tracker Runtime in epochtime format, but should rather be shown in human readable format. |
|
enhancement - Add “Open in Search” Button for Failed Search Simulations in FLX Hybrid Tracker Wizards |
This enhancement adds an “Open in Search” button that appears when search simulations fail in the FLX hybrid tracker creation wizards. This allows users to manually execute the search query in Splunk’s search UI to debug syntax errors, execution failures, or missing mandatory fields. |
|
enhancement - Enhanced entity search capabilities and quick access to status messages in Virtual Tenants and Tenant Home UIs |
We’ve improved the entity search functionality and added quick access to entity status information. You can now search for entities by their unique key ID, and clicking on an entity name opens a modal with status message cards. The modal includes a convenient “Open entity overview” button for quick navigation to detailed entity information. |
|
change - License management UI - outdated mention of deprecated components and missing components |
The licensing UI references an outdated component and misses other restricted components. |
|
change - potential GB/TB conversion issue in the dashboard TrackMe SVC usage stack |
This simplifies the unit conversion to prevent any confusion between GB/TB |
|
enhancement - Virtual Tenants UI - Tenant Home UI links now use keyid instead of object value |
Updated Tenant Home UI action links to use keyid instead of object as the URL parameter. This change prevents issues with complex object values that may contain special characters or formatting that causes problems in URL encoding and routing. The keyid is a stable, controlled identifier that provides better reliability when opening entities in the Tenant Home UI from the Virtual Tenants overview table and High Priority Overview modal, ensuring that entities with complex object values can be reliably opened without URL parsing issues. |
|
enhancement - Flex Objects - Auto-preset tracker name from selected use case in Flex Objects creation wizard |
The Flex Objects (FLX) use case creation wizard now automatically presets the tracker name field with the selected use case name when a use case is chosen from the library. This reduces manual data entry and helps ensure consistency between use case names and tracker identifiers. Users can still manually edit the tracker name if customization is needed. |
|
feature - Concurrent FLX Trackers Support |
TrackMe now supports multiple FLX (Flex Objects) use case trackers running concurrently against the same objects. Previously, when multiple trackers monitored the same entities, status descriptions, metrics, and configuration fields would be overwritten by the last executing tracker. This enhancement preserves all information from all trackers by storing tracker-keyed JSON objects within existing fields, while automatically aggregating values according to specific rules (worst-status for status, merge-all for metrics, highest-value for disruption_min_time_sec, lowest-value for max_sec_inactive, collect-all for lists). |
|
change - Flex Objects library - update Splunk cpu & memory use case to match same objects following flx concurrent support |
This minor change of these use case follows the addition of concurrent flx trackers support. |
|
enhancement - Flex Objects (flx) - In the use case wizard, provide a quick open in search access also if no entities are returned while the search is successfully executed |
This enhancement adds an “Open in Search” button and informational message when a Flex Objects tracking simulation completes successfully but returns no entities. This provides users with easy access to investigate their search query, similar to the existing functionality for error cases. |
|
enhancement - Minutes Support for Delay/Latency Thresholds |
Added minutes (m) unit suffix support for delay and latency threshold inputs. You can now specify delay and latency thresholds using minutes in addition to seconds, hours, days, and weeks. This makes it easier to configure thresholds for shorter time periods without having to calculate seconds manually. |
|
enhancement - Flex Tracker Examples and ML Configuration Updates |
This update refreshes flex tracker examples in the React UI, standardizes outlier metrics configuration across all flex tracker use cases in the library, and updates default metrics to use p95 (95th percentile) instead of average for better peak usage monitoring. |
|
feature - Virtual Tenants UI - Virtual Tenants Card Detail Level Configuration & Clickable Badges |
Two major enhancements to the Virtual Tenants UI: Card Detail Level Configuration allows administrators and users to control the level of detail displayed in Virtual Tenants cards, providing enhanced visibility into entity alert status by priority level. Additionally, all priority badges on tenant cards are now interactive, enabling users to quickly access filtered entity overviews directly from the cards. |
Version 2.3.4 - build 1766484049 (23/12/2025)¶
Hint
TrackMe 2.3 — Major UI Modernization Release
We are pleased to introduce our fully redesigned user interfaces.
This release represents a major step forward in performance, scalability, and user experience.
With TrackMe 2.3, all of user interfaces are now built on top of Splunk UI native React.
This is a complete and full rewrite of TrackMe main user interfaces, which we are excited to share with you.
Many various improvements and enhancements were implemented to fully support the new interface, and to ensure a smooth transition from the old Splunk stack JS to a modern and native React UI.
SHA256: 44db7515f3ca64a7c5ed63895633e277d2b16eef96490f324b04bc6695b279d4
Issue Number |
Description |
Details |
|---|---|---|
bug - Tenant Home UI - Alert creation dropdown provides invalid options for acknowledgment |
The alert creation modal was providing invalid options for the acknowledgment dropdown. Fixed to display only valid options: sticky and unsticky. |
|
bug - Tenant Home UI - Performance issues in logical groups management screens with high number of groups |
When managing a large number of logical groups, the management screens experienced performance issues that could freeze the browser window. This fix introduces automated pagination to address the performance problem. |
|
bug - Tenant Home - Select all checkbox inconsistency behavior does not actually select all matching entities |
The “select all” checkbox in the Tenant Home Entities Overview table only selected records visible in the viewport instead of all records matching the active filter or search. Fixed by updating the selection logic to use all filtered records, ensuring bulk operations work correctly with filtered result sets. |
Issue Number |
Description |
Details |
|---|---|---|
enhancement - Command trackmegetcoll - Ensure tenant_id value cannot be null or empty |
The trackmegetcoll command is used in various concepts such as alerts. This update ensures the tenant_id value in a record cannot be null or empty, preventing tenant_id from being rendered as null or empty in case of anomalies. |
|
enhancement - Expandable Charts for Scheduler and Ops Status Tables |
Adds expandable rows to the Scheduler Review and Tenants Operational Health modals, showing two charts per report: Runtime Statistics Over Time (line chart) and Scheduler Execution Over Time (column chart). This enhancement allows quick access to runtime metrics and scheduler views for a particular search without leaving the user interface. |
|
enhancement - Add refresh icon shortcut in entity full screen view and normalize entity views buttons layout |
This enhancement adds a refresh icon in the entity view next to the main selector. It also normalizes button styles and layout for UI consistency purposes, including standardizing the slide panels back button. |
|
feature - Stateful alerting refactoring with pre-filtering custom command and single alert enforcement |
Stateful alert events are now pre-filtered before they reach the alert action backend, improving performance and reducing unnecessary processing. The command automatically retrieves the stateful alert configuration (including “orange as alerting state” setting) to ensure consistent filtering. Additionally, the UI now prevents users from creating multiple stateful alerts per tenant, enforcing a one-to-one relationship between tenants and stateful alerts. |
|
enhancement - Tenant Home UI - Improve user interface behavior and consistency for automated and manual refreshing |
In the Tenant Home UI, auto-refresh now pauses when the user is reviewing entity detailed statistics, preventing disruption once the entity slider view is opened. Additionally, the refresh action now properly refreshes entity cartouches, the primary screen, and the actual charts or views currently being inspected by the user. |
|
feature - Bank Holidays Management |
TrackMe administrators can now configure bank holiday periods that prevent alerts from triggering, similar to maintenance mode. Bank holidays apply globally to all tenants and can be set as one-time periods or recurring holidays that automatically repeat each year. The feature includes: an intuitive web interface for creating, editing, and deleting bank holiday periods with a modern React-based UI; calendar visualization with each holiday period displaying a mini calendar showing the month with highlighted dates; year organization with periods automatically grouped by year (oldest first) for easy navigation; country import for importing holidays for 40+ countries including US, UK, France, Germany, Italy, Spain, Canada, Australia, Japan, Brazil, and many more; recurring holidays that can be marked to automatically generate future occurrences; bulk operations to clear all periods at once with a single action; and automatic maintenance where the system automatically creates future occurrences and cleans up past periods for recurring holidays daily, ensuring bank holidays are always up-to-date without manual intervention. |
|
enhancement - Hybrid trackers management - Automatically re-create hybrid tracker records if KVstore content was unexpectedly purged |
The tenant health tracker now automatically handles the re-creation of hybrid tracker records if the central KVstore contains the hybrid trackers metadata, and these trackers exist in the central store but not in the dedicated KVstore of the tenant. |
|
enhancement - Tenant Home UI - Automatically detect automated Ack conflicts when creating alerts |
This enhancement automatically detects if a tenant (and component if applicable) already has an automated acknowledgment creation action when creating a stateful alert or vice versa when creating a legacy alert for the component. This prevents users from creating both a stateful alert with auto-acknowledgment enabled while an existing legacy technical alert exists, or creating a legacy component alert if there is an existing stateful alert that performs auto-acknowledgment. The system will inform the user of the conflict risk and automatically disable the auto-acknowledgment as needed (either for the stateful alert when creating a stateful alert with an existing technical alert with automated acknowledgment, or the opposite when creating a technical alert with the auto-acknowledgment action if there is a stateful alert already performing automated acknowledgment). |
Version 2.3.3 - build 1765917730 (16/12/2025)¶
Hint
TrackMe 2.3 — Major UI Modernization Release
We are pleased to introduce our fully redesigned user interfaces.
This release represents a major step forward in performance, scalability, and user experience.
With TrackMe 2.3, all of user interfaces are now built on top of Splunk UI native React.
This is a complete and full rewrite of TrackMe main user interfaces, which we are excited to share with you.
Many various improvements and enhancements were implemented to fully support the new interface, and to ensure a smooth transition from the old Splunk stack JS to a modern and native React UI.
SHA256: fb3624e3be08255b79b52ffa5501e6344805535d9a191d5bf8492e3aef9526f0
Issue Number |
Description |
Details |
|---|---|---|
bug - TrackMe Virtual Tenants UI - Remove the back button from RBAC update screen |
There should not be a back button in the RBAC update screen. |
|
bug - TrackMe Tenant Home UI - Wrong endpoint called for dhm when doing bulk edit lagging policy, leading to a 404 |
When performing bulk edits for lagging policy on the dhm component, the endpoint called is incorrect, which leads to a 404 error. |
|
bug - Virtual Tenants UI - Long alias or description in the Virtual Tenant account can badly affect the cards layout |
Fixed a layout bug in the Virtual Tenants cards where long tenant descriptions (or other long text) caused cards to expand beyond their width and overlap adjacent cards. |
|
bug - TrackMe Tenant Home UI - Inconsistent results in the enabled entities count (first single view) in some cases |
There is an issue in the calculation made by the UI for the first single view showing the number of enabled entities. In some contexts, the calculation is incorrect and leads to an invalid number. |
|
bug - DB Connect poor quality and capability management can affect the SDK method service.confs[“app”] in limited privileges mode |
DB Connect is affecting applications calling service.confs[“app”] SDK methods in non-privileged modes. |
|
bug - Schema upgrade - Missing variable initialization leads to backup error message during schema upgrade |
A missing initialization for a variable is leading to an exception during the schema upgrade for the backup verification. |
|
bug - Remove outdated app dependency verification for semicircle_donut which is not required anymore in 2.3.x |
The app dependency semicircle_donut is not required anymore for TrackMe 2.3.x. |
|
bug - Tenant Home UI - Group by view in the table results gets unexpectedly reset to the default when accessing the top menu selector |
When accessing the top selector menu while a different group by was selected, the group by is unexpectedly reset to the default. |
|
bug - Virtual Tenants UI - Redundant API call to trackmeload and missing pre-settings for indexes and RBAC |
Redundant API call: trackmeload was called twice — once in VirtualTenantsContentInner and once in VirtualTenantsContent (for theme), causing duplicate requests. Missing pre-settings: Tenant creation wizards didn’t use trackmeconf from the trackmeload response to pre-set owner and RBAC defaults (indexes, owner, admin/power/user roles), so they used hardcoded values instead of the configured defaults. |
|
bug - Open in search FQDN consistency |
Some “Open in search” links in Tenant Home and Virtual Tenants UIs used inline make_url calls instead of the makeSplunkUrl helper, so they didn’t respect the server FQDN and root URL context. Standardized all “Open in search” links to use makeSplunkUrl for consistent URL handling. |
Issue Number |
Description |
Details |
|---|---|---|
enhancement - TrackMe Home UI - Add tooltip to entity table icons (Actions column) |
This minor enhancement adds tooltips for UI consistency purposes to the icons in the Actions column. |
|
feature - Virtual Tenants/Tenant Home UI - Add a “collapse all” / “expand all” shortcut icon in the table header |
This enhancement adds a new icon action in the table header after the “All entities” dropdown, that allows collapsing / expanding all groups easily. |
|
change - Upgrade all Splunk UI packages to latest releases |
Updated Splunk UI packages to latest releases. |
|
enhancement - Virtual Tenants UI - Missing drilldown in pie charts to match the Tenant Home behaviour |
The Virtual Tenants UI and the overview tenant modal contain the same pie charts as the Tenant Home UI does. However, the screen was missing the drilldown chart actions. This enhancement updates the Virtual Tenants UI so it matches the Tenant Home behaviour. |
|
enhancement - Virtual Tenants/Tenant Home UI - Improve rendering of the dhm Idx/st summary column |
This is a minor improvement of the dhm column for Idx/st summary. |
|
enhancement - Virtual Tenants/Tenant Home UIs - Prevent sort on summary / last metrics columns for the components where it does not make sense |
In mhm, the “Summary” column should not be sortable. In flx/fqm, the “Last metrics” column should not be sortable. In wlk, the “Metrics summary (24h)” column should not be sortable. |
|
enhancement - TrackMe Home UI - Add the kebab selector in single view cards of the main screen and when missing |
Some single view cards were missing the kebab selector. |
|
enhancement - Virtual Tenants/Tenant Home UIs - Minor user interface enhancements |
Added refresh button with tooltip to TenantUpdateStatus modal, positioned in the top-right corner. Added refresh button with tooltip to Virtual Tenants main screen header, before the settings button. Added refresh button with tooltip to Tenant Home UI header, before the settings button. Added tooltips to settings and action buttons in both Virtual Tenants and Tenant Home UIs. Replaced remaining emoji/unicode icons with CSS dots. |
|
change - Deprecating and removing the usage of the Python sparklines module which was only used by the SmartStatus action |
We are deprecating and removing the usage of the sparklines module which was used in SmartStatus, and providing very low value. |
|
change - Python compatibility - Prepare TrackMe for Python 3.13.x compatibility with upcoming Splunk releases |
These changes are performed to handle TrackMe compatibility with the upcoming Splunk migration to Python 3.13. |
|
enhancement - Virtual Tenants UI - Minor enhancements in the table views for update status and operation status |
Minor improvements to the rendering of the tables. |
|
enhancement - Schema upgrade - Safer and more robust identification of past backups in the last 24 hours during schema upgrade |
Implemented a more robust identification of backup operations initiated or performed during the past 24 hours when the schema upgrade is triggered. This avoids triggering a backup during the schema upgrade if a backup was requested or completed recently. |
|
enhancement - Stateful alerts - Adding a safety check REST call to the realtime decision maker to verify the object state before accepting the incident, reducing max time since last update to 10 minutes (for non closure events), adding safeties to filtering events based on existing stateful record epoch |
Added a REST call to load_component so we can verify the object_state from realtime decision maker, before accepting the alerting status. Reduced the 60 minutes check that refuses creating a new incident if the last non closure event is not newer, to 10 minutes. Added an additional safety for time filtering when a stateful event exists. |
|
enhancement - Tenant Home UI - Auto-refresh is not implemented yet in the new React UI |
The Tenant Home did not have an auto refresh feature yet, unlike the Virtual Tenants React UI. |
|
feature - Auto-refresh Virtual Tenants/Tenant Home UI - Allow enabling/disabling at system level, add toggle on/off icon in the UIs and allow user persistent preference |
Auto-refresh can be enabled/disabled by default for all users at the system level (enabled by default). In both user interfaces, a new dynamic icon allows toggling on and off auto-refresh. Users can define in their own preference to enable or disable by default auto-refresh, which would override the system level preference. |
|
enhancement - Virtual Tenants UI - Detect if the Splunk service is not operational or behaving properly, and alert the user at load time |
The current implementation did not detect or warn the user if the Splunk search service is not operational. |
|
change - Clean up outdated and decommissioned system level preference Allow admin operations |
This system level preference is now deprecated and unused since TrackMe 2.3.x, and can be safely cleaned up. |
|
enhancement - Virtual Tenants / TrackMe Home UI - Add vertical scrollbar for the table entity menu so users can scroll through options when the screen resolution is limited |
In both UIs, the menu did not show a scrolling bar which could prevent users from accessing the full list of options. |
|
feature - Virtual Tenants / TrackMe Home UI - Allow users specifying the addition of specific fields to the entity table view, which is cookie persistent per tenant and for the user |
This new feature allows users to define custom list of fields depending on the available fields of the entity records, which persist via the user cookie for the given Virtual Tenant. |
Version 2.3.2 - build 1765452718 (11/12/2025)¶
Hint
TrackMe 2.3 — Major UI Modernization Release
We are pleased to introduce our fully redesigned user interfaces.
This release represents a major step forward in performance, scalability, and user experience.
With TrackMe 2.3, all of user interfaces are now built on top of Splunk UI native React.
This is a complete and full rewrite of TrackMe main user interfaces, which we are excited to share with you.
Many various improvements and enhancements were implemented to fully support the new interface, and to ensure a smooth transition from the old Splunk stack JS to a modern and native React UI.
SHA256: 358637a2c2bc04292df77f1af8fe2dd539214bcad5c9370c72a4bf02a60f5b78
Issue Number |
Description |
Details |
|---|---|---|
bug - TrackMe Tenant Home/Virtual Tenants - The table should show by default only enabled entities |
By default, only the enabled (monitored_state=”enabled”) entities should be shown in the table for both UIs |
|
bug - Tenant Home UI - Bulk edit priority management is missing the pending priority level |
The bulk edit modal should allow handling the priority level “pending” |
|
bug - Tenant Home UI - Wrong endpoint is used for some actions such as delete temporary and permanenlty for other components than dsm |
The delete action from bulk and for some of the components is targeting a wrong endpoint, leading to a 404 error. |
|
bug - Tenant Home UI - minor inconsistent checkbox layout in some modal screens |
Very minor layout issues for the checkboxes in some modal screens. |
|
bug - Tenant Home UI - Issue opening the data sampling add rule modal from the main screen menu instead of on a per entity basis |
The link to “Manage: Data sampling custom rules” doesn’t behave properly when opened from the main screen menu. |
|
bug - Tenant Home - Missing advanced tools for lagging policy simulation and auto definition |
These advanced tools have not been migrated from the legacy UI. |
Issue Number |
Description |
Details |
|---|---|---|
enhancement - TrackMe Tenant Home - Adds a per entity selector in the table view providing quick access to entity edit options |
This enhancement adds the kebab selector on a per entity basis. |
|
enhancement - TrackMe Tenant Home/Virtual Tenants - Add the column monitored_state in the table |
This enhancement re-adds the monitored state column in the table view |
|
enhancement - TrackMe Tenant Home/Virtual Tenants - Sets all columns not based on filterable to be sortable |
Ensure all columns show the sort header option |
|
enhancement - Virtual Tenants / Tenant Home UIs - Adds a “Refresh” action in the table engine menu allowing to refresh the table content only |
This enhancement adds a “Refresh” action underneath the “Open in search” action within the engine icon next to the table views. |
|
enhancement - Virtual Tenants/Tenant Home UIs - Adds the “Group: Anomaly reason” in the shortcut menu for both user interfaces |
The group by anomaly reason is a valuable option that needs to be re-added. |
Version 2.3.1 - build 1765362371 (10/12/2025)¶
Hint
TrackMe 2.3 — Major UI Modernization Release
We are pleased to introduce our fully redesigned user interfaces.
This release represents a major step forward in performance, scalability, and user experience.
With TrackMe 2.3, all of user interfaces are now built on top of Splunk UI native React.
This is a complete and full rewrite of TrackMe main user interfaces, which we are excited to share with you.
Many various improvements and enhancements were implemented to fully support the new interface, and to ensure a smooth transition from the old Splunk stack JS to a modern and native React UI.
SHA256: e2a26c6f06626bfa18f22279e338ea2512d406ddf1c31365190b562a623437c1
Issue Number |
Description |
Details |
|---|---|---|
bug - Tenant Home UI - inconsistent selector menu width in benchmark step from hybrid tracker creation wizard |
The width of the kebab selector in the benchmark step for some components is not consistent and expands over the whole div of the container |
|
bug - Rest API reference UI - usage of the search facility can lead to a critical uncatched exception in the UI |
In the Rest API reference UI, a weakness in the code may lead to a critical failure of the user interface with a typescript error “TypeError: Cannot read properties of undefined (reading ‘toLowerCase’)” |
|
bug - Tenant Home UI - Missing priority level selection multiselect for the creation of a stateful alert in the alert creation wizard |
The alert creation wizard is missing the multiselect input to the selection of the priority levels for emails notifications. This is a regression from the React UI migration. |
Version 2.3.0 - build 1765269590 (09/12/2025)¶
Hint
TrackMe 2.3.0 — Major UI Modernization Release
We are pleased to introduce our fully redesigned user interfaces.
This release represents a major step forward in performance, scalability, and user experience.
With TrackMe 2.3.0, all of user interfaces are now built on top of Splunk UI native React.
This is a complete and full rewrite of TrackMe main user interfaces, which we are excited to share with you.
Many various improvements and enhancements were implemented to fully support the new interface, and to ensure a smooth transition from the old Splunk stack JS to a modern and native React UI.
SHA256: 3ac6e7ef8f236a357f702bd44b91e3a0a78484e24164b136708379493beb3e2f
Version 2.2.4 - build 1764227551 (27/11/2025)¶
Hint
For Splunk 9.1.1 and later
From TrackMe 2.1.x, there is no more compatibility with Splunk 9.0.x and earlier.
The last release compatible with Splunk 9.0.x is TrackMe 2.0.99
SHA256: 94120a98ec7f36abc8be4f1d6207136b209914c8d8cede60fcf02cd49ddc4b00
Issue Number |
Description |
Details |
|---|---|---|
bug - Metric hosts tracking - permanently deleted objects not honored |
In splk-mhm, permanently deleted objects are not properly taken into account. |
|
bug - Virtual Tenants UI (React) - pie charts are not refreshed when hitting the refresh all action, nor through auto-refresh |
There is a logic issue in the React UI which leads to the pie charts for scheduler activity and tenants activity not updating on their own through auto-refresh or manual refresh. |
|
bug - Virtual Tenants UI (React) - debug console log left active when expanding entities overview |
A console log debug statement has been left active in the React Virtual Tenants UI. |
|
bug - TrackMe Home UI (Legacy) - drilldown on single view for enabled entities should filter out on enabled entities only (all components) |
The drilldown action for the “All enabled entities” should filter entities with monitored_state=”enabled”, but currently filters monitored_state=*. |
Issue Number |
Description |
Details |
|---|---|---|
enhancement - Backup & Restore - Show the backup archive size in the user interface |
The backend stores the size in bytes of the backup archive. This enhancement ensures this information is displayed in the summary table within the user interface. |
|
enhancement - Backup & Restore - Add a per KVstore size summary that can be easily accessed through the UI |
This enhancement adds the detail of the per KVstore size, easily accessible in the per backup details through the user interface. |
|
enhancement - Virtual Tenants UI (React) - Additional safety to prevent tenant cards overlap at certain DPI/Zoom |
This enhancement provides an additional safeguard to prevent tenant cards from overlapping at certain DPI/Zoom levels. |
|
enhancement - TrackMe REST API - Prevents duplications in permanently deleted entities KVstore collections |
When performing permanent deletion, the current implementation does not account for already existing records in the KVstore for the same object. This enhancement adds a verification and will bypass the creation of the deleted record if necessary. |
|
enhancement - TrackMe Health Tracker - Adding a subtask to verify for duplicated records in the permanently deleted records collection and act if necessary |
This enhancement adds a subtask in the main task inspect_collection:permanently_deleted_records_inspection which detects and purges any duplicated records based on the object value. |
|
feature - Virtual Tenants creation and update wizards (React) - Adds a panel showing events creation so we provide better visibility of the operations being processed |
This new feature provides an enhanced user experience when creating or updating Virtual Tenants by automatically adding an event view showing the logs associated while the operation progresses. |
|
change - Decommission of the legacy Virtual Tenants UI |
The legacy Virtual Tenants UI based on Splunk JS is now decommissioned and removed from TrackMe. |
|
feature - TrackMe REST API - provide a merged endpoint to retrieve rules and data from a pure Python logic |
This feature provides a new endpoint to get a merged summary of the data and rules for Outliers. It also enhances the endpoints for rules, and provides an additional data endpoint. |
|
change - Hybrid trackers - For splk-dsm, sets the default time span to 30s rather than 1s |
This minor change updates the default time span for splk-dsm trackers from 1s to 30s. |
|
change - Configured webpack to build Splunk React UI components in production mode |
Configured webpack to build Splunk React UI components in production mode per Splunk React UI documentation. This removes development warnings and guidance from production builds published to Splunk Base. Changes include: added webpack DefinePlugin to all webpack configs to inject process.env.NODE_ENV, removed devtool: ‘eval-source-map’ from production builds, and updated build/build.py to set NODE_ENV=production when building Splunk UI packages. |
Version 2.2.3 - build 1762443437 (06/11/2025)¶
Hint
For Splunk 9.1.1 and later
From TrackMe 2.1.x, there is no more compatibility with Splunk 9.0.x and earlier.
The last release compatible with Splunk 9.0.x is TrackMe 2.0.99
SHA256: 62a2250a099215174561d46474c4cb47ae48edb98586dc4e3455a9b4a3243366
Issue Number |
Description |
Details |
|---|---|---|
bug - Virtual Tenants UI (React) - regression when expanding an entity in the overview table |
A regression was identified when expanding the entity from the Virtual Tenant UI overview. |
|
bug - Virtual Tenants UI (React) - properly handle the API response if the tenant fails to be created so the response appears in the modal |
Ensure to properly handle the response if the tenant fails to be created. |
|
bug - regression in Backup & Restore UI when attempting to download depending in some contexts |
Fixed a regression in the Backup & Restore UI where archive downloads failed due to missing validation of the archive_base64 field in the response. Added error handling for JSON parsing and base64 decoding, plus validation to ensure the response contains valid archive data before processing. |
Issue Number |
Description |
Details |
|---|---|---|
change - trackmetrackerexecutor - Allows forcing the execution of a tracker through the savedsearch command using the argument force_savedsearch_execmode=True |
This minor change allows forcing the execution of a tracker using the savedsearch command. |
Version 2.2.2 - build 1762387662 (06/11/2025)¶
Hint
For Splunk 9.1.1 and later
From TrackMe 2.1.x, there is no more compatibility with Splunk 9.0.x and earlier.
The last release compatible with Splunk 9.0.x is TrackMe 2.0.99
SHA256: 6273f390c19fd3e699a09d760cf9d19b919d9a854b9a4ab2a93493d2ad360177
Issue Number |
Description |
Details |
|---|---|---|
bug - Virtual Tenants UI (React) - the open in search metrics link generates a non-working search due to single quotes escaping |
The open in search link for metrics at the tenant level does not work as intended due to single quotes escaping. |
|
bug - Virtual Tenants UI (React) - Pagination issues in the overview table |
There is an issue in the pagination of the table from the new Virtual Tenants user interface, which leads to stopping from generating all entities in the table. This update addresses these issues and implements options in the table header allowing to navigate through the pages, in addition with an automated scrolling if the user scrolls down the entities. |
Issue Number |
Description |
Details |
|---|---|---|
change - AppInspect warning check_idx_binary_compatibility |
Address AppInspect warning. |
|
enhancement - Virtual Tenants Overview: row virtualization |
Implemented lightweight row virtualization with dynamic height measurement for expansion rows; DOM stays tiny and scrolling remains smooth even with 10k+ rows. |
|
enhancement - Virtual Tenants UI (React) - Improved responsive tenants cards to avoid some issues in specific customer environments |
These enhancements improve the responsive aspects of the Virtual Tenants cards, to address some potential UI glitches in customer environments with very high desktop scale. |
Version 2.2.1 - build 1762134116 (03/11/2025)¶
Hint
For Splunk 9.1.1 and later
From TrackMe 2.1.x, there is no more compatibility with Splunk 9.0.x and earlier.
The last release compatible with Splunk 9.0.x is TrackMe 2.0.99
SHA256: 0931aba1c09903a63cceedad05a3452665e4a15b9d2e353b6192347f7872453b
Issue Number |
Description |
Details |
|---|---|---|
bug - Backup & Restore - potential failures in restoring TrackMe at the stage of the virtual accounts creation |
Under some conditions, it is possible that TrackMe is unable to complete a restore operation when attempting to re-create the Virtual Tenant accounts, due to several inconsistencies in the restore code. |
|
bug - TrackMe Health tracker - Virtual tenant account check and repair comes too late in the execution and is ineffective if the account does not exist |
The TrackMe health tracker has a step that checks and repairs the virtual account if missing, however this comes too late in the code logic and we fail to continue in the early stage in this case. |
|
bug - Virtual Tenants UI (React) - missing preview charts for ML Outliers |
In the new Virtual Tenant UI, the overview panel should show the ML Outliers mini-charts when ML is enabled for the entity. Due to a silent Python exception, the endpoint does not render the charts definition currently. |
|
bug - Virtual Tenants UI (React) - information panels should vary depending on the components |
When expanding entities, the new Virtual Tenant shows entity key information in a nicely formatted manner. However, the current implementation is stuck to dsm/dhm and should vary depending on the components. |
|
bug - Virtual Tenants UI (React) - prevents issues refreshing charts when collapsing and re-expanding twice the same entity |
There is an issue affecting the mini-charts generation when collapsing and re-expanding the same entity twice. |
Issue Number |
Description |
Details |
|---|---|---|
enhancement - Backup & Restore - Verify that the user context exists on the target during a restore operation, and fallback to nobody otherwise |
When performing a restore operation, we would fail to properly perform the restore if the original owner context does not exist on the target. This enhancement ensures that we verify the user context, and if necessary we fallback to the nobody user context. |
|
enhancement - Virtual Tenants (React) - ensure to show a wait spinner as soon as the user expands a given entity |
When an entity is expanded, we should immediately show a wait spinner to inform the user that TrackMe is retrieving the entity information for the mini-charts queries to be executed. |
|
enhancement - Virtual Tenants UI (React) - handle overview status message for converging Flex trackers to only keep down_entities in extra_attributes to prevent from ending with a massive large payload |
This enhancement prevents from ending with a very large payload in the overview panel for converging Flex trackers. |
Version 2.2.0 - build 1761787469 (30/10/2025)¶
Hint
For Splunk 9.1.1 and later
From TrackMe 2.1.x, there is no more compatibility with Splunk 9.0.x and earlier.
The last release compatible with Splunk 9.0.x is TrackMe 2.0.99
SHA256: 2c2de97ac5befc07d178ab87ea4b692a5b34b29157fa2f68759c2c94b6bd832d
This major release introduces a brand new refactored user interface for the Virtual Tenants management built on top of Splunk UI native React.
Issue Number |
Description |
Details |
|---|---|---|
bug - mcatalog should include the object_id in stateful alerts, minor issue in the charts_resources |
The mcatalog generation should include the object_id. The logic for the charts_resources is incorrect for wlk/flx/fqm. |
|
bug - TrackMe REST API & libs - tracker simulation API response differs if breakby is an explicit none or not set |
The API responds unexpectedly if the breakby is set to a “none” string depending on the component. |
|
bug - duplicated rename in the macro trackme_idx leads to no results being returned (this macro is historical and not used any longer) |
This macro has a duplicated rename statement and returns no results because of this. However, this is not used anymore in our codebase and will be considered for removal in a future release. |
|
bug - TrackMe REST API - multiops endpoints for tenant creation should properly interpret the absence of hybrid_objects in the REST payload |
If the payload does not include hybrid_objects, it should be set as an empty list to avoid the API from rejecting the call rather than not having any trackers to be created. |
Issue Number |
Description |
Details |
|---|---|---|
feature - Virtual Tenants next generation user interface - Native React with Splunk UI |
This release introduces the first version of the next generation user interface for Virtual Tenants, built in native React on top of Splunk UI. |
|
feature - TrackMe REST API endpoints - Adds charts_resources object to the API endpoint load_component_data for usage in TrackMe next generation user interface |
This feature adds the charts_resources object to the API response, which will be reused in TrackMe next generation user interface. |
|
enhancement - TrackMe stateful and notable alert actions - Adding a safety check for the status of the maintenance mode to control at the Python level any decision according to the status of the maintenance mode |
This enhancement adds an additional Python-level layer of safety which verifies the status of the maintenance mode and allows or prevents decisions according to it. |
|
enhancement - React UI - standardize error handling across React UIs |
Standardized error handling across React UIs: Maintenance Mode, Backup/Restore, License, and Maintenance KDB. Implemented a robust parseErrorResponse that prefers API-provided fields (error, message, response, payload, messages[0].text), falls back to raw text, then status text. Ensured the existing error modal displays these detailed messages consistently instead of generic HTTP phrases. |
|
enhancement - Maintenance KDB user interface - improve responsive input modal |
The input modal for adding records needs to be more responsive and properly adapt to any screen resolution. |
|
change - Remove dependency from Splunk_SA_CIM application |
TrackMe currently relies on the Splunk_SA_CIM for a few minor actions; this change allows removing any dependency regarding the SA CIM application for TrackMe. |
Version 2.1.33 - build 1759998519 (09/10/2025)¶
Hint
For Splunk 9.1.1 and later
From TrackMe 2.1.x, there is no more compatibility with Splunk 9.0.x and earlier.
The last release compatible with Splunk 9.0.x is TrackMe 2.0.99
SHA256: 88af89b916d798baf032f00f8574765fc671fe9cca57ed15ac594ff6b090a9bc
Issue Number |
Description |
Details |
|---|---|---|
bug - duplicated rename statement in macro trackme_metrics_idx causes no results |
There is an invalid duplicated rename in the macro trackme_metrics_idx which causes it to no return any results. |
|
bug - Fields Quality Monitoring (splk-fqm) - the concept of sample_hard_limit was not fully implemented in release 2.1.32 |
This safety was meant to be adding an hard limit in the creation of sampling based jobs for splk-fqm, but was not properly implemented at the phase of the actual job creation. |
|
bug - Backup & Restore - prevent from stoping the restore operation if failing to re-create the Virtual Tenant account |
There can be conditions where we fail to restore the Virtual Tenant account, and we should not stop the restore process if this happens. Secondly, we should sliently attempt to delete the Virtual Tenant account first, and have a safer definition of what keys are allowed in the Virtual Tenant account data. |
|
bug - TrackMe Backup & Restore - Backup and restore operations now handle existing backup files correctly by using timestamped temporary directories, resolving “same file” errors that occurred when backup archives already existed on the target server. |
Potential failure of restore requests due to working directory management. |
Issue Number |
Description |
Details |
|---|---|---|
enhancement - License management user interface - migrating to native Splunk UI React |
The license management interface is now migrating in native React UI. |
|
feature - Rest Api Reference user interface - migrating this UI to a Splunk UI React Native user interface |
The Rest Api Reference dashboard is migrated to a React native user interface built on top of Splunk UI. |
|
feature - Maintenance Kdb UI transition to Splunk UI React native |
The Maintenance Kdb user interface has been converted to native Splunk UI React. |
|
feature - TrackMe Backup & Restore - Implement a function to allow deleting a specific target archive backup file |
This adds a target delete capability to the delete_backup endpoint, to delete a specific archive file (locally or remotely). This updates the Backup & Restore management user interface to allow calling this action. |
|
feature - Maintenance Mode user interface migration to Splunk UI native React |
The maintenance mode user interface has been migrated to a React native UI on top of Splunk UI. |
Version 2.1.32 - build 1759703239 (05/10/2025)¶
Hint
For Splunk 9.1.1 and later
From TrackMe 2.1.x, there is no more compatibility with Splunk 9.0.x and earlier.
The last release compatible with Splunk 9.0.x is TrackMe 2.0.99
SHA256: b970de58c208cf22512c41a5149723b5fde09c998ac390d91d0578117523c2de
Issue Number |
Description |
Details |
|---|---|---|
Feeds tracking - The adaptive delay backend does not preserve the value for future tolerance for the entities due to a bug in the underneath API endpoints logic |
When the adaptive delay does request an update of the delay value, the underneath API endpoints for dsm and dhm do not preserve properly the existing value for the future tolerance due to a flaw in its logic and especially for this field. |
|
Fields Quality Monitoring (splk-fqm) - searches underneath charts in fields overview screen should contain the context constraint to honor properly contexts with complex breakby |
In relatively complex scenarios where a single tracker generates more than a single context, the searches underneath charts do not honor properly the context, which leads to incorrect results and longer run time searches. |
|
Backup & Restore - The backup API export endpoint deletes the original backup archive after its export instead of preserving it on the search head file system |
The export endpoint unexpectedly removes the original backup archive from the search head file-system. Once hit, the endpoint should provide the content of the archive without altering the original file. |
|
TrackMe General Health Tracker - prevent licensing issue |
Prevent unexpected unbound reference in case of license endpoint failure. |
|
Potential failure of the custom command trackmetestremoteaccounts under some circumstances |
Some issues were identified in the code of this custom command which can lead to its failure under some circumstances. |
|
TrackMe Health Tracker - Prevent the task optimize_tenant_scheduled_reports from generating errors for replica tenants |
This task improperly attempts to verify reports for replica tenants, leading to the generation of error messages. |
|
Flex Objects (splk-flx) - duplicated log file handler trackme.flx.metrics leads a failure of the flx parse process when using metrics_list |
A duplicated log file handler leads to the failure of the Flex parsing if using metrics_list |
|
Disruption Queue - Prevents error messages in logs related to _key is missing from the disruption record due to a flaw in the assignment logic |
In some conditions, TrackMe might unexpectedly modify the original disruption record removing the _key from the record while attempting its update leading to a non-ending loop of error messages regarding the missing _key in the record. |
|
TrackMe log file handler - logic weakness can lead to a file handler unbound error |
A weakness in the Python logic for TrackMe log file handlers can result in error messages and failures to generate the expected content. |
|
TrackMe audit logger - prevent audit generation failure with bad character (49) in reply size |
This error leads to potential error messages with symptoms of bad character (49) in reply size due to different coding issues and weaknesses. |
|
TrackMe Backup & Restore - variable mismatch for restoring sample ratio for alerts |
A mismatch in the variable calls would impact restoring sample_ratio on alerts. |
|
TrackMe Backup & Restore - Fields Quality Monitoring has revealed some potential issues with non scheduled reports failing to be restored to a None value in the cron_schedule of the properties |
We have identified potential failures in restoring Fields Quality related objects due to an unexpected None value in the savesearch properties, that the function underneath attempted to load as a cron expression. |
|
Python logging - TrackMe loads various libs from the lib Python files, in some contexts the logging handler may not be set properly leading to silent logging |
This issue is limited to the logging performed directly in the functions stored in |
|
TrackMe Fields Quality - Minor glitch in the UI padding for dictionary management |
No padding has some unexpected side effects on the dictionary management screen. |
|
TrackMe custom command trackmetestremoteaccounts fails to render a consistent record when the remote account fails due to reachability, leading to the dashboard for remote account overview to be failing rendering the expected results |
If the account fails the connectivity test, it might not appear in the rendered results leading to the failure at rendering the results expected for the overview dashboard. |
|
Splunk SVC audit dashboard - not working single for Stack Average daily ingest (GB) |
The single view “Stack Average daily ingest (GB)” may fail to render results if slave is not defined. |
Issue Number |
Description |
Details |
|---|---|---|
Add a dedup capability in the show hybrid trackers REST API endpoints |
This enhancement adds dedup capabilities to the show hybrid trackers endpoints, to handle any non expected duplication of the records in the KVstore collection. |
|
Add an additional safety to prevent from generating any duplicated record in the hybrid KVstore collections |
This adds an additional safety to prevent any duplicate generation. |
|
Virtual Tenants - Check and fix tenant_id and component target API endpoint |
This feature adds a new endpoint which can be used to verify and create any missing knowledge object of a given Virtual Tenant and a target component. |
|
TrackMe REST API - Ensure each resource group for Virtual Tenants resources groups use their own handler class |
Python code improvement to ensure each REST API endpoint resource group refers to its own super class. |
|
Feeds tracking (splk-dsm/dhm) - Bulk Edit lagging policy improvement, separate each configuration item in its own bulk edit to avoid updating unwanted parameters for the lagging policy |
In the bulk edit function, the current behavior updates all parameters at once, but this might not be desirable in most of the cases as this will update all policy parameters. |
|
Bulk Edit - better alignment for the tags update action buttons |
Tags buttons should be better aligned in the bulk edit screen. |
|
Fields Quality (splk-fqm) - When using sampling mode, allows defining a custom value in addition with preset values from the sampling dropdown |
In Fields Quality, the user can select the sampling mode with a preset value for the events ratio, this enhancement allows choosing a custom value for the ratio straight from the wizard. This issue addressed some minor issues regarding the call of the function in charge of refreshing the summary view of the creation of the tracker, which was not calling the right function for non CIM context tracker creation. |
|
TrackMe Backup & Restore - Allows downloading a backup archive from the user interface via a simple download button |
This new feature allows TrackMe administrators to easily download any available backup archive file using the backup & restore user interface, in a simple click! |
|
TrackMe Backup & Restore - Automatically support Search Head Cluster context for the export archive API endpoint |
This enhancement allows the API export endpoint to automatically attempt to retrieve a requested backup archive from the member actually owning the archive file, providing native support for Search Head Cluster (SHC) contexts. |
|
TrackMe Backup & Restore - Allows importing (uploading) a TrackMe backup in the user interface |
This feature allows importing a backup archive in a simple click! |
|
TrackMe Backup & Restore - Always skip stateful charts collection from backup operations |
TrackMe stateful charts KVstore collections should always be excluded from backup operations. |
|
TrackMe packaging - prevents the generation of empty .conf files by the Splunk UCC |
TrackMe relies on the Splunk UCC framework for the application package generation. However, Splunk UCC generates empty files for expected Splunk config files such as tags.conf, which is unnecessary and can be removed from the final package. |
|
General Health Tracker - Adding a task to verify and purge KVstore records from the stateful charts collections after 48 hours (by default) |
Chart records in the stateful charts record collection are not useful for a long period of time, and should be safely purged automatically by TrackMe. |
|
TrackMe General Health Tracker - Adding the task virtual_tenants:auto-repair:components_reports |
This new task in the general health trackers identifies and fixes Virtual Tenants with missing component reports. |
|
Optimization and logging improvements of main key TrackMe backends components to reduce runtime and enhance logging for performance tracking |
These enhancements slightly optimize some of the key TrackMe backend components to reduce their runtime and improve logging and performance tracking. Runtime of trackers can be reduced by more than 50%. |
|
Fields Quality Monitoring (splk-fqm) - Implementing a configurable hard limit for sampling ratio |
This enhancement adds a built-in sample hard limit concept for FQM |
|
Fields Quality Monitoring (splk-fqm) - Improve the benchmark results by taking to account by custom break sequence in the results |
When using a custom break by sequence, this enhancement makes sure that the benchmark adapts the break by statement of the underneath search. |
|
Increasing default timeout value from 300 to 600 seconds in most of TrackMe REST operations |
In some use cases, very busy systems may take a longer time than expected to respond to REST calls leading to timeouts that do not necessarily translate into underlying issues, and that could be avoided with a more generous timeout value. |
|
TrackMe Stateful alerts - charts generation and therefore associated searches execution should only occur if email delivery ends up enabled for the given entity |
For optimization purposes, the stateful alert backend should only execute charts generation and associated searches execution only and only if email delivery ends up being enabled for a given entity. |
|
TrackMe Backup & Restore - Automatically support remote archive for the restore endpoint |
Similarly to the export endpoint, the restore endpoint can now automatically identify if the archive is hosted remotely and attempt to retrieve it automatically first by calling the export endpoint then processing the restore request. |
|
TrackMe Backup & Restore - When discovering an unknown backup archive locally available, set the server_name field to the local server name instead of the original metadata one |
When TrackMe discovers an archive, which happens either if the archive is unknown or during an import, we should update the server_name of the KVstore record with the local server name instead of the metadata. |
|
Splunk Cloud SVC - Splunk has transitioned some time ago to a new source which provides more accuracy and completeness |
Splunk Cloud has migrated to a new source for SVC consumption (source=splunk-svc-search-attribution) which we should rather use for the different SVC related materials in TrackMe. This change will automatically update any underneath existing Workload or Flex Object trackers. |
|
TrackMe Backup & Restore - purge on retention behavior, handle remote counterparts in SHC context, extend default retention to 30 days |
Extend the default retention from 7 to 30 days. Handle capability to deal with remote counterparts. |
|
TrackMe Backup & Restore - New Splunk UI React native user interface for management of Backup & Restore in TrackMe |
This feature marks a significant step in TrackMe with the first ever Splunk UI React native UI, and brings a brand new sophisticated user interface for backup & restore management in TrackMe, built on top of Splunk UI in native React. |
Version 2.1.31 - build 1758668980 (23/09/2025)¶
Hint
For Splunk 9.1.1 and later
From TrackMe 2.1.x, there is no more compatibility with Splunk 9.0.x and earlier.
The last release compatible with Splunk 9.0.x is TrackMe 2.0.99
SHA256: 2fe51a9696419e90d0e4c53c35d74cb1a044444c7663b9d1dcf5a4dd53714950
Issue Number |
Description |
Details |
|---|---|---|
Tenant Health Tracker wrongly re-enabled |
Fixes a bug where the general Health Tracker re-enabled tenant-specific health trackers even when the corresponding Virtual Tenant was disabled. |
|
Incorrect command mapping for FQM inspector |
The trackmesplkfqminactiveinspector custom command was mistakenly targeting the Flex component instead of Fields Quality Monitoring (splk-fqm). |
|
Health Tracker task failure on entities_auto_disablement |
Improves error resilience of the inspect_collection:entities_auto_disablement task and prevents incorrect assignment of virtual accounts during its execution. |
Issue Number |
Description |
Details |
|---|---|---|
Drilldown search support for Flex Objects |
Introduces drilldown search capability for Flex trackers. Drilldowns can be configured per tracker and support both local and remote accounts. A new UI button opens the drilldown search in Splunk directly. |
|
Remove unused unit test archive |
Removes the deprecated unit_tests_disabled directory from release packaging. |
|
Normalize Python dependency loading |
Standardizes all Python backend modules to use the centralized import_declare_test loader for OS/Python compatibility. Fixes minor typos in library files. |
|
Improve HEC error tracking use case in Flex |
Enhances the default HEC tracking use case with a default drilldown search and corrects time alignment by using the original _time. |
|
Default metric selection in Flex entity screen |
Adds support for configuring a default metric to be pre-selected when opening the entity modal. Controlled via the default_metric field in tracker settings or UI. |
|
Update OOTB Flex use cases with default metric |
Updates built-in Flex use cases to utilize the default metric selection when relevant for improved user experience. |
Version 2.1.30 - build 1758113820 (17/09/2025)¶
Hint
For Splunk 9.1.1 and later
From TrackMe 2.1.x, there is no more compatibility with Splunk 9.0.x and earlier.
The last release compatible with Splunk 9.0.x is TrackMe 2.0.99
SHA256: 81a7446c680a27c7da21a889ec03bbdcc1cdc60126e09db7bcf95c71b32a0eb6
Issue Number |
Description |
Details |
|---|---|---|
Hybrid trackers UI shows duplicate entries |
Fixes a regression introduced in #1210, where the Health Tracker task to patch missing hybrid tracker entries caused visual duplication in the Hybrid Trackers UI, although no actual duplication of reports occurred. |
Issue Number |
Description |
Details |
|---|---|---|
Tenant-level override of CMDB lookup settings |
Introduces the ability to override global CMDB lookup search definitions at the Virtual Tenant level, allowing component-level customization per tenant. If no override is set, the global default applies. |
|
New SPL command trackmeyamlpath for YAML parsing |
Adds a new custom streaming search command that enables parsing of YAML-formatted data directly in SPL pipelines. Useful for dynamic extraction of YAML fields from logs and structured events. |
Version 2.1.29 - build 1757965912 (15/09/2025)¶
Hint
For Splunk 9.1.1 and later
From TrackMe 2.1.x, there is no more compatibility with Splunk 9.0.x and earlier.
The last release compatible with Splunk 9.0.x is TrackMe 2.0.99
SHA256: 60ffd192607ac2c7fc650e5c051f758d65905c5408d26b7f072b059de3c6974c
Issue Number |
Description |
Details |
|---|---|---|
Flex: status description not overridden when dynamic thresholds alert |
When dynamic thresholds are in alert, the status_description and status_description_short fields are now properly overridden to avoid conflicting messages from the search logic. |
Issue Number |
Description |
Details |
|---|---|---|
UI layout optimization for high-resolution displays |
Enhances layout scaling and chart height calculations for high-resolution screens, resolving visual compression issues where charts appeared too small relative to the screen space. |
|
Health Tracker: hybrid tracker KVstore verification |
Adds a new Health Tracker task to validate and patch missing hybrid tracker entries in the dedicated KVstore collection, ensuring consistency in tracker metadata. |
|
Flex HEC error tracking use case enhancements |
Updates the Flex HEC parser error tracking use case to use absolute time ranges and include explicit 0 values, improving clarity and data representation in charts. |
|
Deprecation of splk-cim component |
Removes the legacy splk-cim component from the Virtual Tenant creation UI as part of deprecation efforts. |
Version 2.1.28 - build 1757413356 (09/09/2025)¶
Hint
For Splunk 9.1.1 and later
From TrackMe 2.1.x, there is no more compatibility with Splunk 9.0.x and earlier.
The last release compatible with Splunk 9.0.x is TrackMe 2.0.99
SHA256: 444c16c01234b7787292c9a81f65907d655e2b999d22783384cf84a185db98ac
Issue Number |
Description |
Details |
|---|---|---|
Splunk Remote Deployments: bearer token validation step |
Adds an extra step during token rotation to validate connectivity using the new bearer token before updating a remote account. Addresses rare edge cases where a token appears valid but fails in use. |
|
Macro not applied in splk-fqm wrapper monitor reports |
The macro trackme_fqm_get_description_extended was not used in wrapper monitor jobs or simulation searches. This fix updates the schema upgrade to ensure it’s consistently applied. |
|
Optimize tenant scheduled reports task failure |
Addresses an edge case where missing required properties (e.g., earliest, latest, cron, time_window) prevent search enablement logic from executing properly in the Health Tracker. |
|
KVstore insert error for splitline workload data |
Fixes a rare condition in the Workload component where KVstore insertions for splitlines could fail unexpectedly. |
|
UI glitch in Run Tracker filter for some components |
Resolves visual misplacement issues with the tracker filter box introduced in earlier UI updates. |
|
Flex thresholds using zero interpreted as boolean |
Corrects threshold creation logic where 0 values could mistakenly be treated as boolean false, preventing proper threshold creation in use cases. |
Issue Number |
Description |
Details |
|---|---|---|
Backup compression upgraded to Zstandard (zstd) |
TrackMe backup archives now use .zst for faster compression/decompression at scale. Legacy .tgz format remains supported for backwards compatibility. |
|
Purge leftover uncompressed backup directories |
Adds a pre-check during backup operations to clean up any previously uncompressed backup directories that may have been left behind. |
|
Improved error handling in Backup & Restore |
Backup operations now continue despite certain errors, ensuring partial data loss doesn’t cause total backup failure. |
|
SLA breach event frequency changed from 24h to 7d |
The default value for sla_breaches_events_frequency has been increased from 24 hours to 7 days to reduce alert fatigue and align with typical SLA reporting cycles. |
|
Workload versioning: configurable SHA256 parameter selection |
Adds support for configuring which search parameters (search, earliest, latest, etc.) contribute to version_id hashing. Wildcards are supported. Changes are logged with diff_<parameter> tracking. |
|
Workload versioning defaults improved |
The default list of fields used for version hashing now includes cron, enablement, and schedule_enablement to capture more relevant changes. |
|
New Flex use case: Detect HEC parser errors |
Introduces a new Flex Object tracker designed to monitor for Splunk HEC parsing errors in indexed events, aiding troubleshooting and ingestion pipeline health. |
|
Fields Quality Monitoring: default to head mode |
Changes the default data collection mode to head rather than sampling, as it is simpler to manage in most environments despite the latter being more powerful. |
|
Workload ML Outliers disabled by default |
Machine Learning Outlier detection is now disabled by default during Virtual Tenant creation for Workload, as it provides limited value in this context. |
Version 2.1.27 - build 1756708723 (01/09/2025)¶
Hint
For Splunk 9.1.1 and later
From TrackMe 2.1.x, there is no more compatibility with Splunk 9.0.x and earlier.
The last release compatible with Splunk 9.0.x is TrackMe 2.0.99
SHA256: c7718c937bdc4f270e6e482e5b705962bea30009256a6aede264792e942ca2dd
Issue Number |
Description |
Details |
|---|---|---|
Schema upgrade blocked by stale tracker references |
If trackers were manually deleted outside of TrackMe, schema upgrades (e.g. from 2.1.11) may fail due to stale references in TrackMe’s central collections. This update ensures these orphaned references are handled gracefully. |
|
dispatch.sample_ratio not properly backed up |
TrackMe’s backup process did not include the dispatch.sample_ratio property, which is required to restore certain Fields Quality Monitoring reports using Splunk sampling. The property is now correctly backed up and restored. |
|
Simulation view fails for non-CIM contexts |
A regression affecting single-panel views in simulation mode for non-CIM contexts in Fields Quality Monitoring (splk-fqm) has been fixed. The issue was caused by incorrect default metadata definitions. |
Issue Number |
Description |
Details |
|---|---|---|
Exclude stateful chart records from backup restore |
Records from stateful charts collections are now excluded from restore operations to avoid unnecessary error messages. These are temporary records and do not require restoration. |
|
Improved Virtual Tenant status handling in UI |
Introduces a new PENDING status to better reflect the readiness of a tenant. Also improves the logic for clearing tenant statuses to avoid delays caused by automatic health tracker runs. |
|
Filter input for tracker selection in Home UI |
Adds a filter box to the tracker selection dropdown in the Run Tracker screen, improving usability especially during Fields Monitoring workflows. |
|
Disable SmartStatus alert action by default |
SmartStatus alert actions are now disabled by default for legacy alerting definitions, avoiding unintended alert behavior. |
|
Support for phase 2-only Fields Quality collect jobs |
Enables users to create collect jobs in Fields Quality Monitoring that skip phase 1 and only perform phase 2. This is useful when reusing previously collected quality events to produce alternate aggregations or views without redundant collection. |
Version 2.1.26 - build 1756360749 (28/08/2025)¶
Hint
For Splunk 9.1.1 and later
From TrackMe 2.1.x, there is no more compatibility with Splunk 9.0.x and earlier.
The last release compatible with Splunk 9.0.x is TrackMe 2.0.99
SHA256: 0c5080e7cf19f45176cd916fe0f62601c75ee8c54b047f86bf34ece2d8edef7f
Issue Number |
Description |
Details |
|---|---|---|
Invalid search syntax in health tracker task virtual_tenants:stateful_alerts_duplicate_opened_incidents_cleanup |
The scheduled task responsible for identifying and closing duplicate opened incidents contained invalid SPL syntax, preventing execution. |
|
splk-fqm performance issues in distributed environments |
Simulation and execution searches in Quality Monitoring (splk-fqm) were experiencing abnormally long runtimes in distributed Splunk environments. This was caused by improper streaming command behavior. The issue was resolved by explicitly forcing result sorting to ensure processing happens on the search head. |
|
splk-fqm custom break-by fields not honored |
Fields Quality Monitoring (splk-fqm) failed to respect user-defined custom break-by field configurations across simulations, global entity tracking, and internal logic. This update ensures consistent support throughout the system. |
|
backup and restore sample ratior not restored |
Fields Quality Monitoring (splk-fqm) introduced the usage of sample ratio, which is not currently supported by the restore functionality. This update ensures that the sample ratio is properly restored when restoring a backup. |
Issue Number |
Description |
Details |
|---|---|---|
Safety check for data_lag_alert_kpis.allow_adaptive_delay in decision logic |
Introduces validation for this configuration value, preventing misbehavior due to invalid macro definitions. |
|
Deduplication of stateful records at alert execution |
Adds logic to automatically detect and close duplicate stateful alert records that may occur due to race conditions. |
|
Null byte protection in Quality Monitoring |
Implements a search-time filter to prevent Python SDK errors caused by null bytes in Splunk events. |
|
Backoff retry for REST API config retrieval |
Adds automatic retry logic for REST calls that fetch configuration data with privilege escalation, improving reliability under heavy load. |
|
New REST API endpoint to update Virtual Tenant account parameters |
Adds a granular administrative endpoint to update individual tenant configuration fields without requiring access to the full Configuration UI. |
|
Improved schema upgrade backup handling |
Enhances backup initiation logging and timeout handling during schema upgrades in large environments to prevent false error reporting and reduce retry attempts. |
Version 2.1.25 - build 1756195621 (26/08/2025)¶
Hint
For Splunk 9.1.1 and later
From TrackMe 2.1.x, there is no more compatibility with Splunk 9.0.x and earlier.
The last release compatible with Splunk 9.0.x is TrackMe 2.0.99
SHA256: a526985fea753a44513214a98ae049115c65544fbd8497e7731a1f125b52f55c
Issue Number |
Description |
Details |
|---|---|---|
Non-ASCII characters in stateful alert email object names |
When the monitored object contains non-ASCII characters (e.g. accented letters), TrackMe ensures safe storage in KVstore using a hexadecimal representation. However, this encoding was leaking into email notifications, showing unreadable object names. This fix now properly decodes the object name when generating email notifications so that the human-readable name is restored. |
Issue Number |
Description |
Details |
|---|---|---|
Upgrade to latest Splunk UCC framework |
This release updates TrackMe to leverage the latest stable version of the Splunk Universal Configuration Console (UCC) framework. Previous breaking changes in UCC had prevented immediate adoption. This upgrade restores compatibility and enables new UCC capabilities moving forward. |
|
License expiration popup warning |
TrackMe now proactively warns users when the installed license (Enterprise, Unlimited, or Trial Edition) is about to expire. If fewer than 15 days remain, a modal popup is automatically displayed to alert administrators. |
|
Improve naming of merged index-level entities in feeds tracking (splk-dsm) |
This change improves the naming convention for merged entities that operate at the index level in feeds tracking. By using the |
|
Prevent non-ASCII object duplication in search-time extractions |
In Splunk, indexed fields containing non-ASCII characters can sometimes produce multiple values at search time (decoded and raw). This enhancement modifies the search-time field extraction logic to ensure only the decoded, user-friendly value is shown, improving consistency and usability. |
|
Chart auto-type detection for count metrics in stateful alerts |
For embedded charts in stateful alerting emails (splk-fqm, splk-flx, splk-wlk), if the metric name contains the word “count”, TrackMe will automatically switch the chart type to a bar chart for better visual representation of discrete quantities. |
Version 2.1.24 - build 1755187604 (14/08/2025)¶
Hint
For Splunk 9.1.1 and later
From TrackMe 2.1.x, there is no more compatibility with Splunk 9.0.x and earlier.
The last release compatible with Splunk 9.0.x is TrackMe 2.0.99
SHA256: 0937d0f5e94f94d31515ffae5c635971534b2a4ea22e11ab74cca219af7ce9ef
Issue Number |
Description |
Details |
|---|---|---|
Handle reserved fields in FQM dictionaries |
Fields Quality Monitoring (splk-fqm) previously did not correctly handle reserved fields such as event_id, metadata, and summary when they were included in a data dictionary. These fields are internally used by TrackMe and cannot be used as-is for auditing. This fix ensures any such reserved field is dynamically renamed with a orig_ prefix (e.g. orig_event_id) during processing, preventing conflicts and unexpected behavior. |
Issue Number |
Description |
Details |
|---|---|---|
Full support for non-CIM contexts in FQM |
This feature completes the support for non-CIM contexts in Fields Quality Monitoring (splk-fqm). While the backend was already capable of handling non-CIM data, this enhancement adds full UI integration and logic in TrackMe to allow users to manage and monitor fields quality across any type of data, not just CIM-compliant events. |
Version 2.1.23 - build 1754290192 (04/08/2025)¶
Hint
For Splunk 9.1.1 and later
From TrackMe 2.1.x, there is no more compatibility with Splunk 9.0.x and earlier.
The last release compatible with Splunk 9.0.x is TrackMe 2.0.99
SHA256: ee76ec6fadb1617bffa6c075a882ee7dca12c345b6ea5a58cd4f5c548290ba0a
Issue Number |
Description |
Details |
|---|---|---|
FQM global pie chart does not show failures |
In the Fields Quality Monitoring (splk-fqm) global entity view, the right-hand pie chart fails to display failed results due to a typo in the field name used to calculate the chart. |
|
FQM tenant status icon shows incorrect red cross |
In the Virtual Tenant UI for splk-fqm, the mouseover tooltip incorrectly shows a red cross indicating failure for the overall tenant status, despite the actual status being healthy. |
Issue Number |
Description |
Details |
|---|---|---|
Improved Test Regex filter in FQM dictionaries UI |
Enhances the “Test Regex” button in the dictionaries management screen by dynamically pre-setting the source filter according to the dictionary’s context, simplifying testing workflows. |
|
Drilldown support for pie charts in FQM entity views |
Adds support for interactive pie chart drilldowns in both global and per-field entity views in Fields Quality Monitoring (splk-fqm). |
|
New shortcut to get non-matching events for FQM |
Introduces a shortcut button to directly access sampled events that do not match the dictionary regex, streamlining troubleshooting of data quality issues. |
|
Create empty dictionaries and UI improvements |
Adds the ability to create a brand new empty dictionary from the UI, along with various enhancements to improve the usability of the dictionary management interface. |
|
Bulk thresholds editing for FQM and Flex |
Introduces a bulk edit feature for threshold management, applicable to both Fields Quality Monitoring (splk-fqm) and Flex Objects (splk-flx), to speed up large-scale configuration changes. |
|
Enhanced status messages and per-category summary in FQM |
Adds dynamic, detailed status messages that reflect the outcome of each field inspection. Also introduces a per-category summary in the field quality results with absolute and percentage metrics, providing clearer insight into compliance across all checks. |
Version 2.1.22 - build 1753866030 (30/07/2025)¶
Hint
For Splunk 9.1.1 and later
From TrackMe 2.1.x, there is no more compatibility with Splunk 9.0.x and earlier.
The last release compatible with Splunk 9.0.x is TrackMe 2.0.99
SHA256: 091bf77bfae127dcc2b926c29681a3e707d9e8a62e7ac9a4b013a500f6934ab1
Issue Number |
Description |
Details |
|---|---|---|
New Component: Fields Quality (splk-fqm) |
Introduces a brand new component for CIM and non-CIM fields quality monitoring in Splunk and TrackMe. Based on the work described in the white paper (https://docs.trackme-solutions.com/latest/white_paper_fields_quality.html), it provides a scalable and mature workflow for continuous fields quality monitoring with a major focus on CIM contexts. Create jobs in a couple of clicks and get multi-dimensional entities instantly. |
Issue Number |
Description |
Details |
|---|---|---|
Flex Object CMDB icon broken |
The CMDB link icon stopped working for Flex Objects due to a regression introduced when UI-driven thresholds were added for Flex. |
|
Stateful alerts email account listing fails in Splunk Web |
The Splunk REST query used to populate the email account dropdown in Splunk Web (after alert creation) was invalid, causing the dropdown to fail. |
|
SmartStatus compatibility issue with Splunk 9.1/9.2 |
Updated sparkline library caused SmartStatus to fail in Splunk 9.1/9.2 due to Python 3.7.x incompatibility. |
Issue Number |
Description |
Details |
|---|---|---|
New streaming command: trackmeexpandtokens |
Adds a streaming command designed to expand tokens in a streaming manner, primarily for stateful alerting active commands. |
|
Stateful alerting improved token replacement |
Enhances active commands token replacement logic by leveraging the newly introduced trackmeexpandtokens command. |
|
REST API empty string fallback |
Ensures TrackMe-level options render as empty strings if null to prevent issues with the latest Splunk UCC release. |
|
Stateful alert creation wizard validation |
Prevents users from creating stateful alerts unless mandatory inputs (e.g., email recipients) are provided, improving usability and reducing API errors. |
|
Consistent import_declare_test usage |
All TrackMe REST API endpoints now use import_declare_test for consistent Python library loading and improved control. |
|
Flex Objects subgroup support |
Adds support for defining subgroup values in Flex trackers, enabling multi-dimensional grouping in Tabulator views. |
|
Stateful alerting latest priority retrieval |
Enhances stateful alerting to always retrieve and consider the latest priority value from the tenant KVstore collection before upstream results. |
Version 2.1.21 - build 1752477750 (14/07/2025)¶
Hint
For Splunk 9.1.1 and later
From TrackMe 2.1.x, there is no more compatibility with Splunk 9.0.x and earlier.
The last release compatible with Splunk 9.0.x is TrackMe 2.0.99
SHA256: 0d10f8440707aa1939d20cbc95995f58d753b5412c4a7de47854f3d38a454077
Issue Number |
Description |
Details |
|---|---|---|
Flex Object (splk-flx) mvfind matches substrings |
Fixes a logic error in the mvfind function used in SPL for Flex Object CIM compliance. The previous implementation matched substrings, which caused inconsistent summary status values. Now matches only exact strings. |
|
Flex Object simulation fails if object field is missing |
Ensures the object field is present in Flex simulations. If the field is missing, the parser sets status to 1 instead of raising a Python exception. |
|
Stateful alerting fails on Python 3.7 (Splunk 9.2.x) |
Resolves Python compatibility issues in stateful alerting caused by OS-dependent libraries missing support for Python 3.7 in Splunk 9.2.x. |
Issue Number |
Description |
Details |
|---|---|---|
New “pending” priority level |
Adds a new “pending” priority level to support qualification workflows, enabling entities to be flagged for review before being included in alerting. |
|
Alert macro usage update |
Ensures alerts use the updated macro trackme_apply_maintenance_mode_v2 for improved behavior. |
|
Maintenance macro matching safety |
Prevents incorrect tenant ID matches due to substring logic in macros, improving reliability of maintenance targeting. |
|
Maintenance timezone safety |
Improves handling of timezone conversion when the user’s profile does not explicitly define a timezone and operates outside UTC. |
|
Schema upgrade robustness |
Ensures upgrades can continue safely even if conflicting objects exist from prior rollbacks or restores. |
|
Fields quality - Render regex per field |
Improves backend and UI to track and display the regex expression applied per field in field quality analysis. |
|
Flex Object thresholds - Compare against metrics |
Allows threshold logic to reference another metric in the same record rather than being limited to static numbers. |
|
Stateful alert - Custom chart time range |
Adds support for customizing the time range used to generate embedded charts in stateful alert emails. |
|
Stateful alert - Cooldown between alerts |
Prevents creation or updates of incidents within 60 minutes of the last opened alert to avoid premature or duplicate detections. |
|
General Health Tracker - Cleanup duplicates |
Adds logic to automatically detect and remove duplicated open incidents from the stateful KVstore collection. |
|
Fields Quality - Accept null or empty fields |
Allows the field dictionary to accept empty or null field values and override regex failures using accept_unknown or accept_empty. |
Version 2.1.20 - build 1751374209 (01/07/2025)¶
Hint
For Splunk 9.1.1 and later
From TrackMe 2.1.x, there is no more compatibility with Splunk 9.0.x and earlier.
The last release compatible with Splunk 9.0.x is TrackMe 2.0.99
SHA256: f054ff962fac174aba5ecd6efdaf080247f8cdc9225bd3b0a95582b0027146dd
Issue Number |
Description |
Details |
|---|---|---|
Elastic Source tracker disabled by mistake |
A hotfix regression affected Elastic Sources where the health tracker optimization maintenance task incorrectly disabled the shared elastic source tracker even when entities still required management. This release restores correct tracker enablement logic. |
Version 2.1.19 - build 1751273959 (30/06/2025)¶
Hint
For Splunk 9.1.1 and later
From TrackMe 2.1.x, there is no more compatibility with Splunk 9.0.x and earlier.
The last release compatible with Splunk 9.0.x is TrackMe 2.0.99
SHA256: fd492b3d6fd7a1271ac6069baf0c9f5106d6199fdb25ce4095b993ee23a01a1e
Issue Number |
Description |
Details |
|---|---|---|
Non existing custom command reference |
A non-existing custom command (trackmesendemail) was referenced in commands.conf, potentially leading to Splunk warnings or appinspect failures. Removed for compliance and clarity. |
|
Configuration screen rejects advanced group by |
Regex validation in Virtual Tenant configuration prevented eval or non-CSV group by options, limiting Tabulator flexibility. Validation logic is now adapted. |
|
Regex validation and default value issues |
Fixes logic errors in regex validators and corrects invalid default values to ensure robust configuration parsing. |
|
SmartStatus future tolerance extraction bug |
Host and source extractions failed due to incorrect retrieval of future_tolerance values. Now resolved for reliable extractions in DSM/DHM. |
|
UI freezes on large search source code |
Show Trackers view loaded entire SPL source, which could freeze the browser with large searches. Optimized for performance stability. |
|
Email formatting inconsistencies |
Remaining formatting issues in some email clients, notably Outlook, resolved by simplifying HTML div structures. |
|
Embedded chart compatibility in emails |
Replaces SVG with PNG in alert emails to ensure full compatibility with all clients (Outlook, Gmail, etc.), along with supporting code enhancements. |
|
Outliers chart UI glitch |
Deleting and re-creating ML models broke the main outlier chart until full UI reload. Fixed to restore seamless chart rendering. |
|
Flex status metric mismatch |
Under some threshold breach conditions, the status metric did not reflect the decision maker logic. Now moved generation to trackmedecisionmaker for consistency. |
|
Incorrect component registration in Disruption |
Invalid component sent to registration function caused harmless log errors. Now corrected to send the proper component. |
|
Ack tracker anomaly reason comparison bug |
Under specific conditions, Ack could release prematurely due to incorrect comparison logic. Normalization now ensures accuracy. |
|
Role concurrency exception handling in SDK search |
run_splunk_search did not handle role concurrency limits gracefully. Now improved to detect and retry accordingly. |
|
Event field wrongly indexed as metadata |
trackme_events_ingest_evals and trackme_audit_events_ingest_evals transforms caused event fields to be indexed as metadata, creating warnings due to length. This is now prevented. |
Issue Number |
Description |
Details |
|---|---|---|
Incremental schema upgrades |
The schema upgrade process now updates the version incrementally after each function completes, improving resilience against upgrade interruptions. |
|
Prevent concurrent backups post-upgrade |
Health trackers now detect in-progress backups from logs rather than KVstore, preventing simultaneous backups during upgrades. |
|
More embedded charts in alerting |
Adds incident, flipping, and state charts as embedded visuals in StateFul alerting emails, enhancing diagnostic clarity. |
|
Persistent charts across alert phases |
Ensures ML Outliers and related charts are included consistently in opened, updated, and closure phases for continuity. |
|
Outliers exclusion periods apply to all models |
Period exclusions can now be applied to all ML models for an entity simultaneously via UI bulk actions. |
|
Background ML bulk actions |
mlmonitor and mltrain bulk operations now execute asynchronously (fire-and-forget), avoiding UI timeout issues. |
|
Status metrics for inactive Flex entities |
Flex objects now generate status metrics via inactive trackers with associated handler events for accurate lifecycle tracking. |
|
Automated utility scheduling |
TrackMe utilities (e.g., mltrain/mlmonitor) schedules are automatically enabled/disabled based on operational need, reducing workload. |
|
Health tracker self-monitoring |
Adds maintenance task to verify Virtual Tenant Health Tracker is active, ensuring core functionality is never unintentionally disabled. |
|
Hide cron schedule in Alerts UI |
The cron schedule field is now hidden from alert creation UI to prevent misconfiguration by untrained users. |
|
Simplified StateFul alert creation |
Provides granular priority-based actions for notifications and commands, streamlining the StateFul alert setup workflow. |
|
Improved search backoff strategy |
run_splunk_search now uses progressive backoff for retries, improving reliability on systems with concurrency limits. |
|
Fields Quality major enhancements |
Introduces three new SPL utilities (trackmefieldsqualityextract, trackmefieldsqualitygensummary, trackmefieldsqualitygendict) and a full rewrite of the Flex Object OOTB use case for CIM compliance and continuous monitoring. |
Version 2.1.18 - build 1748377090 (27/05/2025)¶
Hint
For Splunk 9.1.1 and later
From TrackMe 2.1.x, there is no more compatibility with Splunk 9.0.x and earlier.
The last release compatible with Splunk 9.0.x is TrackMe 2.0.99
SHA256: 6aab45bc762ea66ca4f06f961efdc2244a52c31c511dff5b70fbba7090602c05
Issue Number |
Description |
Details |
|---|---|---|
Tabulator group state not preserved |
Resolves improper group state reset on manual or auto refresh in TrackMe UI Tabulator. |
|
DHM metrics incorrect for multi-sourcetypes |
Fixes macro logic to account for all sourcetypes on volume calculations in splk-dhm. |
|
email_send_update_if_ack_active not respected |
Ensures updates are emailed if entity is acknowledged and flag is enabled. |
|
Unbalanced quotes in splk-mhm |
Fixes tracker regression from 2.1.16 affecting hybrid creation. |
|
Email chart uses min instead of max |
Status now reflects highest state instead of lowest. |
|
Outlook formatting issues in emails |
Enhances HTML for Outlook client compatibility. |
|
Virtual Tenant creation fails with limited permissions |
Applies proper privilege elevation in REST headers. |
|
StateFul alerts not restored |
Includes StateFul alerts in backup and restore processes. |
|
Scoped restore affects unrelated KV collections |
Filters collections by tenant during scoped restore. |
|
Restore fails on Splunk email actions |
Excludes native Splunk email settings to prevent restore failures. |
|
Drilldown uses API v1 instead of v2 |
Corrects dashboard links to target REST API v2. |
|
Outliers default latest time not applied |
Updates trackme-settings.conf to use -1d as default. |
|
ML charts fail with past latest_time |
Fixes chart simulation to support historic latest values. |
|
No UI refresh after Flex logical group edit |
Automatically refreshes status views post group changes. |
|
Missing event_id for inactive objects |
Ensures summary events include event_id for red-state entities. |
|
Full-down service shows orange |
Adjusts status logic to show red (status=2) if all members are down. |
|
State event error in splk-cim |
Resolves outlier-based Python error in CIM component. |
|
Ack expires on empty anomaly list |
Prevents misinterpretation of empty lists as state changes. |
|
Tracker fails if tags_manual is native list |
Adds type safety to ensure tags_manual is always a string. |
|
Blue state considered down |
Treats object_state=blue as up for Flex convergence logic. |
|
Missing mvexpand for email accounts |
Ensures all delivery options are listed in UI popup. |
|
Tag audit records include full entity |
Fixes audit trail to log tag list only, not entire object. |
Issue Number |
Description |
Details |
|---|---|---|
Load tenants if one is corrupted |
Backend resilience added to avoid full failure on partial tenant corruption. |
|
Skip disabled entities in convergence |
Default behavior now excludes monitored_state=”disabled” from convergence. |
|
Right-click popup improvements |
Enhances readability of contextual entity view. |
|
Add converging_status to extras |
Adds up/down visibility in extra_attributes. |
|
Auto-Ack config in wizard |
Enables toggling Auto-Ack at creation time for StateFul alerts. |
|
Prevent new alert if Ack is active |
Updates only if Ack exists, avoids duplicate threads. |
|
Render gaps in alert charts |
Gaps now rendered instead of misleading zeroes. |
|
Allow closure within 5 mins |
Prevents suppression of incident closure events. |
|
Accept threshold in seconds or units |
Enhances threshold entry with unit suffix support (h/d/w). |
|
Fetch tracker definition live |
UI now pulls real-time definition to avoid outdated data confusion. |
|
New Studio dashboard template |
Adds OOTB Dashboard Studio template for service health. |
|
Support JSON dict parsing |
Allows trackmefieldsquality to extract structured fields. |
|
Minimum percentage up for green |
Convergence logic now accepts minimum healthy percentage threshold. |
|
Alert status in email header |
Visually tags alerts as critical/informational with color code. |
|
Retry on restore failure |
Adds fallback retry if dependency isn’t restored yet. |
|
Filter API by keys |
Accepts comma-separated object keys for component data. |
|
UI/URL filter by keyid |
Adds keyid param support for safer drilldown with special chars. |
|
Use keyid in alert drilldown links |
Avoids URL errors for non-ASCII object names. |
|
Configurable thresholds per entity |
Flex tracker and UI support for per-entity metric thresholds. |
|
Pre-checks before Ack call |
Ensures entity is alerting before REST-based Ack. |
|
Larger chart height in Flex UI |
Defaults to 450px for improved visual clarity. |
|
List down entities first |
Prioritizes down entities in status descriptions. |
|
Prism.js for JSON formatting |
Syntax highlights JSON in entity popups. |
|
Skip disabled entity in alerting |
Ignores processing for disabled entities in StateFul alerting. |
|
Priority selector in flip UI |
Adds dropdown in status flipper for setting entity priority. |
|
Disruption Queue feature |
Introduces time-based disruption tracking before turning entities red. |
|
Improve audit search consistency |
Enhances uniformity of audit tab searches across components. |
|
Update OOTB use cases |
Leverages new thresholds and disruption logic in bundled Flex trackers. |
|
Push expected data from CMDB |
Adds trackmepushdatasource to create entities from referentials. |
|
Improve tenant wizard preview |
Enhances UX with embedded table preview in creation flow. |
|
Disable SLA events if frequency=0 |
Skips SLA breaches generation for disabled or configured tenants. |
|
Suppress entity list in all-green |
Avoids listing all entities if they’re all up. |
|
Improve corrupted tenant error UI |
Adds friendly remediation steps for tenant load failures. |
|
Check for orphan/outdated incidents |
New health tracker task verifies alert integrity. |
|
Remove deprecated health task |
synchronize_trackers_attr task removed as obsolete. |
Version 2.1.17 - build 1746041932 (30/04/2025)¶
Hint
For Splunk 9.1.1 and later
From TrackMe 2.1.x, there is no more compatibility with Splunk 9.0.x and earlier.
The last release compatible with Splunk 9.0.x is TrackMe 2.0.99
SHA256: bbc6cb524f5e4d93d70f5c9f003408f8a8b6d9a0231919ba3e966abafc1ab5a3
Issue Number |
Issue Description |
Issue Details |
|---|---|---|
Appinspect - prohibited characters in sourcetypes |
A newly introduced Appinspect check |
Issue Number |
Enhancement Description |
Enhancement Details |
|---|---|---|
New streaming command |
Adds a new TrackMe custom command designed to support fields quality auditing in Splunk environments. |
|
SmartStatus - improve search for data in the future |
Extends the future/past time range in the UC logic to capture events where timestamps are more than 4 hours ahead, preventing search failures. |
|
Upgrade Tabulator JS library |
Upgrades the embedded Tabulator JavaScript library to version 6.3.1. |
|
Health Tracker - new task |
Introduces a new health task to automatically verify and fix missing index declarations in tenant configurations, which could otherwise lead to errors during event generation. |
Version 2.1.16 - build 1745791632 (27/04/2025)¶
Hint
For Splunk 9.1.1 and later
From TrackMe 2.1.x, there is no more compatibility with Splunk 9.0.x and earlier.
The last release compatible with Splunk 9.0.x is TrackMe 2.0.99
SHA256: 9f31ae61532da1b343e6ff1dcc5734c33e3dce61972809c5ce2dd4bd54715f9c
Issue Number |
Issue Description |
Issue Details |
|---|---|---|
TrackMe sub-logging regression |
TrackMe 2.1.15 caused regressions in logging subsystems, resulting in missed ingestion of audit events, handler events, and others. This release fixes all associated logging issues. |
|
TrackMe Home UI - SLA theme color issue |
In the SLA tab, if the SLA is breached, the message should display in red theme. This was not happening properly in some use cases and is now corrected. |
Issue Number |
Enhancement Description |
Enhancement Details |
|---|---|---|
StateFul Alerting - Execute commands based on incident state |
Introduces active commands triggered when incidents are opened, updated, or closed, enabling state-aware integration with third-party systems (e.g., ServiceNow). See documentation. |
|
SOAR Monitoring - Page size control and recent window logic |
Enhances the |
|
Audit & Troubleshoot - Splunk Remote Accounts dashboard |
Provides a new dashboard to review the status of Splunk Remote Deployment accounts and monitor token rotation status via the new |
|
Flex Object Library - Search Head health check UC update |
Updates the Search Head health check use case to immediately trigger red status if the response is anything other than success. |
|
StateFul Alerting - Include trackme:state events for early trigger |
Incorporates |
|
StateFul Alerts - Control email updates when Acknowledged |
Adds a control option at the alert level to determine whether updated email notifications should be sent when the entity has an active Acknowledgement, improving alerting behavior. |
Version 2.1.15 - build 1745332184 (22/04/2025)¶
Hint
For Splunk 9.1.1 and later
From TrackMe 2.1.x, there is no more compatibility with Splunk 9.0.x and earlier.
The last release compatible with Splunk 9.0.x is TrackMe 2.0.99
SHA256: 6a3df5cfd71bfdd1f841c558f5db19c486c7a627716c8993cfb8dda1420b60bf
Issue Number |
Issue Description |
Issue Details |
|---|---|---|
Trackers and degraded mode - remote accounts regression |
A regression caused remote account-based trackers to remain in degraded mode even after the issue was resolved, preventing proper recovery after outages. |
Issue Number |
Enhancement Description |
Enhancement Details |
|---|---|---|
TrackMe REST API logging - prevent external collision |
Additional improvements were made to TrackMe’s REST API logging to ensure no logging collision occurs with other external applications in shared environments. |
|
StateFul Alerting - Alert wizard UI update |
Enhances the alert creation wizard to dynamically display or hide “Emails only” options based on the selected alert mode, improving clarity and user experience. |
Version 2.1.14 - build 1744885691 (17/04/2025)¶
Hint
For Splunk 9.1.1 and later
From TrackMe 2.1.x, there is no more compatibility with Splunk 9.0.x and earlier.
The last release compatible with Splunk 9.0.x is TrackMe 2.0.99
SHA256: 0087a889a3c25510a9a6a71c86f5b0c7f696d064ac3c17a24ca9ff6f25efeb89
Issue Number |
Issue Description |
Issue Details |
|---|---|---|
TrackMe logging - REST API potential logging conflicts |
In certain environments, TrackMe’s REST API logging lacked explicit handler definitions. This could result in logging conflicts where TrackMe logs contain unrelated external logs, or TrackMe logs are leaked into external logs. |
|
Hosts Tracking (splk-dhm) - regression in host-level latency/delay |
A regression introduced in version 2.1.11 prevented proper persistence and handling of host-level latency and delay thresholds in splk-dhm monitoring logic. |
Version 2.1.13 - build 1744663474 (14/04/2025)¶
Hint
For Splunk 9.1.1 and later
From TrackMe 2.1.x, there is no more compatibility with Splunk 9.0.x and earlier.
The last release compatible with Splunk 9.0.x is TrackMe 2.0.99
SHA256: 60a9959a9779c3f62420eec025368a156a46b78692209b57957714d99193da53
Issue Number |
Issue Description |
Issue Details |
|---|---|---|
StateFul Alerting - ingest only does not generate stateful events |
Due to a bug in the alert action, ingest-only mode does not function as intended and fails to generate stateful events. |
|
StateFul Alerting - Alias field is missing |
The alias field is not included in the stateful events, which may impact downstream logic or integration relying on this metadata. |
|
StateFul Alerting - local MTA triggers configuration exception |
Systems using a local MTA (mail transfer agent) for email delivery encountered an exception due to missing trackme_emails configuration. This update ensures the fallback to localhost config is handled properly. |
|
StateFul Alerting - configurable options for local MTA |
Added new system-level options in the General tab to support sender address and other configurations when using the localhost MTA for email delivery. |
Version 2.1.12 - build 1744327446 (11/04/2025)¶
Hint
For Splunk 9.1.1 and later
From TrackMe 2.1.x, there is no more compatibility with Splunk 9.0.x and earlier.
The last release compatible with Splunk 9.0.x is TrackMe 2.0.99
SHA256: 16eb3f5bc532b09860006c3faf7741939a8ae1d3680095e749e4d3d15368b269
Issue Number |
Issue Description |
Issue Details |
|---|---|---|
StateFul Alerting - Splunk 9.1/9.2 Python 3.7 compatibility |
StateFul Alerting introduced in 2.1.11 fails in Splunk 9.1.x and 9.2.x due to import errors caused by Python 3.7. This fix ensures the StateFul feature no longer crashes and gracefully disables embedded charts if Pygal cannot be loaded. Note: Emails charts are not available in Splunk 9.1/9.2 environments. |
Version 2.1.11 - build 1744200878 (09/04/2025)¶
Hint
For Splunk 9.1.1 and later
From TrackMe 2.1.x, there is no more compatibility with Splunk 9.0.x and earlier.
The last release compatible with Splunk 9.0.x is TrackMe 2.0.99
SHA256: 0122ea5cd0ed73a17562f24a12cb3c8808a75501d7021d70b07c37bf8970494c
Issue Number |
Issue Description |
Issue Details |
|---|---|---|
Minor typos in config/help descriptions |
Fix various typos or grammatical issues in TrackMe. |
|
Audit Data Sampling dashboard token bug |
Hard coded value in a main search for the tenant_id token replacement. |
|
Schema upgrade fails if alerts were manually deleted |
Customers experienced issues upgrading to 2.1.10 if alerts were manually deleted. |
|
Restore alert actions not re-enabled |
Issue in re-enabling alert actions due to improper “actions” formatting. |
|
SLA regex input issue |
UCC config doesn’t allow editing SLA classes due to regex validation bug. |
|
UI filters in Virtual Tenant view |
KO filtering breaks navigation when no results exist. |
|
SVC metrics now in _cmc_summary |
Splunk Cloud index change; update to TrackMe logic accordingly. |
|
Ack expiry bug for future_over_tolerance |
Incorrectly treated as anomaly reason change, prematurely expiring Acks. |
|
0d auto-disablement disables all entities |
Logic flaw disables all entities when 0d is defined. |
|
Transforms backup fails if admin renamed |
Hardcoded admin username in REST call macro. |
|
Flex group rename escaping issue |
Problem handling double quotes in remote contexts. |
|
Incorrect export for timeline viz |
Should be “none” instead of “app” in default.meta. |
|
Disabled ranges ignored in delayed entity inspector |
Setting range to 0 doesn’t disable it properly in backend. |
|
Default entity priority dropdown ignored |
Affects Flex/Workload/CIM Virtual Tenant creation. |
|
UC large lookup file inconsistent timeout |
max_sec_inactive is 1h while schedule is every 12h. |
|
ML Outliers only renders one model |
Bug prevents rendering of multiple models per entity. |
|
ML tab missing in splk-cim |
Outliers tab missing in UI even if ML is enabled. |
|
Adaptive delay causes config loss |
Auto-updates override non-delay settings like max latency. |
Issue Number |
Feature Description |
Feature Details |
|---|---|---|
Health Tracker alert consistency check |
New task to check for manually removed alerts and purge stale entries. |
|
Schema Upgrade resilience |
Prevents failure if alerts were removed outside of TrackMe. |
|
Handlers event notifications system |
Track handler actions and health status in a new tab per entity. |
|
Exclude KVstores from backups |
Backup exclusion list for KVstore collections. |
|
Exclude KVstore/KO from restores |
Restore blocklist for collections and knowledge objects. |
|
Logging deprecation fix |
Address deprecated log.setLevel usage. |
|
Virtual Tenant creation UI refresh |
CSS and label improvements. |
|
Modal UI enhancements |
Ensure all modals have a header close button. |
|
SOAR failure use case optimizations |
Performance improvements for high-scale environments. |
|
Prevent browser grammar on Flex inputs |
Disable grammar checking on code inputs. |
|
SOAR Broker status enhancements |
Status red triggered if not active. |
|
Tracker health consistency tasks |
Checks existence of trackers and KO references. |
|
Constraint inputs UI improvement |
Use textarea for better experience. |
|
Decision Maker message clarity |
Better status messages to reduce confusion. |
|
Alert modal UI refresh |
Simplified and improved per-alert modal design. |
|
Host thresholds precedence |
Host-level thresholds now override sourcetypes. |
|
Stateful alerting and email threading |
Full-featured incident lifecycle with HTML email and embedded charts. |
|
Sticky Acks default |
Sticky Ack now default based on user preference. |
|
SOAR concurrent playbooks tracking |
REST API and Flex tracker to monitor playbooks live. |
|
Info/SPL/success UI consistency |
Prevent UI messages from rendering off-screen. |
|
SLA breach event throttling |
Configurable generation frequency for SLA breach events. |
|
Virtual Tenant auto-repair |
Automatically detects and fixes upgrade failures. |
|
Update Splunk Remote Account URLs |
New admin API endpoint to update splunk_url. |
|
Improved rendering for search/inspector menus |
Better UI handling of embedded Splunk actions. |
|
Remote Search performance metrics |
Query each SH member, return response time and job count. |
|
Reduce frequency of delayed entity inspector |
Less frequent checks to reduce resource costs. |
Version 2.1.10 - build 1741820646 (12/03/2025)¶
Hint
For Splunk 9.1.1 and later
From TrackMe 2.1.x, there is no more compatibility with Splunk 9.0.x and earlier.
The last release compatible with Splunk 9.0.x is TrackMe 2.0.99
SHA256: 1503eff8cd5b8864a30ea9bc04c6518c2ac96d14508f192256cfc3be76fb0930
Issue Number |
Issue Description |
Issue Details |
|---|---|---|
UI Virtual Tenant - Remove Deprecated Color Option |
The color_theme_red_default option, replaced by color_theme_alert_default in 2.1.9, was still available and has now been removed. |
|
TrackMe Outliers Detection - ML Model Creation Failure |
Fixed an issue where new ML models could not be created if no previous models existed for an entity. |
|
TrackMe Outliers Detection - auto_correct Not Defined |
Resolved an issue where auto_correct was not being set when adding a new model for Flex Object trackers via the UI. |
|
TrackMe Health Tracker - Missing Tenant Account Handling |
Fixed an issue where the health tracker would not recreate missing Virtual Tenant accounts due to a missing force_create_missing parameter. |
|
TrackMe REST API - Incorrect tenant_default_priority Check |
Fixed an issue where tenant_default_priority was incorrectly validated as default_priority, causing API failures. |
|
Hybrid Trackers - Inconsistent time_window Scheduling |
Addressed inconsistencies in how TrackMe schedules time_window for hybrid trackers, ensuring uniform behavior. |
|
Virtual Tenant UI - Drag-and-Drop Issue |
Fixed a UI issue where dragging Virtual Tenant boxes did not work correctly when multiple rows were present. |
|
CIM Tracking - Exception Handling for ML Detection |
Fixed a Python assignment error that could occur when an ML anomaly was detected in CIM tracking. |
|
Data Sampling UI - relative_time_window_seconds Not Honored |
Fixed an issue where user-defined relative_time_window_seconds values were not being correctly applied in the UI. |
|
Data Sampling Backend - relative_time_window_seconds Not Applied |
Fixed an issue where the backend (trackmesamplingexecutor command) ignored user-defined relative_time_window_seconds. |
|
Remote Accounts - Token Rotation Failure |
Fixed a token rotation failure due to a hardcoded service account name in the REST API. |
|
CIM Compliance - Incorrect Outlier Field Count |
Fixed an issue where green and red field counts were not displayed correctly in the UI when ML Outliers were detected. |
|
ML Outliers - Training Failure When Deleting Old Models |
Resolved a failure in ML Outliers training where old models were not being properly deleted before retraining. |
|
ML Outliers - UI Chart Rendering Issue |
Fixed an issue where ML Outliers charts would not load unless the page was manually refreshed. |
|
Batch Priority Updates - Missing Action Field |
Ensured that generic_batch_update always includes an action field in responses for improved debugging. |
|
CIM Compliance - Duplicate JSON Download Requests |
Fixed an issue where downloading a CIM JSON configuration triggered duplicate requests. |
|
Virtual Tenants UI - Status Preview for Flex Objects |
Improved Flex Object preview to display status_description_short and allow right-click actions in the UI. |
|
Acknowledgment Tracker - Expiration Failure for Removed Components |
Fixed an issue where expired acknowledgments could not be processed for components that had been removed. |
|
Virtual Tenant Component Deletion - Associated Alerts Not Removed |
Ensured that when deleting a component, any associated alerts are also removed automatically. |
|
Python Backend - Improper Logging Restoration |
Fixed an issue where TrackMe’s Python metric generation libraries failed to restore proper logging in some conditions. |
|
jQuery Scan Failure in Splunk URA App |
Addressed a jQuery scan failure in Splunk URA caused by the deprecated Splunk-built timeline app. |
Issue Number |
Issue Description |
Issue Details |
|---|---|---|
Virtual Tenants and Home UI - Enhanced Look and Feel |
Improved TrackMe UI with modernized visuals and better handling of modal screens, especially for low-resolution contexts. |
|
Flex Objects - Group Renaming Capabilities |
Added ability to rename Flex Object groups, automatically updating associated trackers, migrating entities, and preserving historical metrics. |
|
REST API - Remove Unnecessary Logging for Global Index Settings |
Prevented unnecessary error messages when a Virtual Tenant uses “global” index settings, reducing redundant log entries. |
|
Data Sampling Dashboard Enhancements |
Improved out-of-the-box Data Sampling review dashboard for better usability and insights. |
|
Outliers Detection - Default kpi_span Control |
Introduced a system-wide option to define the default kpi_span value for newly created ML models. |
|
trackmegenjsonmetrics Command - Enhancements |
Improved command to support automatic recognition of numerical values and prefix-based modifications for better metric handling. |
|
Flex Objects UI - Pre-Filtering Entities in Metric Views |
Added a pre-filter text input to help users refine selections when adding entities to metric charts. |
|
Flex Object - Improved Splunk Cluster Global Status Use Case |
Enhanced the cluster monitoring use case to consider additional health factors such as replication, site factors, and active bucket fixing. |
|
Flex Object - Filter Valid OOTB Use Cases |
Ensured only valid out-of-the-box use cases are displayed, filtering out outdated or removed configurations. |
|
SOAR with Flex Objects - Refactored Playbook and Adhoc Error Detection |
Redesigned detection for SOAR playbook and adhoc failures, adding REST lookups to extract associated metadata. |
|
TrackMe Theming - Match Skipping/Degraded Colors |
Adjusted color scheme to ensure consistency with TrackMe’s global theming. |
|
ML Outliers Detection - Bulk Rule Updates |
Introduced a REST API endpoint for bulk updates to ML outlier detection rules, integrated into the UI. |
|
Flex Objects - Split License Usage Volume by Deployment Type |
Separated license usage tracking for Splunk Cloud and Splunk Enterprise due to differences in pool concepts. |
|
Priority Management - Identify Policy/External Control |
Added priority_reason field to clarify if an entity’s priority is controlled by policies or external sources. |
|
SOAR Integration - Prevent ES8 Conflict |
Renamed soar.py to avoid conflicts with embedded libraries in Splunk Enterprise Security 8. |
|
Enhanced Priority Management - Policy and External Overrides |
Improved UI messaging and per-entity override capabilities when policies or external systems manage priorities. |
|
Virtual Tenant - Control Machine Learning Activation |
Introduced mloutliers_allowlist parameter to selectively enable ML outlier detection per component. |
|
Virtual Tenants - Improved Creation UI |
Enhanced tenant creation UI with clearer labels and real-time feedback. |
|
Flex Objects - Converging Multi-Dimensional KPI |
Introduced a KPI pct_availability to aggregate multiple Flex entities into a single service availability metric. |
|
License Verification - Prevent Incorrect Actions on KVstore Failure |
Ensured TrackMe does not take license-related actions if a KVstore exception prevents verification. |
|
TrackMe Acknowledgements - Preselect ack_type |
Defaulted ack_type dropdown to match the existing acknowledgment record for an entity. |
|
UI Enhancements - Improved Legend Styling |
Adjusted legend design for better readability. |
|
Flex Objects - Deduplication for Metric Ingestion |
Added deduplication capabilities to prevent duplicate metrics by tracking the last seen epoch in KVstore. |
|
Flex Objects - Refactored Splunk Cloud SVC Consumption Use Cases |
Improved Splunk Cloud SVC tracking use cases, adding a dedicated use case for service consumers. |
|
Feeds Tracking - Adaptive Delay Enhancement |
Incorporated SLA percentage into Adaptive Delay logic to avoid threshold adjustments during outages. |
|
Flex Objects Library - Universal Forwarders Version Compliance Use Case |
Added a new use case to track the percentage of compliance for Splunk Universal Forwarder versions, leveraging a highly efficient tstats TERM search against internal and S2S TCP activity. |
|
Flex Objects Library - Update to splk_deployment_server_clients Use Case |
Minor enhancement and update to the Flex Object use case for tracking deployment clients. |
Version 2.1.9 - build 1738934449 (07/02/2025)¶
Hint
For Splunk 9.1.1 and later
From TrackMe 2.1.x, there is no more compatibility with Splunk 9.0.x and earlier.
The last release compatible with Splunk 9.0.x is TrackMe 2.0.99
SHA256: 85f83d14bb98010e9fe1f2f56989b4daf085a118367f587eae9522bf7bd03ac8
Issue Number |
Issue Description |
Issue Details |
|---|---|---|
Flex Object - Ensure status_description_short Always Has Value |
Fixed an issue where status_description_short could be empty under rare conditions, particularly when max_sec_inactive is 0 and the entity has not been handled by the inactive entities tracker. |
|
CIM Compliance Tracking - Flipping Event Generation Errors |
Fixed a Python error causing failures in generating flipping events under specific conditions. |
|
SOAR Tracking - Automation Brokers HA Issues with Large Asset Volumes |
Resolved REST API pagination issues that impacted SOAR Automation Brokers tracking and high availability features when a large number of assets were configured. |
Issue Number |
Issue Description |
Issue Details |
|---|---|---|
Flex Object/Workload - Allow Disabling Inactive Entity Purging |
Updated trackmesplkflxinactiveinspector and trackmesplkwlkinactiveinspector commands to allow 0 as a valid argument, disabling entity purging. |
|
Trackers - Inherit Earliest/Latest and Control Alert Behavior |
Removed the explicit need for earliest and latest arguments, allowing them to inherit from metadata variables unless specified. Introduced an argument to control whether an empty result set should impact Virtual Tenant operational status. |
|
Data Source Monitoring - Real-time Entity Status Refresh |
Enabled real-time updates to entity status for Data Sampling (splk-dsm). |
|
Health Tracker - Improved Logging and Performance |
Enhanced logging for trackme:health events, including ACL details and additional metadata. Improved performance using requests.session to reduce REST overhead. |
|
Hybrid Tracker Wizard - Clarify Optional Burn Benchmark Tasks |
Explicitly marked burn benchmark tasks as optional in the Hybrid Tracker creation wizard to reduce user confusion. |
|
Flex Objects - Multi-Entity Selection for Chart Generation |
Added support for selecting multiple entities within the same Virtual Tenant when generating charts for specific metrics. |
|
Flex Object Trackers - UI Enhancements with Single Stats Visualization |
Added single stat visualizations (Perc95, Max, Avg) to the Flex entity modal views for improved usability. |
|
Cribl Monitoring - Enhanced Status Descriptions |
Added status_description_short field to all Cribl monitoring use cases for improved user experience. |
|
Virtual Tenant UI - Improved Alert Visualization |
Updated the Virtual Tenant UI with an enhanced color scheme for better visualization of high and critical priority entities in alert states. |
|
Home UI - Modernized Alert Priorities Display |
Improved the TrackMe Home UI with a modernized look and feel for managing single views associated with alert priorities and alert counts. |
Version 2.1.8 - build 1738021014 (27/01/2025)¶
Hint
For Splunk 9.1.1 and later
From TrackMe 2.1.x, there is no more compatibility with Splunk 9.0.x and earlier.
The last release compatible with Splunk 9.0.x is TrackMe 2.0.99
SHA256: fb323b1bc0c529ffcb1342dbd6c0146d8f5b20e8fcbbbf7c06719801ef759f46
Issue Number |
Issue Description |
Issue Details |
|---|---|---|
Notable Events - Drilldown Link Ignores Custom Web Root Endpoint |
Fixed an issue where drilldown links in notable events did not preserve additional URL path parts when using a custom Splunk Web root endpoint. |
|
Home UI - Refresh Button Failure with Custom Splunk Web Root |
Fixed an issue where the refresh button failed due to an invalid REST endpoint definition when using a custom Splunk Web root endpoint. |
|
Audit System - Missing Tenant ID in Audit Events |
Resolved missing tenant_id values in some audit events, ensuring they are properly displayed in the entity audit tab. |
|
AppInspect Failure - Inline Comment Parsing Issue |
Addressed an issue where the AppInspect check check_collections_conf_for_specified_name_field_type incorrectly failed due to inline comments in configurations. |
|
Notable Alerts - Missing Tenant ID Filter |
Fixed an issue where notable alerts did not include tenant_id as a search filter, preventing cross-notable events in multi-tenant environments. |
|
Prevent splunkd Startup Error from Timeline Viz Integration |
Addressed splunkd startup error messages caused by missing README spec instructions in the timeline visualization integration. |
|
REST API - Missing Double Quotes in SPL Import/Export Examples |
Fixed missing double quotes in resource examples for SPL import/export. |
|
Tags Policies - Updating Policy ID Causes 404 Error |
Resolved an issue where updating the policy ID from the UI led to a 404 error due to incorrect KVstore record retrieval logic. |
|
SLA & Priority Policies - Policy ID Update Causes 404 |
Fixed a similar issue affecting SLA and Priority policy updates in the UI. |
|
Adaptive Delay Tracker - Default Search Time Issue |
Fixed an issue where the recent activity search in the Adaptive Delay Tracker unexpectedly ran over all time due to a missing earliest time argument. |
|
Workload (splk-wlk) - SmartStatus searches for errors tracking |
The generated search for errors (function smartstatus_investigations_uc_wlk_execution_errors) should not use indexed earliest and latest. |
|
TrackMe Dashboards - Errors loading TrackMe logo |
Fixed an issue where TrackMe dashboards failed to load the TrackMe logo due to incorrect path resolution. |
|
Week days monitoring - (all components except splk-dsm) - Week days monitoring by the day selection issues |
Different UI and API issues have been identified for all components, except splk-dsm. |
Issue Number |
Issue Description |
Issue Details |
|---|---|---|
Splunk SOAR - High Availability & Monitoring Enhancements |
Introduced a pool definition capability for automation brokers, improving flexibility over active/passive configurations. Decommissioned the monitor use case in favor of a unified Flex Object use case. |
|
Drilldown Links - Preset Time Range Support |
Added support for influencing preset time ranges in entity views via drilldown links. Allows relative time formats such as -24h or 24h. |
|
Notable Events - Per Alert Default Earliest Time |
Introduced a drilldown_earliest option for defining a per-alert default earliest time in notable event drilldowns. |
|
Timechart Span Definition Enhancements |
Introduced a new macro for automated span value definition in timechart calls, improving reliability over UI-based span determination. |
|
Outliers Detection - Default Latest Time Adjustment |
Changed the default latest value for ML training to -1d instead of now to prevent abnormal periods from affecting training. |
|
Outliers Detection - Handling Feed Interruptions |
Updated outliers detection for splk-dsm/dhm to generate 0 value metrics, ensuring feed interruptions are properly accounted for in detection processes. |
|
Flex Objects - Inactive State Management Improvements |
Improved inactive state detection, real-time status updates, and enhanced anomaly reasoning in splk-flx. |
|
Splunk Remote Account Management - Bearer Token Auto-Rotation |
Introduced automatic bearer token rotation for Splunk remote accounts. Configurable per account with a default rotation interval of 7 days. |
|
Flex Object use cases library - Splunk introspection CPU & Memory Monitoring |
Enhancement to these use cases with the definition of the status short description field. |
|
Flex Object use cases library - DataModel Acceleration Monitoring |
Enhancement to the use case the definition of the status short description field. |
|
TrackMe dashboards - Refresh for Dashboard Studio based dashboards |
Syntax and source code refresh for out of date dashboard studio based dashboards. |
Version 2.1.7 - build 1735907247 (03/01/2025)¶
Hint
For Splunk 9.1.1 and later
From TrackMe 2.1.x, there is no more compatibility with Splunk 9.1.0 and earlier.
The last release compatible with Splunk 9.0.x up to 9.1.0 is TrackMe 2.0.99
SHA256: 3fc504463e4270fd8142ad0bff0c32c46bf33fb329fa13b9d9a6e04f35cefa90
Issue Number |
Issue Description |
Issue Details |
|---|---|---|
Dependency App Issues - Timeline App EOL by Splunk |
The timeline visualization app has reached EOL as of December 24, 2024, and is no longer available on Splunk Base. TrackMe now incorporates these visualization components natively, removing the external dependency. |
Issue Number |
Issue Description |
Issue Details |
|---|---|---|
Flex Object Library - Update for Cluster Management Use Cases |
Updated Flex Object library use cases to replace legacy references to the Splunk master convention with modern terminology for cluster management. |
|
Bulk Edit Tags |
Introduced a bulk edit UI capability for managing manual tags efficiently. |
|
Flex Object Library - Deployment Server Clients Tracking Refactor |
Refactored the Splunk deployment server clients tracking use case to utilize the _ds* indexes introduced in Splunk 9.3.x for better tracking capabilities. |
|
Flex Object Trackers Library Enhancements |
Enhanced the Flex Object trackers library with additional attributes and improved status descriptions, including updates to: - splk_splunk_enterprise_cluster_status - splk_splunk_enterprise_cluster_peers_status |
|
Flex Object Trackers - Short Status Description Field |
Added a status_description_short field for displaying concise status descriptions in the main Tabulator table while maintaining a detailed status description for additional insights. The logic now automatically handles this new field if not present in existing configurations. |
Version 2.1.6 - build 1734273789 (15/12/2024)¶
Hint
For Splunk 9.1.1 and later
From TrackMe 2.1.x, there is no more compatibility with Splunk 9.1.0 and earlier.
The last release compatible with Splunk 9.0.x up to 9.1.0 is TrackMe 2.0.99
SHA256: b9236c33c34fcdfb948629de3007ce874380e20f9f63029a658fcffba7930715
Issue Number |
Issue Description |
Issue Details |
|---|---|---|
Knowledge Objects and Shortcuts Issues with Custom Splunk Web Root Endpoint |
Resolved issues accessing knowledge objects and built-in shortcuts when using a custom Splunk Web root endpoint. Fixed drilldown link generation for TrackMe technical alerts and addressed JS errors in license registration and maintenance knowledge database notifications. |
|
Maintenance Mode Enablement Fails via UI |
Fixed a regression in TrackMe 2.1.5 causing a 404 error when enabling maintenance mode through the UI. |
|
Backup & Restore Issues with Disabled Virtual Tenants |
Resolved exceptions during backup operations when disabled Virtual Tenants exist. The restore process now forces purging of disabled tenants to prevent loading issues. |
|
Remote Search - Default HTTPS Port Handling |
Improved handling of default HTTPS/443 port in remote Splunk REST API requests to avoid failures when the port is not explicitly provided in the URL. |
Version 2.1.5 - build 1734004063 (12/12/2024)¶
Hint
For Splunk 9.1.1 and later
From TrackMe 2.1.x, there is no more compatibility with Splunk 9.1.0 and earlier.
The last release compatible with Splunk 9.0.x up to 9.1.0 is TrackMe 2.0.99
SHA256: 2d3ccbe77a6929fc982f645378521fa56fff97a0d865b11642918f7c8c252eb4
Issue Number |
Issue Description |
Issue Details |
|---|---|---|
System Level Preferences Misconfiguration |
Home UI system level preferences were not properly applied, with Virtual Tenant UI preferences taking precedence. Fixed to honor distinct system level preferences for Home and Virtual Tenant UIs. |
|
Virtual Tenants - Scheduled Search Count Issue |
Show Knowledge Objects screen incorrectly displayed a count of 0 for scheduled searches due to misparsed is_scheduled field. |
|
Get Knowledge Objects - JSON Parsing Error |
The macro get_tenants_reports did not escape double quotes in macro definitions, leading to invalid JSON structures. |
|
Data Sampling Migration Issue |
Schema migration from TrackMe versions < 2.0.36 directly to 2.1.x failed for the Data Sampling Tracker. A workaround migration path is recommended until resolved in version 2.1.5. |
|
Schema Upgrade Errors |
Various errors during schema upgrade tasks (2084, 2064, 2099) resolved for migrations from TrackMe 2.0.x to 2.1.x. |
|
Alerts Creation - JSON Key Duplication |
Resolved an issue where duplicate keys were generated in JSON payload during alert creation. |
|
Data Sampling - Typo in Remediation Messages |
Fixed typos in Data Sampling remediation messages. |
|
FIPS Transition Issues |
Minor issues with SHA256 transition from MD5 in version_id metrics ingestion and flipping events identification for splk-wlk and splk-cim resolved. |
|
Flex Objects - Typo in Lookup Files Monitoring Use Case |
Corrected typo in JSON file name and use case name for large lookup files monitoring. |
|
Modular Alerts Logs - Timezone Issue |
Modular alerts logs now properly handle non-UTC timezone settings. |
|
Drilldown Error in Multi-Component Tenants |
Resolved drilldown activation error for components not first in the tab list. |
|
Splunk Web Custom Root Endpoint Issue |
Addressed compatibility issues with custom root endpoint configurations in web.conf. |
|
Workload Metadata Tracker - Minimal Privileges Issue |
Improved handling of minimal privilege accounts in metadata tracker operations for splk-wlk. |
Issue Number |
Issue Description |
Issue Details |
|---|---|---|
Splunk Python SDK Upgrade |
Upgraded to the latest Splunk Python SDK version 2.1.0. |
|
Splunk UCC Validator Warning Messages |
Ensured all UCC configurations include input validators to address warning messages introduced in UCC 5.52.0. |
|
Virtual Tenants Wizard - Custom Fields Enhancement |
Added missing hover action for custom field configurations in the Virtual Tenants wizard. |
|
Splunk UCC Upgrade to 5.53.0 |
Upgraded Splunk UCC to version 5.53.0. |
|
Configuration Management Enhancement |
Improved readability of TrackMe configuration screens by grouping configuration items using UCC 5.53.0 features. |
|
Backup & Restore Feature |
Introduced capabilities to backup and restore knowledge objects and KVstore content for Virtual Tenants and components. |
|
Virtual Tenant API Enhancements |
Improved input verification for tenant index settings to prevent misconfigurations. |
|
Flex Objects Tracker Name Simplification |
Removed |
|
Flex Objects Tracker Name Sanitization |
Enhanced sanitization for requested tracker names during simulation and creation. |
Version 2.1.4 - build 1731085887 (08/10/2024)¶
Hint
For Splunk 9.1.1 and later
From TrackMe 2.1.x, there is no more compatibility with Splunk 9.1.0 and earlier.
The last release compatible with Splunk 9.0.x up to 9.1.0 is TrackMe 2.0.99
SHA256: 46b4db465c4dafc67fdaffc534d629ad894a6ac47a67210d2eda7d508a427e9f
Issue Number |
Issue Description |
Issue Details |
|---|---|---|
Inline Bulk Edit - Adaptive Delay Persistence Issue |
The Adaptive delay setting, modified via inline bulk edit in the Tabulator, does not persist. This occurs due to the UI’s restricted persistent fields, missing Adaptive delay, which should rely on TrackMe’s Python library for centralized handling. |
|
Virtual Tenants - System Level Fallback Misconfiguration |
The fallback configuration for splk_feeds_auto_disablement_period fails if Virtual Tenant lacks the expected definition. Issue impacts auto disablement period settings for inactive entities. |
|
Flex Objects - Error in Inactive Entities Tracker |
Flex inactive entity tracking may fail if max_sec_inactive is undefined, caused by a Python code error when handling this missing value. |
|
Remote Search - Timeout Config Error |
Remote search failures occur due to timeout values received as strings instead of integers. This fix ensures timeout values are processed correctly as integers. |
|
Data Sampling - Remote Entities issues |
Data sampling issues with remote entities. This fix addresses various issues with Data Sampling v2 when entities are remote entities. |
Issue Number |
Issue Description |
Issue Details |
|---|---|---|
Tabulator - JS Upgrade to v6.3.0 |
Upgraded the Tabulator JS component to version 6.3.0 for improved functionality and performance. |
|
Splunk UCC Upgrade to 5.52.0 |
Updated Splunk UCC from version 5.48.2 to 5.52.0. |
|
Virtual Tenants UI - Usability Improvements |
Added quick access buttons for Scheduler and Ops Status, improved modal screens, and a more consistent layout with closing icons where needed. |
|
Flex/Workload Blocklist Extension |
Blocklist features extended to splk-flx/wlk components, adding flexibility to block specific patterns with a schema upgrade to initialize allowlist collections. |
|
Virtual Tenant Account Management Enhancement |
Implements a more secure approach for verifying and updating Virtual Tenant accounts, with auto-check and repair features through the Health Tracker. |
|
Flex Objects - Enhanced Cribl Logstream CPU Usage Detection |
Improved Cribl Logstream CPU consumption use case for fewer false positives and clearer alerts. |
|
Flex Objects - New Use Case for Dynamic Sourcetypes |
Introduces a new use case to detect and track dynamic sourcetypes in Splunk, optimizing log rotation handling. |
|
Data Sources Tracking - Hybrid Tracker Enhancements |
Allows inclusion/exclusion of sourcetypes during hybrid tracker creation for splk-dsm, adding control over custom break-by fields. |
Version 2.1.3 - build 1728629753 (11/10/2024)¶
Hint
For Splunk 9.1.1 and later
From TrackMe 2.1.x, there is no more compatibility with Splunk 9.1.0 and earlier.
The last release compatible with Splunk 9.0.x up to 9.1.0 is TrackMe 2.0.99
SHA256: f33353510b450588df38976b465d87bf95f7614d9223c4a3348b08d48b95af1b
Version 2.1.2 - build 1728540776 (10/10/2024)¶
Hint
For Splunk 9.1.1 and later
From TrackMe 2.1.x, there is no more compatibility with Splunk 9.1.0 and earlier.
The last release compatible with Splunk 9.0.x up to 9.1.0 is TrackMe 2.0.99
SHA256: 361ea0ee5bd07584f96ebd8960af8f1ff6ac82d5f2b68b08ea45cae6f880e848
Issue Number |
Issue Description |
Issue Details |
|---|---|---|
TrackMe Home UI - Workload / Flex / Metric hosts (splk-wlk/flx/mhm) |
The entity screen incorrectly shows “host state” rather than “entity state” next to the state icon. |
|
Acknowledgement - Auto expiration of Acknowledgements based on condition changes |
The Ack that auto raised can be expired by the Ack auto-management. If the anomaly reason is none, it will incorrectly expire the Ack. |
|
TrackMe Hybrid trackers - Missing Hybrid tracker from central collection |
A new task ensures that the hybrid tracker KV collection remains consistent and fixes records if needed. |
|
Blocklists features - Unexpected additional dot in regex-based blocklists |
Adding a regex blocklist with a wildcard results in an extra dot due to incorrect handling of non-regex blocklists. |
|
Data Source monitoring - Data sampling engine issues with future data |
Earliest time can be after the latest, causing sampling searches to fail due to future data indexing. |
|
Home UI - Donut chart doesn’t show green state entities |
A bug prevents green state entities from being represented in the top-right donut chart. |
|
Elastic Sources - Background task for entity count refresh not called |
The Shared Elastic tracker does not call the method to refresh entity count, leading to incorrect data. |
|
Elastic Sources - mstats-based searches don’t generate expected dcount host metrics |
An SPL field name prevents expected host distinct count generation. |
|
TrackMe Health Tracker - Incorrect warning for tags tracker |
Health Tracker generates incorrect warnings due to hard-coded DSM component definition in tags tracker. |
|
API Documentation & Reference - Incorrect API reference examples for tags policies management |
Examples in the documentation are missing the component argument. |
|
Persistence issue for entities with backslashes |
Backslashes in entity names cause issues with persistence of settings like priority and lagging thresholds. |
|
Data Sampling & Events format recognition - Confusing regex simulation message |
When regex does not match any events, the result message is confusing and should clearly indicate 0% match condition. |
Issue Number |
Issue Description |
Issue Details |
|---|---|---|
Blocklist management for splk-feeds - Various improvements |
Enhanced management screen, added comment storage, and background entity count updates for blocklists. |
|
TrackMe Virtual Tenants UI licence information & Schema Upgrade |
Added clickable TrackMe version display, schema version info, and shortcut to manage licence and upgrades. |
|
Virtual Tenants UI - Notify messages for quick action buttons |
Ensured all buttons in the Virtual Tenants screen show notify messages when hovered. |
|
Virtual Tenants UI - Embedded Entities Overview Tabulator |
Introduced a single-pane Entities Overview in Virtual Tenants for easier navigation. |
|
TrackMe Home UI - Quick access to reports from Elastic Dedicated screen |
Added quick Splunk Web access for reports from Elastic Sources management UI. |
|
Data Sources monitoring - Tenant level control of Data Sampling |
Added an option to enable/disable Data Sampling for Virtual Tenants, hiding UI functions accordingly. |
|
TrackMe Home UI - Hiding adaptive_delay feature when disabled |
Automatically hides adaptive_delay-related UI elements when the feature is disabled. |
|
Elastic Sources - Support for mpreview-based searches |
Added mpreview-based searches as a replacement for mtstats, providing true metrics count reporting. |
|
Elastic Sources wizard - Presets for earliest/latest based on search type |
Automatically presets recommended earliest/latest times based on the type of search. |
|
TrackMe Health Tracker - Auto fix duplicated entities |
Automatically detects and fixes duplicated entities in all components. |
|
Cribl Logstream monitoring - CPU usage metrics |
Added CPU usage metrics, including time spent in green/red states, to TrackMe metrics indexes. |
|
Virtual Tenants UI - UX enhancement for Tenants Ops view |
Improved user experience with status selectors, quick access to reports, and logs in the Tenants Ops view. |
|
Virtual Tenants & Home UI - Tabulator sort header improvement |
Removed the sort header for fields where sorting is not meaningful in Tabulator. |
|
Virtual Tenants UI - Scheduler overview enhancement |
Replaced Splunk table with a tabulator view for the scheduler overview with quick actions. |
|
Splunk Remote Search - Configurable timeouts for remote accounts |
Added per-account configurable timeouts for connection and search in Splunk Remote Search. |
|
ML Outliers - Minor log improvements |
Enhanced the quality of logs generated by ML outlier detection. |
|
Hybrid Trackers - Cron schedule validation |
Added cron schedule validity checks using croniter library for all scheduled logic. |
|
Data Sampling & Events format recognition - Python code improvements |
Improved Python code quality and safer behavior for the Data Sampling engine. |
|
Data Sampling & Events format recognition - Entity settings overview |
Added a dynamic entity settings overview in JSON format within the Data Sampling UI screen. |
|
Bulk edits & Audit logging - New audit format for bulk edits |
Refactored bulk edit function to track changes per field, improving audit logging. |
|
TrackMe Audit subsystem - Mass audit REST call improvements |
Switched to mass audit REST calls for better performance and flexibility in the Audit subsystem. |
|
TrackMe events - Consistent event_id convention |
Standardized event_id across all TrackMe-generated events using sha256 hash. |
|
TrackMe Home UI - Allows selecting visible tabs and their order at the level of the Virtual Tenant account |
This feature adds a new parameter in the Virtual Tenant account, to control the order and visibility of the main tabs in the Home UI. |
|
TrackMe Home UI - A new component replaces the usage of the input list for the top tab links in Home, for more flexibility and control |
This adds more flexibility and control, and notably ensures Virtual Tenant level parameters to be initialized before calling components loading. |
|
Virtual Tenant - Allows overriding the system general auto disablement settings for splk-feeds at the level of the Virtual Tenant account |
This features adds a Virtual Tenant level option to override the system general setting defining the behaviour for disabling inactive entities from a certain amount of days. |
Version 2.1.1 - build 1726614488 (18/09/2024)¶
Hint
For Splunk 9.1.1 and later
From TrackMe 2.1.x, there is no more compatibility with Splunk 9.1.0 and earlier.
The last release compatible with Splunk 9.0.x up to 9.1.0 is TrackMe 2.0.99
Introducing TrackMe’s data sampling events format recognition v2!
TrackMe 2.1.0 welcomes the introduction of a brand new version of the events format and recognition for data sampling. (Data quality inspection, PII tracking, and more)
This is major change and improvements in the way TrackMe handles data sampling events, and will allow for slightly more flexibility and control over the data sampling process.
For more information about the engine v2 and its capabilities, see the admin guide: Data sampling
SHA256: eb750290ecf39e926fe7e6528de8fbfdac8f078f9a6922cca7b0167a69cc4f0d
Fixed issues:
trackme-limited/trackme-report-issues#769 - bug - TrackMe Data Sampling UI - links to pre-built KPI metrics search generate an incorrect earliest time
In the data sampling, several quick access buttons allow generating automated KPIs metric searches in a new blank tab.
However, due to a Javascript bug, an incorrect pattern is unexpectedly added to the earliest time.
trackme-limited/trackme-report-issues#770 - bug - Virtual Tenant UI & REST API - Splunk Knowledge Objects explorer and associated endpoint generated an invalid JSON, preventing the UI formatting to work as expected
The Virtual Tenant UI screen for knowledge object access should generate a JSON pretty printed of the properties field.
However, the macro called by the endpoint generates an invalid JSON, and the REST API endpoint should better handle the parsing too.
trackme-limited/trackme-report-issues#774 - bug - Flex Objects & Workload - trackmesplkflxinactiveinspector/trackmesplkwlkinactiveinspector custom commands are designed to handle inactive entities purge, however the process is not currently working as intended
These commands are designed notably to purge entities which have been inactive for too long, after the configured period in days passed as an argument to the commands.
However, this particular action does not work as intended currently, and purge of entities is not currently effective.
This fix addresses these issues and also slightly improves the code quality and logging of these commands.
trackme-limited/trackme-report-issues#779 - bug - SLA tracking - When entities status change, the SLA status will temporary be inconsistent and will show an incorrect time until trackers have reflected the real time change in the KVstore
When a given entity status changes from one to another, the SLA status is temporarily inconsistent due to the discrepancy between the real time status provided by the Decision Maker and the fact that the KVstore object_state is yet to be updated.
With this fix, the SLA status takes into account both values, and will show a specific SLA refresh pending message, and the SLA status and timer will wait for the KVstore to be updated accordingly to avoid any inconsistency.
Enhancements, changes and new features:
trackme-limited/trackme-report-issues#771 enhancement - Virtual Tenant UI - Tenants Splunk Knowledge Objects explorer screen - Add quick actions button for the Tabulator
This enhancement adds various quick action buttons to filter out the Tabulator content against savedsearches only, macros only, and so forth
trackme-limited/trackme-report-issues#772 - enhancement - Notify bar lookup & feel - Responsive design and modern look & feel for the notification bar in TrackMe
This enhancement is a major refresh of the responsive notification bar plugin in TrackMe.
The provides a responsive look & feel notification bar to TrackMe and a much improved and more modern appearance.
trackme-limited/trackme-report-issues#773 - enhancement - TrackMe Home UI - Add quick Splunk Web access to reports & macros from the Hybrid Tracker
This enhancement adds quick access in Splunk Web for reports & macros through the Hybrid trackers management UI for all components
trackme-limited/trackme-report-issues#775 - change - Python - Addressing the deprecation of calling log.setLevel with logging.getLevelName when defining the current logging level in the various Python backends
This change addresses a Python deprecation of calling the method logging.getLevelName within log.setLevel
trackme-limited/trackme-report-issues#778 - enhancement - In Virtual Tenants & Home UI, show the number of enabled entities rather then total number of entities
This enhancement updates the number of entities primarily shown in the Virtual Tenants UI, as well as the Home UI and the left single view, so that we show the total number of enabled entities, instead of the total number entities active + inactive.
This provides more valuable information as well as better clarity in TrackMe.
Version 2.1.0 - build 1726088942 (11/09/2024)¶
Hint
For Splunk 9.1.1 and later
From TrackMe 2.1.x, there is no more compatibility with Splunk 9.1.0 and earlier.
The last release compatible with Splunk 9.0.x up to 9.1.0 is TrackMe 2.0.99
Introducing TrackMe’s data sampling events format recognition v2!
TrackMe 2.1.0 welcomes the introduction of a brand new version of the events format and recognition for data sampling. (Data quality inspection, PII tracking, and more)
This is major change and improvements in the way TrackMe handles data sampling events, and will allow for slightly more flexibility and control over the data sampling process.
For more information about the engine v2 and its capabilities, see the admin guide: Data sampling
SHA256: 2a79af2a363bf1d10beb2f51f8c3f1334298d046015d4a23d1197c14ae5572c9
Fixed issues:
trackme-limited/trackme-report-issues#757 - bug - TrackMe schema migration from 2.0.97 and prior to 2.0.98 and latest should address the tags extension to splk-mhm
In TrackMe 2.0.98, the tags features were normalised and extended to all components.
However, splk-mhm was not included in the list of eligible components leading to various issues in this components.
This change addresses the issue automatically, if the splk-mhm component was enabled, the tags extension will be managed during the schema upgrade.
trackme-limited/trackme-report-issues#761 - bug - TrackMe Health Tracker - subcontext=”entities_auto_disablement” is attempting to perform a REST call per entity instead of a mass disablement operation, leading the tracker to eventually take an abnormal amount of time to be executed while failing to disable entities, and possibly generate skipping searches
The Tenant health tracker runs a subcontext task called entities_auto_disablement, which is designed to automatically disable the monitoring state of entities that have not generated any data according to the system wide setting splk_general_feeds_auto_disablement_period.
However, a bug affecting this task incorrectly attempts to run a REST call per entity, instead of a mass REST call.
In some circumstances, this leads to an abnormal amount of run time for tracker and can cause skipping searches for the tracker
trackme-limited/trackme-report-issues#763 - bug - Typo in UI - Create Hybrid trackers
This fixes a typo in the Home UI and the Virtual Tenant UI, and for the Hybrid tracker creation wizards
trackme-limited/trackme-report-issues#765 - bug - trackmesplkgetflipping can still be affected by a non expected missing object_category value in the KVstore record
In some conditions, exceptions can still be encountered during the call of the streaming custom command trackmesplkgetflipping, leading to failures in properly handling the search logic. (especially in splk-dhm)
This update adds the object_category as an argument to the streaming custom command instead of getting this value from the records, the schema upgrade will process the update of all hybrid trackers wrapper search automatically so that the argument is called.
trackme-limited/trackme-report-issues#766 - bug - Transition to SHA256 based logic for FIPS compatibility mode in TrackMe 2.0.99 needs to be retro-applied on any tracker created by TrackMe
Since TrackMe 2.0.99, we use sha256 instead of md5 to calculate the expected hash for TrackMe entities objects.
In some specific use cases, such as the Flex object for host tracking or some contexts in Workload, this change needs to be reflected on the search logic itself.
The schema upgrade will verify all trackers and automatically update any tracker if needed.
trackme-limited/trackme-report-issues#767 - bug - Virtual Tenants UI - When creating hybrid trackers during the Virtual Tenant wizard, tracker names should be a random combination rather than only the account name
During the Virtual tenant creation, Hybrid trackers can be created per tenant/component, the hybrid tracker names should be a combination of “tracker-<random ID>” instead of just the account name.
trackme-limited/trackme-report-issues#768 - bug - TrackMe Backup REST API endpoints - avoids raising a file does not exist exception in some rase cases
In some specific circumstances, the POST backup API endpoint can raise an exception if the expected file does not exist, this update simply avoids this condition.
Enhancement, changes and new features:
trackme-limited/trackme-report-issues#756 - feature - Data Source tracking - Introducing the Data Sampling events and format recognition engine v2
TrackMe 2.1.0 welcomes the introduction of the engine v2 for the data sampling and events format recognition.
This is a completely rewritten engine in full Python, providing flexible and powerful capabilities for events quality inspection in TrackMe.
The new engine provides flexible options at the system wide level, which can be customised on a per entity basis, such as controlling the min time between sampling iterations, the number of events sampled per iteration (which is now 10K), the truncation of events when storing samples for investigation purposes, initial thresholds for min match inclusive percentage, and more!)
With the the engine v2, parsing of recognitions models is made against the whole event and is no longer limited due to truncation, events are no longer stored in the KVstore then processed, but processed then a sample of sampled events is stored in the KVstore per model matched and for review purposes.
The new engine introduces a brand new concept of major / minor models matching, allowing to tackle minor quality issues without generating non meaningful alerts, TrackMe admin can control the minimal threshold of acceptable percentage of events matching the main model.
Tracking Personally Identifiable Information (PII) can handle as many models as required (exclusive match)
The interfaces were rewritten so the data sampling feature can be controlled and reviewed more efficiently and with more capabilities.
KPIs generation from Data Sampling: The engine now generates KPIs in TrackMe’s metrics models, so you can review over time the events matching percentage per model, the amount of events parsed and matched, as well as other KPIs such as the run time of the sampling operation per entity.
Many additional improvements were made in the data sampling engine v2!
trackme-limited/trackme-report-issues#758 - enhancement - TrackMe Schema upgrade - normalise the schema version to always use a 4 digits based logic, handling the patch version number
This update ensures that TrackMe uses a consistent 4 digits based logic for the schema_version number, and handles notably the question of a new minor release and its associated patch number (ex: 2.1.0 versus 2.0.99)
trackme-limited/trackme-report-issues#759 - feature - TrackMe Notable events - Add a unique identifier in each TrackMe notable event
Some customers may make use of a unique identifier in TrackMe notable events, especially to ensure notables have been consumed accordingly.
trackme-limited/trackme-report-issues#760 - feature - TrackMe Home UI & Tabulator - Add a Download button which allows downloading visible and filtered entities as a CSV file
This new feature adds a Download button above the Tabulator table which allows quickly exporting visible and filtered entities as a CSV file for quick review out or data manipulation out of TrackMe
trackme-limited/trackme-report-issues#762 - enhancement - TrackMe Health Tracker - Logging and code improvements to allow easily monitoring the run_time taken by each task processed by the tracker
This enhancement slightly improves the logging of the run_time taken by each task executed by the Health Tracker using a concept of task_instance_id associated with a task_name
A sample SPL:
` index=_internal sourcetype=trackme:custom_commands:trackmetrackerhealth instance_id=* task_instance_id=* task=* run_time=* tenant_id=* | table _time tenant_id instance_id task task_instance_id run_time _raw | sort 0 - _time `trackme-limited/trackme-report-issues#764 - enhancement - TrackMe Schema Upgrade - before starting upgrade procedures, execute TrackMe’s builtin backup
With this enhancement, when TrackMe detects that migration procedures must be initiated, it will first query a TrackMe backup to be executed.
Version 2.0.99 - build 1723722498 (15/08/2024)¶
SHA256: 6d7174da69a584a5dfdef160f2cb07410630db5b5bcf397aeb1956f83b037cd2
Additional notes about this release
To address FIPS compatibility requirements, we have migrated from md5 to sha256 various TrackMe internal search logics.
There are near no impacts to existing installations, however for customers using TrackMe Workload, you will notice that all monitored objects (Scheduled discovered) will generate a Metadata event, which normally happens only when a change in the search is detected.
This behaviour is due to the change from md5 sum calculations to sha256 calculations for FIPS compatibility purposes, and can be safety ignored and acknowledged as part of the upgrade to TrackMe 2.0.99
Fixed issues:
trackme-limited/trackme-report-issues#738 - bug - TrackMe pagination - When using pagination mode = local, the pagination size is not submitted by the Tabulator and should default to size = 0 since the pagination is performed by the Tabulator rather than the server, which leads to missing records in high scale collections
The default pagination mode is local rather than remote, however when using pagination = local, the default size should be 0 as the Tabulator will not submit this as an argument to the REST call to TrackMe.
This leads currently to missing records in the UI for high scale collections.
trackme-limited/trackme-report-issues#740 - bug - TrackMe Home UI - When opening an entity and if the tenant_id field of the Kvstore has an empty content unexpectedly, the UI fails to load the entity overview modal screen
If in the tenant_id/component KVstore collection, the tenant_id field does not have a content, the UI fails to open the entity overview
trackme-limited/trackme-report-issues#741 - bug - trackmehealthtracker - logging reports the details of untracked entities for splk-dhm rather than the number of them
for splk-dhm, the trackmehealthtracker should not report the detailed content of untracked entities, but how many of them were found instead.
trackme-limited/trackme-report-issues#743 - bug - Data Sampling for splk-dsm - Managing the Data sampling feature (enable/disable/run/reset) would fail for an entity which has not been processed at least once by the data sampling engine
In the current release, managing the status of the data sampling feature can only happen if the data sampling has processed the entity at least once, and would fail otherwise.
This fix ensures that we properly manage the feature depending on the user request, no matter if the entity was processed already or not.
trackme-limited/trackme-report-issues#746 - bug - CIM compliance tracking (splk-cim) - When creating a new entity by cloning and if the CIM constraint contains one or more double quotes, the creation fails
Creating a new entity by cloning for splk-cim fails if the CIM constraint contains double quotes
trackme-limited/trackme-report-issues#753 - bug - Outliers Anomaly detection - Workload (splk-wlk) - TrackMe should not attempt to train models for entities parts of applications that have been disabled in the Workload component
In TrackMe’s Workload component, entities can be enabled/disabled at the app level.
When an application is disabled, TrackMe should not attempt to consider training ML models.
Enhancements, changes and new features:
trackme-limited/trackme-report-issues#736 - feature - FIPS compatibility for TrackMe
Splunk 9.3.x introduced several fixes which made Splunk really FIPS compatible, which disabled some crypto algo such as md5 which is used by TrackMe.
These developments allow TrackMe to be fully FIPS compatible, and FIPS validated from TrackMe Limited.
trackme-limited/trackme-report-issues#742 - enhancement - Data Sampling for splk-dsm - Improve the message and status returned when data sampling is disabled for a given entity to avoid any confusion
When data sampling is disabled, the message shown in the UI, and returned underneath by the API endpoint, should be clearer to avoid any confusion.
trackme-limited/trackme-report-issues#737 - bug - Data Source tracking (splk-dsm) - Grouping issues with reduced pagination and entities for the same indexes that are split over multiple pages
If using a reduced pagination size, entities relying on the same indexes can be split over multiple pages.
This fix may not entirely prevent this as this depends on the pagination size, but the addition of the index in the initial sort should limit the risk of this happening.
trackme-limited/trackme-report-issues#744 - enhancement - Health Tracker - Addition of tenant_id value verification in the record inspection steps
This added step verifies that records of the main KVstore collection have a valid value for the field tenant_id, for consistency purposes.
trackme-limited/trackme-report-issues#745 - change - Virtual Tenant UI default settings - reducing the flex box default size from 374px to 350px
This change updates the default flex box size in of the Virtual Tenants UI
trackme-limited/trackme-report-issues#747 - change - Data Hosts tracking (splk-dhm) - Change the default delay value from 3600 to 86400 seconds for Hosts Tracking
In most use cases, it makes sense to increase the default delay value for Hosts tracking compared to Data source tracking.
Hosts tracking is a very different activity and most often, we need less restrictions when it comes to tracking the last time hosts have sent data as a default.
trackme-limited/trackme-report-issues#748 - bug - TrackMe Home UI - Flex Object creation screen can hide the bottom action buttons if the screen resolution is very low
When creating a new Flex Object tracker, a very low screen resolution can prevent access to the bottom action buttons, unless zooming out from the Web Browser.
trackme-limited/trackme-report-issues#739 - feature - Flip events - Add a calculated disruption_time value in seconds within the flip results message when the entity switches from green to red
When a given entity state changes from red to green, this changes adds a new calculated field disruption_time in seconds to ease further calculations of availability for users.
When the state are matching other conditions, the field has a 0 seconds value.
trackme-limited/trackme-report-issues#749 - enhancement - Data Sampling for Data Sources tracking - improve the message in the UI when sampling has not been processed yet
When Data Sources tracking is pending and has not been processed yet, the message shown is simply N/A, and would deserve to be better explained.
trackme-limited/trackme-report-issues#750 - enhancement - TrackMe Health Tracker - Add a step to verify consistency regarding permanently deleted records
When entities are permanently deleted, TrackMe stores records referencing these entities, so we will not discover these entities again.
In some circumstances such as restoring the KVstore collection, there could be a discrepancy due to the fact that entities are existing in the main KVstore collection, while in the same time listed as permanently deleted.
This additional verification ensures that if such a case happens, TrackMe would automatically purge associated records in the main KVstore.
trackme-limited/trackme-report-issues#751 - feature - Data Sources/Data Hosts tracking (splk-dsm/splk-dhm) - Add avg/max choices and additional choices with threshold in performance metrics tab
This feature adds further more choices in the performing metrics screen, notably it adds choices between avg/max calculations at the time chart level, as well as options to include the current threshold for latency/delay.
trackme-limited/trackme-report-issues#752 - enhancement - Flex Objects library - Improve grouping for Splunk Cloud SVCs tracking use cases
TrackMe has currently two builtin use cases for SVCs tracking in Splunk Cloud, the grouping should be improved so we dissociate global SVC tracking and per app SVC tracking.
trackme-limited/trackme-report-issues#754 - enhancement - Workload (splk-wlk)- When managing applications enablement, the tenant component summary should be refreshed
In the workload component, TrackMe administrators can enable or disable entities at the application level.
When doing so, we should refresh the component summary as soon as possible, without waiting for the main tracker to perform it.
Version 2.0.98 - build 1722591315 (02/08/2024)¶
SHA256: 371c327a8f492c07e57b60c8f8e505ecb8e9ba0aacca5d864ebfb31084612d26
Fixed issues:
trackme-limited/trackme-report-issues#700 - bug - SmartStatus alert action - Python exception in some circumstances when accessing the anomaly_reason
The SmartStatus alert action can raise an exception while trying to investigate the anomaly_reason field.
trackme-limited/trackme-report-issues#702 - bug - Bulk edit - Critical priority button should be available in Bulk edit entities
Critical priority was added in TrackMe 2.0.95, but in Bulk Edit we didn’t add the associated button to mass update for the new priority.
trackme-limited/trackme-report-issues#705 - bug - Virtual Tenants UI - copy to clipboard TrackMe spl for Virtual Tenant creation can failed when executed due to boolean in JSON not properly handled
When creating a new Virtual Tenant via the UI, one can at the end of the execution copy to clipboard the TrackMe SPL command that can be used to achieve the same creation in CLI.
However, an issue appears with the enablement of the component that remains in boolean and is not correctly handled in the SPL statement.
trackme-limited/trackme-report-issues#708 - bug - TrackMe Home UI Tabulator - regression due to trackme-limited/trackme-report-issues#697 for the management of encoded backslashes prevents the Alias to be inline editable
A regression is affecting the Alias editable capability within the Tabulator due to the management of the encoded backslashes in issue#697.
This fix ensures the Alias is editable again within the Tabulator while still handling encoded backslashes.
trackme-limited/trackme-report-issues#710 - bug - Adaptive Delay (command trackmesplkadaptivedelay) - In some conditions, the backend tries to split a string into a list while already a list, raising a Python exception
In the command trackmesplkadaptivedelay, we turn the anomaly_reason into a Python list from pipe separated, in some circumstances the field is already a list and the backend should check for the type of the object before applying the split.
trackme-limited/trackme-report-issues#719 - bug - TrackMe Notables and multi value fields in properties - mv fields should be properly handled in the properties, and stored as list within the JSON event
When TrackMe generates a TrackMe notable event, the properties field contains all fields stored in the KVstore record for that entity.
Currently, multivalue fields are not correctly handled, and end in a pseudo multi value string structure instead.
trackme-limited/trackme-report-issues#725 - bug - Data Source tracking (splk-dsm) - Missing call to trackme_default_allow_adaptive_delay in the abstract macro called by the health tracker results in the field allow_adaptive to be empty in some conditions
When the Health Tracker inspects offline entities (entities not actively generating data within the trackers scope), it shall call the macro that defines the default allow adaptive value.
trackme-limited/trackme-report-issues#727 - bug - SmartStatus - The use case search for future tolerance and the extraction of samples in the future is not consistent
When SmartStatus is called and run the UC for data in the future (future over tolerance), one of the searches extracts a sample of events in the future.
The current search syntax is not ideally consistent and should be fixed for more meaningful results.
trackme-limited/trackme-report-issues#729 - bug - Feeds tracking (splk-dsm/dhm/mhm) - Auto-disablement of entities handled by the system wide configuration setting does not work as expected
For feeds tracking, a system wide option was meant to allow automatically disabling the monitoring state of feeds tracking entities if the entity has not actively sent data since a certain period of time. (45 days by default)
However, the features is not properly working and does not influence the monitored state.
This change updates the process and transfer this work to the Virtual Tenant health tracker instead.
It fixes the action and enhances the worklfow by calling instead the associated API endpoint (rather than modifying silently the monitored_state), which also allows audting the change properly.
The period is also changed by default to 60 days, and the option is moved from General to splk-general for more consistency.
trackme-limited/trackme-report-issues#731 - bug - Machine Learning Outliers - Avoid generating an error with the command trackmesplkoutliersgetrules when dealing with Flex tracking that do not handle ML models
Prevents generating an error message from this custom command and for Flex trackers that do not handle ML models.
trackme-limited/trackme-report-issues#732 - bug - TrackMe Home UI - Missing open in search for Notable events in the entitiy screen for all components
When the mouse focus is on the Notable table in the entities screen, there should be an open in search option underneath the table.
trackme-limited/trackme-report-issues#734 - bug - TrackMe Home UI for splk-flx/splk-wlk - Machine Learning Outliers - In Adding model, the KPI dropdown selector does not populate properly
When adding a new ML model for splk-flx/splk-wlk, the dropdown selector for the KPI selection does not populate due to a token generation issue.
trackme-limited/trackme-report-issues#735 - bug - TrackMe Home UI - regression in the tracking alert screen when clicking on a given alert to see the different charts, leading to none of the charts to be visible
In the Home UI and the Tracking alerting tabs, a regression due due to a previous change (defining the default timerange via the Virtual Tenant account) leads to non of the charts to be visible when opening the activity of a given alert.
Enhancements, changes and new features:
trackme-limited/trackme-report-issues#699 - change - Splunk UCC 5.8 decommissioned placeholder in entity from globalConfig.json
Splunk UCC 5.8 removed the placeholder option for entity, this change ensures compatibility for the current and future releases of Splunk UCC.
trackme-limited/trackme-report-issues#701 - change - Upgrade of moment.js to last version 2.30.1 - Appinspect warning
Appinspect warning has raised a message regarding the moment.js lib that needs to be upgraded.
trackme-limited/trackme-report-issues#703 - feature - Bulk Edit - Allow handling all options for lagging policies via bulk edit for eligible components
In Bulk edit, this evolution adds a section providing full control for lagging monitoring policies for splk-dsm/splk-dhm.
trackme-limited/trackme-report-issues#707 - feature - TrackMe Home UI - Add buttons to expand all / collapse all grouped items in the Tabulator JS
This feature adds “Expand all” and “Collapse all” buttons to allow expanding or collapsing items per group in the Tabulator JS table for the TrackMe Home UI.
trackme-limited/trackme-report-issues#709 - feature - Flipping events - Log the previous anomaly_reason when generating flipping events
When TrackMe detects a change in the status of an entity, it generates a flipping event.
With this evolution, TrackMe will also log the previous anomaly_reason in addition to the new anomaly_reason.
trackme-limited/trackme-report-issues#711 - feature - All components - Tabulator in Home UI and entities grouping - Allows controlling entities grouping by configuration
This new feature allows controlling the Tabulator group at the level of the Virtual Tenant account.
With this control, you can define a list of custom fields of your choice for multi-level grouping, or you can use expressions to compose a custom field for the Tabulator grouping.
This evolution provides a number of quick actions buttons in the Home UI, so you can change the grouping temporarily, for instance such as grouping by anomaly reason or priority, and allows calls back the default grouping.
trackme-limited/trackme-report-issues#712 - change - Address Appinspect warning about splunk_resource_usage
Appinspect reports a warning about: default/props.conf contains a [splunk_resource_usage] stanza.
This change addresses this warning which is due to a field alias for the purposes of the Workload component (splk-wlk).
trackme-limited/trackme-report-issues#713 - enhancement - Outliers Anomaly detection - Before attempting to render an Outlier model, verify the true existing of the model to avoid failing the search if the model is not yet ready
This enhancement allows TrackMe to verify the true existence and readiness of a Machine Outliers model before attempting to process with the render search, avoiding to generate a failing search in the system.
In some circumstances, TrackMe may spawn rendering searches while the model is not yet ready, it has not been trained yet or the KPI underneath does not generate metric points, which results in the generation of a failing search from Splunk perspective.
This evolution prevents this situation by performing a true verification of the model readiness.
trackme-limited/trackme-report-issues#714 - change - Virtual Tenant creation - When creating a new Virtual Tenant and splk-dhm is the only enabled component, automatically disable ML Outliers at the Virtual Tenant account so it can be qualified for further enablement
This change automatically disables ML Outliers detection feature at the Virtual Tenant account level, and when creating a new Virtual Tenant where splk-dhm is the only enabled tenant, so it can be decided later on to enable it or not.
The purpose of this change is to reduce system pressure for users that do not qualify enough TrackMe configuration, leading to very large ML models volume to handle.
trackme-limited/trackme-report-issues#715 - change - Data Hosts/Metric Hosts tracking (splk-dsm/splk-mhm) - Add a safety regarding the presence of object_category before calling the command trackmesplkgetflipping
This change adds a safety feature at the Python level to ensure the presence of a valid value for the field object_category in the tracker process execution, and before it calls the streaming command trackmesplkgetflipping.
The objective is to avoid an unexpected condition that could lead the search to fail.
trackme-limited/trackme-report-issues#717 - feature - Extend and normalize the tags feature to all TrackMe components
This extends the concept of tags, handled at the entity level and by policies, for all TrackMe components equally. (this was first released for splk-dsm)
Decommissioning the historical enrichment tag for splk-dhm/splk-mhm which were made redundant since we introduced the CMDB integration, and for consistency purposes.
After the upgrade, the schema upgrade will upgrade necessary objects and create new objects for newly eligible components, there are no interventions required.
trackme-limited/trackme-report-issues#718 - enhancement - TrackMe REST API - Improve the behavior when forcing the deletion of a Virtual Tenant via the del_tenant endpoint
When calling the del_tenant API endpoint in force mode, we should systematically try to clean any report that could be associated with the Virtual Tenant as per the upstream request.
Avoid systematically returning the status of failure, in force mode we will always try to delete knowledge objects that may not exist.
trackme-limited/trackme-report-issues#720 - change - TrackMe Home UI - When creating a technical component alert, the Ack mode should be a dropdown instead of a text box selector
When creating a new alert for the component, the Ack mode selector is provided as a text input rather than a more adapted dropdown selector as only two options are possible.
trackme-limited/trackme-report-issues#722 - enhancement - Tabulator in Home UI - Add control against the allow adaptive column in the Tabulator, Add missing column for more consistency in splk-dsm/splk-dhm
This enhancement adds the allow adaptive thresholding column to the Tabulator for splk-dsm/splk-dhm for consistency purposes.
It also adds some missing columns regarding lagging policies features for these components, and makes column size and titles more consistent.
trackme-limited/trackme-report-issues#723 - change - TrackMe persistent backend - Address some inconsistency in the list of the persistent fields per component
TrackMe uses a library Python file that defines the list of fields which should be considered as persistent.
This is used to ensure that we detect a modification of these fields while a concurrent update logic (tracker) can be running, so these changes are not lost.
This change addresses some inconsistency in these lists.
trackme-limited/trackme-report-issues#721 - enhancement - Role Based Access Control (RBAC) - Ensure vtenant main collections and vtenant summary main collections are made readable to roles added to Virtual Tenants
TrackMe’s built-in mains KVstore collections and transforms are by default readable to a few specific roles, admin/sc_admin and TrackMe built-in roles.
When handling RBAC to allow access to foreign roles, we should also check and grant read access to these collections for RBAC to work as expected without further intervention from Splunk admins.
trackme-limited/trackme-report-issues#724 - enhancement - Maintenance mode - Access as a non-admin should ideally show an informational message rather than a blocked error
When accessing the maintenance mode dashboard as a non-TrackMe admin, we should ideally show an information message, instead of having the dashboard blocked with an insufficient permission issue.
trackme-limited/trackme-report-issues#726 - enhancement - Virtual Tenants creation - Safer verification and management of requested Virtual Tenant identifier
When creating a new Virtual Tenant, there are some conventions that TrackMe will apply, such as forcing lowercase, using hyphens as the separator.
In some conditions, the current verification can be bypassed leading to issues during the Virtual Tenant creation. This enhancement ensures a safer and more consistent approach.
trackme-limited/trackme-report-issues#728 - feature - Allows defining a Virtual Tenant wide indexed constraint for splk-dsm/splk-dhm that automatically influences associated generated searches created by TrackMe, such as UI search action button or SmartStatus
This feature allows defining at the Virtual Tenant level a custom indexed constraint, which is then automatically used while defining automated searches such as the search button in the Home UI, or searches created by the SmartStatus.
This can be useful in a scenario where each Virtual Tenant is associated with a custom indexed constraint, such as referring to a splunk_server_group or any other required indexed string.
trackme-limited/trackme-report-issues#730 - change - Moving the default future tolerance system wide option from General to splk-general for consistency purposes
The system wide option Future indexing tolerance is moved from General to splk-general for more consistency in the options.
trackme-limited/trackme-report-issues#733 - enhancement - Flex Object library - Add dcount host to the drop detect use cases (splk_detect_drop_events_count_absolute/splk_detect_drop_events_count_rolling)
Improvement to the Flex Obect library use cases related to drop events detection, adding the dictinct count host KPI.
Version 2.0.97 - build 1720562684 (09/07/2024)¶
SHA256: 44c4a80e9584f546583f4cc43661a45c499f05b50f26e31159fa419225ced26e
Fixed Issues:
trackme-limited/trackme-report-issues#669 - bug - Flex Object (splk-flx) - When triggering due to Anomaly Outliers and when not actively managed by a tracker, a Flex Object entity will not return to green state if the Outliers conditions is fixed
If a Flex entity turns red due to Outliers condition, and if that same entity is not actively managed by a tracker (for instance if the tracker is time conditioned for some reasons it’s not active in the tracker time window), TrackMe will not update the status of the entity properly.
This is due to the fact that we should take into account the flag field status in addition with the object_state especially for Flex objects
trackme-limited/trackme-report-issues#670 - bug - Outliers Anomaly detection - Singles in the simulation screen do not honour the simulation screen time range selector and use the front page UI time range instead
When performing Outliers simulation, there are different single views designed to show the key behaviours and statistics.
However, the searches driving the calculations underneath do not honour the simulation specific time range selector, and instead obey to the time range selector of the main entity screen.
trackme-limited/trackme-report-issues#672 - bug - Outliers Anomaly detection - Disabling ML detection on a per entity basis is not properly honoured by TrackMe
ML Outliers Anomaly detection can be disabled on a per entity basis.
There is a regression in the current release of TrackMe and the Decision Maker component which prevents this setting from being properly honoured.
This fix addresses the issue and also provides an enhanced behaviour making this immediately reflected.
trackme-limited/trackme-report-issues#674 - bug - TrackMe State events - the sourcetype trackme:state should by default expect object_state and not state as the field name containing the object_state (default configuration for allow list in trackme_settings.conf)
When trackers are executed, TrackMe generates state events in trackme:state
The fields behaviours are dicted by the TrackMe configuration, however the allow list currently expects the field “state” where we should expect “object_state” as per TrackMe’s convention
trackme-limited/trackme-report-issues#675 - bug - TrackMe Flip events - For consistency purposes, TrackMe should also include the anomaly_reason field in the event generation
When TrackMe entities experience a status change, a corresponding flipping event is generated with the sourcetype trackme:flip
The field anomaly_reason is a key field in TrackMe’s convention, it is part of the flipping message but should also be included on its own for consistency purposes with other TrackMe concepts.
trackme-limited/trackme-report-issues#676 - bug - Data Source tracking - Tags manual - Creating manual tags fail if there are no tags policies created for the tenant
If there are no tags policies in the Virtual Tenant, attempting to create manual tags for a given entity fails due to a Python raise condition, leading to the an error message instead.
trackme-limited/trackme-report-issues#685 - bug - Bulk Edit - Select all tick box in the Tabulator does not honour table filters and leads to all visible entities to be selected
When performing bulk edit entities in TrackMe, there is an option “tick all” which allows selecting all entities.
However, there has been a regression, and TrackMe does not apply current filters from the Tabulator table, leading to all entities to be selected by the tick all checkbox, rather than only resulting entities.
trackme-limited/trackme-report-issues#690 - bug - Virtual Tenants UI - Avoid switching between operation and degraded on the Virtual Tenant flex box when there is an actual tracker in failure
In TrackMe’s Virtual Tenant UI, if an issue is affecting a tracker, in some circumstances the degraded cross information on the Virtual Tenant box will switch from degraded to operation, then at back to degraded.
This is due to a Python flaw in the logic of the process_exec_summary function in lib/trackme_libs_load.py.
trackme-limited/trackme-report-issues#691 - bug - Virtual Tenants UI - screen TrackMe Tenants Operational health statuses can have the Tabulator table hidding buttons with large number of tenants
In the Virtual Tenants UI and when there are a large number of tenants, the bottom buttons of the screen TrackMe Tenants Operational health statuses may be hidden by the table.
trackme-limited/trackme-report-issues#693 - bug - Metric Hosts tracking (splk-mhm) - When creating a new hybrid tracker on a remote target, the break by statement is invalid leading to no results for the tracker
This bug affects the creation of a new hybrid tracker for splk-mhm when the target is a remote target.
The break by statement generated is invalid and missing the host call in the statement.
trackme-limited/trackme-report-issues#696 - bug - Hybrid Tracker (all components) - Ensure to safety truncate the submitted tracker name to 40 chars at the API level and prevents from any risk of failure due to Splunk 100 chars limit
Handles conditions where the submitted tracker ID could lead to a report name requested by TrackMe’s API that goes beyond the 100 max chars accepted by Splunk
Enhancements, changes and new features:
trackme-limited/trackme-report-issues#668 - change - Tabulator - Upgrade to Tabulator 6.2.1
Upgrade of Tabulator JS to release 6.2.1
trackme-limited/trackme-report-issues#619 - feature - Maintenance Mode - Support for enabling Maintenance Mode with selection of applicable tenants, support for Maintenance Knowledge DataBase #619
This introduces support for selective Maintenance Mode on a per tenant basis, you can enable the Maintenance Mode for all tenants (default) or a list of applicable Virtual Tenants.
Support is also added to the Maintenance Knowledge DataBase in TrackMe, as well as automatically influencing SLA calculations depending on if the maintenance period for applicable for the entity tenant.
After the upgrade to 2.0.97, TrackMe’s schema upgrade will automatically update TrackMe alerts to call the new macro trackme_apply_maintenance_mode
trackme-limited/trackme-report-issues#650 - change - Overview eventcount timechart calculations and Performance metrics tab timechart calculations for spl-dsm/splk-dhm, for consistency purposes, use a sum calculation per metrics at the timechart level instead of an avg, as it happens for the latest_eventcount_5m
In the overview chart tab, when looking at increased timeranges, we should rather use a sum calculation for eventcount metrics for consistency purposes.
In the Performance Metrics tab, and for splk-dsm/splk-dhm. TrackMe uses a “sum(latest_eventcount_5m) as latest_eventcount_5m” where others metrics are calculted using an avg.
None of these are technically false and just different reading, but for users going trough a basic approach of comparing true eventcount, this can be confusing.
trackme-limited/trackme-report-issues#671 - change - Outliers Anomaly detection - Allow full control on the period_calculation definition
This update allows complete control for the definition of the period_calculation.
The time quantifier period expression can be submitted without pre-defined periods, for default models generation and on per model basis.
trackme-limited/trackme-report-issues#677 - change - Hybrid Trackers creation screen - Automatically pre-fill the tracker name with a randomly generated ID
When creating hybrid trackers, a text input is expecting a name to be choosen for this tracker.
To improve the global user experience, automatically prefill this input with a randomly generated identifier.
trackme-limited/trackme-report-issues#678 - enhancement - Flex Objects (splk-flx) and TrackMe KPI generation - Support for time definition in metrics generation at ingest time
This enhancements provides support in TrackMe to generate metrics with an upstream value for the metric time stamp.
This allows supporting use cases where the time in the Tracker logic is not equal to when the tracker is executed, but rather part of the SPL statement.
trackme-limited/trackme-report-issues#679 - feature - Flex Object use cases library - New use cases splk_detect_daily_variations_volume_global / splk_detect_daily_variations_volume_index
These two new use cases are designed to leverage the Splunk license indexing logs to track the daily absolute amount of data indexed globally on the license pool, and on a per index basis.
These KPIs then are used to train Outliers Models with the goal of detecting abnornal decrease/increase of indexing volume per entity.
trackme-limited/trackme-report-issues#680 - enhancement - Outliers Anomaly detection - Add %w as an option for the time_factor (time factor influenced per week day)
This enhancement adds support for a time factor option per week day (%w) for the configuration of Machine Learning models via TrackMe’s UI
trackme-limited/trackme-report-issues#681 - feature - TrackMe Home UI and Virtual Tenant account preferences - Add time range selections up to 1y and allows defining the default time range at the level of the Virtual Tenant account preferences
Adds new period for 6 months (180d) and 1 year (365d) in the time ranger selector of TrackMe’s main UI.
Allows defining on a per Virtual Tenant account the default time range to be selected when accessing entities.
trackme-limited/trackme-report-issues#682 - enhancement - Common Information Model compliance (splk-cim) - Improvement of the preview search functions and direct links to open searches in a new window
Add the from datamodel search
Add direct links button for from / datamodel / tstats searches which dynamically open the search into a new window with local/remote account support
trackme-limited/trackme-report-issues#684 - feature - Acknowledgment management - Expire Ack on anomaly reasons changes so TrackMe can raise a new alert when conditions for alerting have changed
This new feature allows TrackMe Ack to be influenced by the change of anomalies affecting entities.
Conditioned by system level configurable options (See Configure / General / Expire Ack on anomaly reason change behaviour, Expire Ack on anomaly reason change min time since, Expire Ack on anomaly reason only for auto ack), this new feature completes and enhances the Ack capabilities in TrackMe.
If an entity that turned red due to an Outliers detection for instance, and later on is also affected by an additional condition such as a lag breach, the Ack will be automatically expired so that a new alert can be raised transparently by TrackMe.
trackme-limited/trackme-report-issues#687 - enhancement - Data Hosts tracking (splk-dhm) - The Performance metrics tab in entity overview should include the Delay Metrics and also include dynamic explanations as with splk-dsm
In Overview entity then Performance Metrics tab, we should for splk-dhm provide access to the Delay metrics, as well as explanations regarding these metrics calculation, similarly to splk-dsm
trackme-limited/trackme-report-issues#688 - enhancement - TrackMe Tracker executor backend - Improved detection of silently failing trackers
When TrackMe executes trackers, this execution goes through a quality and review backend with the custom command
trackmetrackerexecutorEspecially, this process tracks for execution failures, generates run time metrics for TrackMe’s trackers and feeds the Tenant operation statuses.
In some circumstances, some types of execution failres can happen silently and the current version of the backend does not notice it, this fix slightly enhances and is capable of detecting any conditions leading to the failure of the tracker.
trackme-limited/trackme-report-issues#689 - enhancement - TrackMe Health Tracker - Add an additional safety check to identify and purge unexpected foreign records that would have been added by mistake to a main data KVstore collection
Each tenant has a TrackMe Health Tracker which performs various maintenance routines, in this issue we add an additional action to check for the presence of unexpected foreign records in the main KVstore collection, and purge these records automatically if any.
Foreign records could have been added by mistake when manipulating KVstore collections, and would lead to be blocking many logics in TrackMe.
trackme-limited/trackme-report-issues#692 - feature - TrackMe Virtual Tenants - New API endpoint to clear the Virtual Tenants Operation Status actionable through the Virtual Tenants UI
This new API endpoint allows TrackMe Admins to clear the Virtual Tenants Operation Status and optionally request the imediate refresh through the execution of the tenant’s health tracker.
In the Virtual Tenants UI, this feature can be requested via the screen TrackMe Tenants Operational health statuses for all tenants, or a selection of tenants with the option to execute or not the health tracker.
Clearing the Virtual Tenant Operation status can be useful when dealing with a degraded Virtual Tenant which status is blocked due to some issues.
trackme-limited/trackme-report-issues#694 - feature - SOAR Monitoring - Adding Flex Object UC to track SOAR/Splunk forwarding integration (splk_soar_forwarding_splunk)
This additional Flex Object use case for SOAR focusses on tracking the SOAR/Splunk forwarding integration
trackme-limited/trackme-report-issues#695 - feature - Flex Object library - New Flex Use Case splk_splunk_infra_log_level_variations which deals with Splunk logs and their logging level and use Machine Learning to detect abnormal behaviours of your Splunk instances and deployments
This new Flex Object use case tracks Splunk internal log events and their associated logging level to detect suspscious trends, which are symptomatics of Splunk behaving improperly and facing or about to face serious issues.
To achieve this, we leverage TrackMe’s Flex component and our Machine Learning implementation, we then track trends notably of errors in Splunk logs to alert when an abnormal amount of errors is detected.
trackme-limited/trackme-report-issues#697 - bug - All components - Entities containing backslashes generate all sorts of issues in TrackMe, this condition can notably be encountered in Workload (splk-wlk) with very bad report naming
Entities ending up with backslashes can generate various issues in TrackMe, especially in advanced features such as ML Outliers or Metadata tracking for splk-wlk.
This issue addresses this problematic by encoding backslahes at the discovery Python phases, and decode transparently for users as needed.
trackme-limited/trackme-report-issues#698 - enhancement - Workload (splk-wlk) - Management of dupplicated entities at the phase of the health tracker execution
In the Workload component (splk-wlk), the Health Tracker verifies for duplicated entities, and deletes automatically one of the duplicated randomly.
However, it can happen in some conditions that we will keep continously deleting the wrong entity which then keeps being re-created.
For more consistency, this fix will allow TrackMe to purge both concerned entities, so only the right one gets re-created accordingly.
Version 2.0.96 - build 1718623969 (17/06/2024)¶
Major UI filtering performance improvements
This release introduces major performance improvements in the TrackMe main UI, especially when performing entity filtering, which is now nearly instantaneous, regardless of the collection size.
These improvements are made possible by the switch to client-side (local) pagination and filtering in Tabulator, which can now also be controlled through general and per-tenant parameters since this release.
SHA256: 02e835c27b2c681a7ad89f0c9e100a4a6317e824bb9fb3d21286e1108ceabee0
Fixed issues:
trackme-limited/trackme-report-issues#657 - bug - Outliers Anomaly Detection - TrackMe does not honour the method_calculation defined at the model level when performing training and rendering of the model #657
On per model basis, a method calculation can be applied at the level of the mstats search, which will be associated with the KPI span to influence the Outliers root calculation.
However, currently TrackMe does not honour properly the method calculation due to a bug in TrackMe’s Outliers Python library.
trackme-limited/trackme-report-issues#659 - bug - Outliers Anomaly Detection - Default system parameters should not require a value for static LowerBound/UpperBound #659
In Configuration / splk-outliers-detection, saving parameters should not require a value for LowerBound/UpperBound
trackme-limited/trackme-report-issues#665 -bug - TrackMe Home User Interface - Outliers Anomaly Detection appearance remaining issues after performing training via the Manage Outliers UI
Folllowing fixes from trackme-limited/trackme-report-issues#638, there are remaing issues and conditions leading to the Outliers MLTK chart to fail appearing properly after a training is made through the Manage Outliers UI screen.
This is due to the fact that refreshing the search underneath the MTLK Outliers charts while the chart is not visible yet leads to this issue.
Enhancements, changes and new features:
trackme-limited/trackme-report-issues#658 - enhancement - Outliers Anomaly Detect - Add additional options for the Outliers kpi_span #658
Complete selectable options for the kpi_span per model with additional values up to 24h
trackme-limited/trackme-report-issues#660 - feature request - Filter functions - Add in the “By Acknowledgment state” new options to filter on Acknowledged entities per priority
In TrackMe’s UI, one can use filter functions to prefilter on multiple conditions at once.
This feature requests is to add filter functions for Acknowledged entities based on priority filters
trackme-limited/trackme-report-issues#661 - enhancement - TrackMe Home UI performance - client side pagination and filtering in Tabulator for largely improved performances especially when filtering
By implementing client side (local) pagination and filtering, this release introduces major performance gains in TrackMe main UI, especially when performing entities filtering based on any available simple or complex conditions.
The pagination mode and pagination size can now also be controled at the level of the Virtual Tenant account, with the base general configuration that can be customised when creating tenants, and once the tenant has been created through the Virtual tenant account
These enhancements bring major performance improvements to TrackMe, slightly improving the end user experience.
trackme-limited/trackme-report-issues#662 - enhancement - Virtual Tenants UI - Make the results from focus searches more readable and valuable
In the Virtual Tenants UI, when putting the focus on a given tenant / status by priority, a search runs and provides an high level overview of underneath entities.
The purpose of this issue is to simpify the approach to get more readable and valuable results, from this release the search will generate a simpler list of concerned entities ordered by their flip status. (ordered by the last time these entities have had a status changed)
trackme-limited/trackme-report-issues#663 - enhancement - Adaptive Thresholding - Allows to control the review period through the argument review_period_no_days at the level of the adaptive tracker
In this issue, we introduce a new argument to the Adaptive delay custom command which controls the period of time used to identify entities to be reviewed over time following a change made the Adaptive Treshold backend.
The argument review_period_no_days accepts 3 period options: 7, 15 or 30 days for the period of review.
After the upgrade, TrackMe will automatically update existing and active trackers through the schema upgrade.
trackme-limited/trackme-report-issues#664 - change - Adaptive Thresholding - Change of the default period for review from 7 days to 30 days following the introduction of the new option review_period_no_days
Associated with the new argument review_period_no_days, the default is now set to 30 days to improve the behaviour over time of the Adaptive Tresholding backend, and ensure we review for long period enoughs entities that have been modified by the backend.
Version 2.0.95 - build 1718137396 (11/06/2024)¶
New priority level with critical priority
This release introduces an additional priority level “critical” for TrackMe entities.
This will provide more flexibility and consistency for customers to leverage various CMDB and logics, and alert with different types of actions depending on the importance of associated entities.
You may need to review your current alerts, and include the new priority level in your alerting logic.
SHA256: 10f1318c0895f7cd4d648f1a9e48795858ebc5991c0c27447ace816058a9c84a
Fixed issues:
trackme-limited/trackme-report-issues#638 - bug - TrackMe Home User Interface - Outliers Anomaly Detection chart may not show up properly in some circumstances, as after Models modifications or attempting to handle a non valid model #638
The Outliers Anomaly Detection tab triggers when actioned by the user, and will display the models statistics and the Outliers chart.
In some circumstances, such as after a modification of a model or after attempting to display an entity with no models, the chart fails to display properly and will not display until the UI is fully refreshed.
This is caused by attempting to enable / disable the containing HTML div at the CSS level which does not behave well with the MLTK viz chart.
trackme-limited/trackme-report-issues#641 - bug - Metrics hosts monitoring (splk-mhm) - Get component loads to fail entities due to regression since 2.0.93
Entities fail to be loaded properly for splk-mhm due to the load component librairies evolutions
The component incorreclty attempts to load Outliers KVstore collections, which is not applicable to splk-mhm resulting in failure to load entities when opening the UI
trackme-limited/trackme-report-issues#642 - bug - Data Source monitoring (splk-dsm) - Data Sampling status and enablement should be immediately reflected by the DecisionMaker
When modifying the Data sampling feature enablement, this should be immediately and properly reflected in the DecisionMaker results as well as the TrackMe UI screen.
trackme-limited/trackme-report-issues#645 - bug - REST API - Update endpoints calling the method generic_batch_update will not take into account replacements with empty values, which impacts reset actions such as in splk-dhm/mhm
When calling REST API endpoints for update purposes, TrackMe implements a batch update method to update KVstore records as fast as possible.
This Python method is called generic_batch_update and currently ignores replacement of values by an actual empty value.
However, doing so causes a regression for some specific endpoints such as the reset endpoint for splk-dhm/mhm.
This fix updates the function to call a Python native object method instead to update the records transparently.
trackme-limited/trackme-report-issues#652 - bug - TrackMe logs rotation should ideally be taken into account for Splunk ingest purposes #652
When TrackMe logs are rotated, our props.conf should take into account incremented log.* files
Enhancements, changes and new features:
trackme-limited/trackme-report-issues#636 - enhancement - Splunk SOAR monitoring of Automation Brokers - enhancement of the REST API endpoint access to retrieve the status of the automation brokers to avoid hitting some scenarios where the normal REST API endpoint misses some statuses errors of the brokers #636
The Flex Object tracker use case for SOAR Automation Brokers monitoring allow retieveing and acting when the SOAR Automation Brokers are not in active state
In some edge use cases, the SOAR automation_brokers REST API misses an offline status of the Automation Broker wrongly if the API endpoints is not accessed with some additional arguments in the parameter of the REST API call
trackme-limited/trackme-report-issues#637 - enhancement - Acknowledgements - Safer code to handle unexpected records with no object_category #637
if Ack records are unexpectly created without a valid object_category, the Ack tracker would not handle this issue properly, and would attempt and fail to retrieve the corresponding record in the data collection.
This would lead the tracker to fail expiring non corrupted Ack records.
This evolution ensures that any corruputed record would be purged accordingly, and will avoid the tracker from failing to manage other valid Ack records
trackme-limited/trackme-report-issues#639 - feature - Bulk edit entities - For Data Sources monitoring (splk-dsm), allows to manage Data Sampling via bulk edit
Manage Data sampling actions via bulk edit: enable / disable / run / reset
trackme-limited/trackme-report-issues#640 - enhancement - Bulk edit - Ensures scroll bar would appear if the screen resolution is too low
If the screen resolution is too low, ensure to load the vertical scrolling bar to avoid truncating the bulk edit screen
trackme-limited/trackme-report-issues#643 - enhancement - SOAR Automation Broker active management - Add a safety layer for ignoring typical fields containing secrets in the JSON post response when updating assets, in addtion with existing automated salted fields exclusion #643
When updating SOAR Assets, and when not using a Vault for password management, we must not include secrets when performing the POST call.
TrackMe already automatically excludes fields which have been salted by SOAR, however as an additional safety and to be retro-compatible with older Assets defined, we also exclude typical fields: apikey,api_key,password,auth_token,client_secret
This can be controled at the level of the POST call using the option: assets_update_forbidden_fields
trackme-limited/trackme-report-issues#646 - enhancement - Data Host/Metric host tracking (splk-dsm/mhm) - Behaviour improvements for the reset actions
The reset actions can be used to reset the current knowledge for a given entity when it comes to indexes, sourcetypes for splk-dhm or metric categories for splk-mhm.
The current behaviour can be improved to better cleanup the associated fields with a more consistent approach.
This enhancement also avoids removing the visibility for the entity that was reset until knoweldge is built again.
trackme-limited/trackme-report-issues#647 - enhancement - TrackMe Notable events - automatically parse the anomaly_reason and turn into a list so Splunk can extract it as an mvfield
The anomaly_reason a primordial field in TrackMe which is used by the DecisionMaker to insert all conditions encountered for a given entity, at the lowest level it is a native Python list.
However, when generating TrackMe notable events, the field is turned into a pipe separated string.
To allow automated mv structure extraction in Splunk, the field should rather be turned back into a list in the JSON structure.
trackme-limited/trackme-report-issues#648 - enhancement - SmartStatus - smartstatus_investigations_uc_dsm_latency and smartstatus_investigations_uc_dhm_latency should rather leverage tstats based search to slightly reduce associated costs
When the SmartStatus is executed and when the entity is red for latency reasons, we currently generate a raw search for a full accuracy regarding the latency calculation.
However, these searches can be slightly expensive at high scale for a relative value, in this issue we migrate the generated searches to a tstats based search instead.
trackme-limited/trackme-report-issues#649 - enhancement - SmartStatus alert action - Protect Splunk workload and prevent SmartStatus alert action from being executed more than once per 24 hours per entity
In some circumstances such as if a TrackMe alert was badly setup without leveraging TrackMe’s Ack concepts, or increasing the suppression period, the SmartStatus alert action could be triggered and executed more than wanted, which in turn could affect Splunk workload and generate more activity than required.
In this issue, we introduce a concept that keeps track of the last seen execution per entity, and we will automatically skip the SmartStatus action if the action has been executed in the past 24 hours already.
trackme-limited/trackme-report-issues#651 - enhancement - Add sum and min as calculation methods when missing as selectable options in Outliers configuration and other dropdown in TrackMe’s UI
In Outliers calculation methods configuration (default configuration and per model fine tuning), the sum and min options should be available.
In selectable options parts of drildown selectors such as in Flex Objects, these methods should be available.
trackme-limited/trackme-report-issues#653 - change - Anomaly Outliers detection - Add -15d in selector for period of calculation, change -360d to -365d for consistency when requesting 1 year for the period, reflect the same periods in the configuration screen for default assignment
Add -15d in selectable options
Swtich -360d to -365d for consistency regarding a year of relative period of time for the calculation period
Reflect the same options in the configuration screen for default perod assignment for consistency
trackme-limited/trackme-report-issues#654 - feature - Entities priority management - Add a new priority with critical priority to provide more flexibility in TrackMe entities management
This release introduces a new priority level “critical” for TrackMe entities.
This will provide more flexibility and consistency for customers to leverage various CMDB and logics, and alert with different types of actions depending on the importance of associated entities
trackme-limited/trackme-report-issues#655 - feature - Priority management - Migrate priority management from macro based to a per Virtual Tenant account option for more flexibility
The priority management is being migrated from the macro trackme_default_priority to an easily configurable option per Virtual Tenant account.
Users can now define the default priority at the time of the creation of the Virtual Tenant, or any time in the Configure / Virtual Accounts configuration screen.
This provides a more flexible and more consistent approach to the priority management in TrackMe.
trackme-limited/trackme-report-issues#618 - Feature Request - Alert configuration “trigger on outliers” and “trigger on sampling” behaviour would lead to miss other anomaly reasons
When creating a TrackMe alert, one can select to trigger or not against Outliers, and Sampling. (note: Sampling is splk-dsm only)
However, the current logic can be much improved to also handle use cases where we have a mutli-detection, and we have more than anomaly in addition with Outliers/Sampling.
With this evolution, TrackMe will parse automatically the anomaly_reason as part of the trackmegetcoll output, adds a new field for the count of anomaly_reason, and finally updates the method when creating a new alert.
trackme-limited/trackme-report-issues#656 - change - CIM Compliance trackers (splk-cim) - Licensing restriction increase to 32 trackers for Enterprise Edition customers
We are increasing the max number of CIM Compliance trackers for Enterprise Edition customers from 16 to 32.
Version 2.0.94 - build 1716849152 (27/05/2024)¶
Hint
Splunk 8.1.x and later, Linux, Python3 support only
SHA256: 465a36c35cc9a161218a9b9c7ff14204d8fd896d72878c943277fc9b5664d4ff
Fixed issues:
trackme-limited/trackme-report-issues#626 - bug - SOAR Automation Broker high availability management - update of the broker will reset unexpectly any secrets of the assets for users not using a Password Vault #626
When performing an active update of the automation broker via the Flex Object use case, we perform an update of the Asset configuration via the SOAR API to swtich the broker from A to B.
For users not using a Password Vault, SOAR handles any credential such as an API token, the token is salted in the data.
When performing the REST POST call to the API, we should remove any field in the JSON structure which starts with a “salt:” to avoid resetting this secret unexpectly, or the asset connectivity is lost.
This only applies to internal SOAR secret management, in the sense that SOAR customers using a Password Vault are not affected by this issue.
- trackme-limited/trackme-report-issues#628 - bug - error when clicking on refresh entities in TrackMe UI when looking at a given entity: search_kv_collection() got an unexpected keyword argument #628
Issue happens when clicking on refresh when looking at a given entity
This is a regression introduced in TrackMe 2.0.92
trackme-limited/trackme-report-issues#629 - bug - Adaptive Tresholding - Avoid attempting to take into account during the review a feed that was previously updated but stop indexing to Splunk in the past 7 days #629
When the adaptive threshold backend updates an entity, this entity automatically enters the review phase to ensure we take into account updated behaviours, such as an outage that was resolved in the meantime.
However, if an entity that was previously updated stop indexing data to Splunk, we should not take it into account anymore if it didn’t index any event for the past 7 days to avoid raising an exception while accessing the adaptive_delay result.
trackme-limited/trackme-report-issues#631 - bug - Workload (splk-wlk) - Regression in TrackMe 2.0.93 due to missing fields in lookup transforms leading to status not met instead of advanced status distinction #631
In TrackMe 2.0.93 and to address some CPU & Memory pressure, we have swtiched the base logic to access KVstores to a search based approach.
This impacted the Workload component due to missing fields in the Lookup transforms, which cannot be access in a search unless part of the transform, this had lead to a status not met instead of the detailed statuses.
Once upgraded, the TrackMe health tracker schema upgrade routine will update the lookup transforms accordingly with no action required.
trackme-limited/trackme-report-issues#633 - bug - Outliers detection potential regression in TrackMe 2.0.93 leading to isOutlier not reported at DecisionMaker time
Due to search based approach when accessing KVstore records in TrackMe 2.0.93, in some circumstances it is possible that detected Outliers do not get reported while loading entities.
This issue introduces a robust and consistent approach at the Python level to lookup Outliers, similarly to other phases in the TrackMe Decision Maker.
Enhancements, changes and new features:
trackme-limited/trackme-report-issues#627 - enhancement - trackmehealthtracker - Optimize run time, costs and behaviour of the inspect_collection phases #627
The schedule job trackmehealthtracker is responsible for various maintenance routines, one of these is called “inspect_collection”
This maintenance routine verifies the consistency of TrackMe entities statuses (object_state) between the KVstore record view and the realtime view from TrackMe’s DecisionMaker processes
The TrackMe DecisionMaker process is a suite of many Python functions depending on the time of component which apply conditions for monitoring, such as delay/latency rules, logical group mapping, Outliers detection and so forth
In this issue, we optimized this specific process with a faster and lighter search based approach to load the KVstore raw collection, load the TrackMe DecisionMaker view (using the trackmedecisionmaker streaming custom command) then performing the comparison
The objective of this update is therefore to reduce the costs of this step, reduce the global runtime of the trackmehealthtracker job and avoids generating skipping search
trackme-limited/trackme-report-issues#630 - enhancement - Adaptive Threshold - Avoid attempting to inspect entities that have not actively generated data in Splunk for a minimum period equivalent to the max_delay_sec argument given to the backend #630
For optimization and costs reduction purposes, TrackMe’s adaptive threshold backend should not attempt to inspect entities which are not actively sending data to Splunk.
The current behaviour implies that we may continue to attempt to inspect entities that are monitored actively but without any recent ingest activity (past 7 days)
To improve consistency while reducing TrackMe’s workload, the Adpative Threshold backend should ensure to take into account entities in the initial inspection phase only if the current delay is < max_auto_delay_sec (default to 7 days)
trackme-limited/trackme-report-issues#632 - enhancement - Decomission ML models orphans cleanup from the trackmehealthtracker as it is also handled via the general health tracker #632
In TrackMe 2.0.84 was introduced the general health tracker which is executed once per day amongst all Virtual Tenants.
Especially, this job handles all cleaning related to Machine Learning, such as detecting and purging Orphans models. (models which entities have been purged, or the tenant was purged)
Previously, this activty was handled by the tenant level health tracker, this is not required any longer and we can save from this activity to optimize and reduce TrackMe’s workload.
Version 2.0.93 - build 1716457845 (23/05/2024)¶
Hint
High CPU and Memory pressure regression from TrackMe 2.0.92: this release addresses several important issues leading to extra CPU and memory pressure introduced with TrackMe 2.0.92
SHA256: 9d6d5cd975f6f7fcbb1966b212206f77a414938b5f5b0446a0bded64233f550c
Fixed issues:
trackme-limited/trackme-report-issues#620 - bug - Option sla_default_threshold in sla is not used on purpose and should have been removed from the configuration UI #620
trackme-limited/trackme-report-issues#621 - bug - Virtual Tenants UI - If using legacy TrackMe load mode, this should also apply to automated refresh #621
trackme-limited/trackme-report-issues#622 - bug - Maintenance mode management UI - Web browser over consumption over time due to resources leak with Javascript autorefresh #622
trackme-limited/trackme-report-issues#623 - bug/enhancement - Performance and footprint reduction at high scale (More than 10k/100k collections) - changes introduced in TrackMe 2.0.92 can lead to extra CPU and memory consumption #623
trackme-limited/trackme-report-issues#624 - bug - CIM Compliance tracking (splk-cim) - object_category should be in the collections for consistency purposes regarding all other components, its lack currently impact notables and acknowledgement #624
trackme-limited/trackme-report-issues#625 - bug - CIM Compliance tracking - When creating a notable or SLA alert, components alert actions are wrongly added to the alert #625
Version 2.0.92 - build 1715771041 (15/05/2024)¶
Hint
Splunk 8.1.x and later, Linux, Python3 support only
SHA256: 800d2adbf600d31124558b3dff4104bc3bb41e405365c284077ddc1500e38864
Fixed issues:
trackme-limited/trackme-report-issues#617 - bug - Regression with the usage of numpy which impacts schedule logic where we limit their run time - due to an Appinspect restriction and numpy storing libs in a hidden directory which was removed automatically by our automation, this leads to the custom command to fail at exec time #617
Version 2.0.91 - build 1715725834 (14/05/2024)¶
Hint
Splunk 8.1.x and later, Linux, Python3 support only
SHA256: 0d41329cd50ed1531b4548ff0e7136b293dec45f25eec57993b315ad5aa0e6ee
Fixed issues:
trackme-limited/trackme-report-issues#601 - bug - Logical Group REST API - avoid raising an exception when groups members, or green / red members are unexpectly null #601
trackme-limited/trackme-report-issues#603 - bug - Prevents an exception in the REST API endpoint post_component_summary_update which is responsible for caching the tenant and component statistics #603
trackme-limited/trackme-report-issues#604 - bug - Missing searchbnf providing usage syntax for the custom command trackmesplkpriority #604
trackme-limited/trackme-report-issues#605 - bug - Priority Policies apply in TrackMe UI - incorrect variable leads to slient failure while applying policies for other components than splk-dsm #605
trackme-limited/trackme-report-issues#608 - bug - Logical Groups - Unexpected non list structured in object_group_members / object_group_members_green / object_group_members_red can lead to Python exceptions and to the related entities not be available in the UI or from trackmegetcoll #608
trackme-limited/trackme-report-issues#609 - bug - Data Hosts tracking (splk-dhm) - At high scale collection (more than 10k hosts), the current pagination count per count leads to incomplete rendering of entities #609
Enhancement, changes and new features:
trackme-limited/trackme-report-issues#597 - enhancement - Adaptive Threshold tracker for Data Sources / Data Host tracking - The recent activty instrospection should take into account a change of the allow_adaptive field in case it has changed after the entity entered the cycle of adaptive review #597
trackme-limited/trackme-report-issues#598 - feature request - Implement a per entity SLA timer and threshold concept, this would be used in a 2 tiers alerting system when a specifc alert would be sent when the SLA of entity is breached after having spent too long in a red state #598
trackme-limited/trackme-report-issues#606 - change - Virtual Tenants UI - entities summary while double clicking on a given tenant should specify “enabled entities” rather than simply “entities” to avoid any confusion #606
trackme-limited/trackme-report-issues#610 - change - Adaptive Treshold tracker - At the creation phase, the Adaptive Treshold tracker should be executed every 20 minutes to avoid risks of generating skipping searches at high scale #610
trackme-limited/trackme-report-issues#611 - enhancement - Improving TrackMe logic to avoid generating skipping searches in various TrackMe scheduled logics #611
trackme-limited/trackme-report-issues#612 - feature - TrackMe Alerting Architecture - Allows creating TrackMe Notables from TrackMe UI, Add builtin documentations and design good practices #612
trackme-limited/trackme-report-issues#613 - change - REST API - bulk edit endpoints update to verify if json_data is submitted as a string, and if so loads it as a dict #613
trackme-limited/trackme-report-issues#614 - enhancement - Persistent fields - centralization of per component persistent fields in collection_dict.py for more consistent and safer code #614
trackme-limited/trackme-report-issues#615 - feature - Flex Object Library - Add a new use case to track the daily volume of data ingested per day and per index, and leverage Machine Learning for the Outlers detection #615
trackme-limited/trackme-report-issues#616 - feature - Bulk Edit performance - Massive improvement in bulk edit performance in TrackMe, bulkd edit now runs in a fraction of seconds no matter the volume of the collection #616
Version 2.0.90 - build 1714432454 (30/04/2024)¶
Hint
Splunk 8.1.x and later, Linux, Python3 support only
SHA256: a0d0360ae77c807bc991fa960580675860a4e75828e6b55f08bf5cd70d97e1b2
Fixed issues:
trackme-limited/trackme-report-issues#584 - bug - New ctime field is not persistent in some components (dsm, wlk) #584
trackme-limited/trackme-report-issues#593 - bug - Data Hosts tracking / Metric Hosts tracking - error message trackmeextractsplkmhm/trackmeextractsplkdhm when the command is executed in no metric generation mode #593
trackme-limited/trackme-report-issues#595 - bug - Data Source / Data host tracking (splk-dsm/splk-dhm) Persistence of fields issue when the Adaptive tracker runs due to some Python level issues with batch update related code in the specific circumstances of sending a partial update #595
Enhanccements, changes and new features:
trackme-limited/trackme-report-issues#585 - feature - priority management - provide a component wide feature for priority dynamic managements using regex based policies #585
trackme-limited/trackme-report-issues#587 - enhancement - Virtual Tenants - Load Tenants high level statistics available when double clicking on the tenant flex box from cachedstats for consistency and better performance at high scale #587
trackme-limited/trackme-report-issues#588 - enhancement - Virtual Tenants UI - Add a configuration choice for the trackmeload mode (REST versus legacy search driven) to address some limited compatibility issues reported by FEDRAMP Classic Splunk Cloud #588
trackme-limited/trackme-report-issues#589 - feature - Machine Learning engine - Add capabilities to define static static_lower_threshold / static_upper_threshold per model #589
trackme-limited/trackme-report-issues#590 - change - Data Hosts tracking (splk-dhm) - presets tstats root span to 1m by default #590
trackme-limited/trackme-report-issues#591 - feature - Virtual Tenants creation UI - Allow in the first steps to define tenants level settings (ML Outliers features and other main Tenants level optons) #591
trackme-limited/trackme-report-issues#592 - feature - Virtual Tenants - Allows to control the enablement of TrackMe Machine Learning Outliers Anomaly detection at the level of the Virtual Tenant #592
trackme-limited/trackme-report-issues#596 - enhancement - Machine Learning - Avoids the error “The ML search is not yet available for rendering” when the ML model is not yet ready for rendering #596
Version 2.0.89 - build 1713898383 (23/04/2024)¶
Hint
Splunk 8.1.x and later, Linux, Python3 support only
SHA256: d7a561e975b0ddfa4c1ee423c7e7eef7f59f339c6d1ee415112ca89cb1a2ec47
Fixed issues:
trackme-limited/trackme-report-issues#562 - bug - REST API - Maintenance mode disable endpoint should return a native JSON response rather than a JSON dumped response #562
trackme-limited/trackme-report-issues#563 - bug - REST API - fix various documentation errors in TrackMe’s REST API endpoints #563
trackme-limited/trackme-report-issues#566 - bug - Machine Learning - perc_min_lowerbound_deviation in repeated twice in dsm Outliers table management, min_value_for_lowerbound_breached/min_value_for_upperbound_breached are missing from dhm tables #566
trackme-limited/trackme-report-issues#569 - bug - DecisionMaker - Prevents against various possibilities of Python exceptions in the TrackMe Decision Maker libraries and calls which can lead to Error processing record #569
trackme-limited/trackme-report-issues#570 - bug - Logical Groups - Ensure to limit match=1 for logical grouping enrichment at search time before reaching the DecisionMaker #570
trackme-limited/trackme-report-issues#571 - bug - Backup and Restore - Builtin TrackMe KVstore backup fails when there are disabled tenants #571
trackme-limited/trackme-report-issues#576 - bug - CIM (splk-cim) - SLA metrics are not generated if the trackme_metric index has been customised #576
trackme-limited/trackme-report-issues#579 - bug - Machine Learning - ML Model addition UI in some components would not render a result when simulating the addition of the model as the command should call the lightsimulation mode rather than the simulation mode since TrackMe 2.0.88 #579
trackme-limited/trackme-report-issues#580 - bug - Machine Learning - custom command trackmesplkoutlierssetrules generates errors when dealing with Flex Object trackers with no Outliers definition #580
Enhancements, changes and new features:
trackme-limited/trackme-report-issues#557 - feature - Flex Object library use cases - Add new UCs for detecting abnormal drop in Splunk feeds events count using Flex #557
trackme-limited/trackme-report-issues#558 - feature - Machine Learning Outliers - Allows up to 1 year in the time range selection for the Outliers calculation by step of 30 days #558
trackme-limited/trackme-report-issues#559 - feature - Machine Learning Outliers - Add max in calculation methods available #559
trackme-limited/trackme-report-issues#560 - feature - Machine Learning Outliers - Flex Object - Support all settings to be defined per Flex Object tracker rule, update built in documentation #560
trackme-limited/trackme-report-issues#564 - enhancements - REST API - When deleting entities, permanently or temporary, the API should also clean up records for Outliers and Sampling, if any. #564
trackme-limited/trackme-report-issues#565 - feature - New immutable KVstore field called ctime in TrackMe main KVstore component collections to keep track of entities origin creation time #565
trackme-limited/trackme-report-issues#567 - enhancement - Virtual Tenants UI - When defining custom indexes as default indexes, the new Virtual Tenant creation UI should preset indexes with corresponding default indexes #567
trackme-limited/trackme-report-issues#568 - enhancement - Workload (splk-wlk) - SmartStatus searches code improvements, ensure to include host=* splunk_server=* in SmartStatus Workload searches, more consistent searches matching the trackers, code improvements #568
trackme-limited/trackme-report-issues#572 - feature - Data Host tracking (splk-dhm) - Add the capability to exclude (blocklist) a list of indexes and/or sourcetypes per host #572
trackme-limited/trackme-report-issues#573 - feature - Machine Learning Outliers - Allow pre-defining at the system level extra parameters for the MLTK fit command, which can also be defined on a per model basis #573
trackme-limited/trackme-report-issues#575 - enhancement - User Interface Home - ensure the main entity modification screens use scroll bar if the screen resolution is too low #575
trackme-limited/trackme-report-issues#577 - feature - Machine Learning Outliers - allow using a custom MLTK algorithm #577
trackme-limited/trackme-report-issues#581 - enhancement - Add an additional numerical verification in the Python function trackme_components_register_gen_metrics to prevents from any risks of generating malformed metrics leading to Splunk notification #581
Version 2.0.88 - build 1712331711 (05/04/2024)¶
Hint
Splunk 8.1.x and later, Linux, Python3 support only
SHA256: 70b5d340687c3e45d3702b1c4ce84e8cb6edb7a866fba75915c4de3cdafff8db
Fixed issues:
trackme-limited/trackme-report-issues#550 - feature - Home interface drilldown & notable drilldown link - Allows submitting an object or alias URL param which filters out and opens automatically the entity overview, also add a drilldown_link to TrackMe Notables #550
trackme-limited/trackme-report-issues#552 - bug - Virtual Tenant UI - count discrepency in summarized stats due to the monitoring enablement not being taken into account #552
trackme-limited/trackme-report-issues#553 - bug - Python shared functions - get_kv_collection function used in some backends can lead to the generation of error messages with document ID conflict #553
trackme-limited/trackme-report-issues#553 - bug - Python shared functions - get_kv_collection function used in some backends can lead to the generation of error messages with document ID conflict #553
trackme-limited/trackme-report-issues#554 - bug - Data Source tracking - trackmesplktags does not implement batch_save leading to potentially increased run time #554
trackme-limited/trackme-report-issues#555 - bug - TrackMe UI - Entities filtering functions do not properly take into account the show Enabled True/False dropdown #555
trackme-limited/trackme-report-issues#556 - bug - Flex Object UC - SOAR Services monitoring - non reachable SOAR shoudl lead to services being red immediately #556
Enhancements, changes and new features:
trackme-limited/trackme-report-issues#550 - feature - Home interface drilldown & notable drilldown link - Allows submitting an object or alias URL param which filters out and opens automatically the entity overview, also add a drilldown_link to TrackMe Notables #550
Version 2.0.87 - build 1711995624 (01/04/2024)¶
SHA256: 40e3bd2e52eed4c5e27e62b6e6386d13264284f65ac91a8cf61ebc6db8e9914b
High performance for high scale collections in TrackMe with pagination, server side filtering, KVstore batch_find & Tabulator theming
This release introduces massive performance improvements in TrackMe, allowing notably high scale collections to be managed with ease.
REST API Pagination- With TrackMe REST pagination capabilities and Tabulator capabilities, TrackMe can handle any number of entities in a collection without any performance degradation, allowing to deal with large collections of more than 100K entities.Server side REST filtering- TrackMe and the Tabulator now perform server side REST level filtering, this slightly optimises response time while filtering for entities with simple or complex filters even when working with very large collections.Server side stats caching- TrackMe now caches tenants and components statistics at the server level, allowing it to retrieve the stats in a fraction of the time it used to take.Python native implementation for the Decision Maker and filter handling- From this release, TrackMe handles entirely the Decision Maker phases and filtering handling in Python, without involving any Splunk searches, allowing to largely optimise the performance of these operations.Background Python threading- TrackMe also uses background side Python threading methods to maintain cached statistics, allowing to largely optimise performance run time of these operations and slightly reducing the usage of search slots in TrackMe.KVstore batch_find and batch_update implementation- This release also implements KVstore batch_find and batch_update for all user side interactions, allowing all entities update actions such as bulk edits or per entity/feature edit (priority update, etc) to take a fraction of the time it used to take in previous releases, no matters the number of entities in the collection.Massive UI side performance improvements- All these changes are reflected in TrackMe’s UI by major reduction of load time, major reduction of the response time during entity updates, and globally slightly enhanced response times in TrackMe.Tabulator theming- This release also introduces new capabilities to update at the system and user level the look and feel of the Tabulator, allowing users to choose between 5 different themes, at the system and user level. (Dark Site, Dark, Light Site, Light, Light Modern)
Fixed issues:
trackme-limited/trackme-report-issues#525 - bug - Data Hosts / Metric Hosts tracking (splk-dhm/splk-mhm) - Allow list KV transforms definitions are lacking the is_rex field, this will be corrected automatically with TrackMe’s schema upgrade #525
trackme-limited/trackme-report-issues#539 - bug - Data Source tracking (splk-dsm) - Allow Adaptive Delay field persistence is not honoured by hybrid trackers #539
Enhancements, changes and new features:
trackme-limited/trackme-report-issues#505 - feature - Filter for acknowledgement comment content in main dashboard #505
trackme-limited/trackme-report-issues#520 - feature - Implement systematic pagination mechanisms at the TrackMe’s REST API level for high scale collections performance, implement server REST side filtering for high performance #520
trackme-limited/trackme-report-issues#522 - change - Tabulator JS - Upgrade to version 6.1 #522
trackme-limited/trackme-report-issues#523 - enhancement - Docs references feature for splk-dsm - Allows robust system wide default parameters, decomission related knowledge objects #523
trackme-limited/trackme-report-issues#524 - feature - REST API TrackMe - Support for params GET based endpoints #524
trackme-limited/trackme-report-issues#526 - enhancement - Blocklists for Feeds tracking (splk-dsm/dhm/mhm) - Allows the alias in addition with the object to choosen as the field to apply the blocklists against, code improvements #526
trackme-limited/trackme-report-issues#534 - change - Decomission of the DataGen concepts replaced with more meaningful blocklist concepts for Feeds tracking #534
trackme-limited/trackme-report-issues#535 - change - Splunk Python SDK 2.0.0 - deprecation explicit lib is required #535
trackme-limited/trackme-report-issues#536 - enhancement - Dependencies verification - Add the Splunk Scientific package in dependencies verifications #536
trackme-limited/trackme-report-issues#540 - enhancement - Data Sources tracking (splk-dsm) - Manual tags refreshed UI, new management endpoints and enhanced workflow #540
trackme-limited/trackme-report-issues#541 - enhancement - REST API endpoints performance optimization - Implement KVstore batch_find and optimize all actions for much faster performances in REST API calls #541
trackme-limited/trackme-report-issues#542 - enhancement - Tags policies tracker for Data Sources tracking (splk-dsm) - Immediately apply tags against the data collection in a batch_save manner for optimial performances and behaviour #542
trackme-limited/trackme-report-issues#543 - feature - TrackMe’s Vtenant UI and Home Tenants themes for Tabulator - Allow to define at the system and user level between 5 Tabulator theme (Dark Site, Dark, Light Site, Light, Light Modern) #543
trackme-limited/trackme-report-issues#545 - change - Machine Learning models management - Ensures privately owned TrackMe ML models from the splunks-system-user are excluded from the Knowledge Bundle replication #545
trackme-limited/trackme-report-issues#546 - change - Python and Splunk SDK 2.0.x - remove outdated or non necessary imports #546
trackme-limited/trackme-report-issues#547 - change - trackmetenantstatus custom command - log in warning rather than error when there is not yet activity registered for a newly created tenant #547
trackme-limited/trackme-report-issues#548 - enhancement - Maintenance mode & Maintenance Knowledge Database - Better handle user local time and show the local time information properly #548
Version 2.0.86 - build 1710525022 (15/03/2024)¶
Hint
Splunk 8.1.x and later, Linux, Python3 support only
SHA256: 30cc9a93c821b1d772b55ff8ed89aa4ba40de9394409b4792d9f8890c7d9d512
Fixed issues:
trackme-limited/trackme-report-issues#529 - bug - Data Hosts tracking (splk-dhm) - Bulk edit for Ack enablement does not honour Ack expiration and type dropdowns (only affects this component) #529
trackme-limited/trackme-report-issues#530 - bug - Data Sources tracking (splk-dsm) - Tags policies update through the UI breaks the policies structure #530
trackme-limited/trackme-report-issues#531 - bug - Python function for central searching in Splunk - preview must be set to false or results may appear to be duplicated #531
trackme-limited/trackme-report-issues#532 - bug - TrackMe performance counters for Trackers report inaccurate measures (trackmetrackerexecutor) #532
Version 2.0.85 - build 1710194416 (11/03/2024)¶
Hint
Splunk 8.1.x and later, Linux, Python3 support only
SHA256: f79ca52d8eed0b4d8db4fad80373c4ea079aeae1ddb8cfd1bbf61cb1b5de0744
Fixed issues:
trackme-limited/trackme-report-issues#527 - bug - splunkremovesearch - The local account should not be accounted against the license restriction (legacy Free Community edition, now Foundation Edition trial, 1 remote account should be granted) #527
trackme-limited/trackme-report-issues#528 - bug - Data Sources tracking (splk-dsm) - TrackMe REST API will not accept global_dcount_host as the min_dcount_field value #528
trackme-limited/trackme-report-issues#521 - bug - Trackers and Licensing - If the user calls a tracker with “_tracker” part of its name, other reports (abstract, wrapper) are wrongly accounted against the license #521
Version 2.0.84 - build 1709505402 (03/03/2024)¶
Hint
Splunk 8.1.x and later, Linux, Python3 support only
Schema upgrade for TrackMe version 2.0.84
This release includes a TrackMe schema upgrade which will automatically clean Outliers orphan records and orphan ML models.
The schema upgrade is executed within the next 5 minutes after the upgrade, through the tenant’s health tracker jobs.
If there is a large amount of orphan models to be cleaned up, this can temporarily increase generate skipping searches for the health tracker as its execution would eventually take much longer than usual.
After this, the health tracker will resume its normal execution and skipping searches for it will disappear.
This process is fully automated, and there are no intervention required.
Schema upgrade issues for jump from old releases of TrackMe v2.0.x
Different issues where addressed in this release to properly support migrating from very old versions of TrackMe v2.0.x. to this release.
You can therefore safety migrate from any earlier version of TrackMe v2.0.x without expected issues.
SHA256: 425ce2d470ec072f17289eedccbb94ce87115c5a063e92af4998a39ff4ed27da
Fixed issues:
trackme-limited/trackme-report-issues#474 - bug - Workload (splk-wlk) - diff_search and other related deleted modification fields are not preserved in the KVstore record in other iterations of the metadata job (but preserved as indexed events, however). #474
trackme-limited/trackme-report-issues#476 - bug - Alert action - The label is incorrect on the type of Ack for the TrackMe auto Ack action. #476
trackme-limited/trackme-report-issues#482 - bug - Flex Library - The lastchanceindex object name should not include the current prefix. #482
trackme-limited/trackme-report-issues#483 - bug - Flex Library - Cribl Logstream destination pressure UC should take into account yellow state metrics (value: 1) as well as green/red metrics. #483
trackme-limited/trackme-report-issues#485 - bug - Hybrid Trackers - Creation via REST API endpoints should mirror UI default False options for break by host/splunk_server. #485
trackme-limited/trackme-report-issues#486 - bug - Virtual Tenant UI - Overview duplicates entities in red state. #486
trackme-limited/trackme-report-issues#489 - bug - Machine Learning models update screen - Depending on the component, the list of metrics is incorrect or incomplete, for Flex Objects, a free text update capability is required. #489
trackme-limited/trackme-report-issues#492 - bug - Adaptive Thresholds for Data Sources (splk-dsm) - Error in the formula for review over time logic when defining the average of the 3 KPIs over 30d/7d/24h. #492
trackme-limited/trackme-report-issues#494 - bug - Adaptive threshold (splk-dsm/splk-dhm) - The Adaptive threshold does not parse the pipe-delimited nature of anomaly_reason properly, thus it ignores entities affected by delay breached in addition to any other anomaly. #494
trackme-limited/trackme-report-issues#497 - bug - Tenants Knowledge Objects permissions issue with Schema Upgrade - Read and Write permissions were inverted in the Schema upgrade in recent versions using standardized libs to manipulate KOs, this leads to created objects during the schema upgrade to eventually define inconsistent permissions. This update fixes it and also automatically fixes any existing tenant. #497
trackme-limited/trackme-report-issues#500 - bug - Reject/remove special or unprintable characters when automatically adding newly discovered sources to TrackMe. #500
trackme-limited/trackme-report-issues#501 - bug - Workload (splk-wlm) - Discrepancy and remaining issues when searches contain non-unicode or foreign characters. #501
trackme-limited/trackme-report-issues#502 - bug - Data Host tracking (splk-dhm) - In some conditions, all sourcetypes red should be overridden by global host level thresholds (host shows red, should show green). #502
trackme-limited/trackme-report-issues#504 - bug - Add quotes for object token in the dashboard “Adaptive delay threshold audit.” #504
trackme-limited/trackme-report-issues#508 - bug - Data Sources (splk-dsm) - Permanent entity deletion via the dedicated button through the modification screen performs a temporary deletion instead (but bulk permanent deletion works as expected). #508
trackme-limited/trackme-report-issues#511 - bug - Virtual Tenants creation can fail during the upgrade process from an old enough version of TrackMe V2. #511
trackme-limited/trackme-report-issues#518 - bug - REST API documentation - A few REST API endpoints incorrectly set the root uri (admin/write) for the resource_spl_example value #518
Enhancements, changes, and new features:
trackme-limited/trackme-report-issues#472 - enhancement - Virtual Tenants - Major performance improvements in the loading time of the UI by avoiding a slot search to get TrackMe tenants in pure Python. #472
trackme-limited/trackme-report-issues#475 - enhancement - Python backend search framework - A consistent and centralized approach to programmatic Pythonic searching in Splunk. #475
trackme-limited/trackme-report-issues#477 - enhancement - Flex Library - Performance runtime improvements for the use case splk_license_usage_per_index. #477
trackme-limited/trackme-report-issues#478 - bug - Flex Library - Wrong outlier metric name in OOTB use case cribl_logstream_pipeline. #478
trackme-limited/trackme-report-issues#480 - enhancement - Flex Library - Queues filling use case set max_inactive_sec to 0, which is now allowed by splk-flx. #480
trackme-limited/trackme-report-issues#481 - change - Alert naming default - Remove “custom on” from the alert default name in the input alert name. #481
trackme-limited/trackme-report-issues#488 - feature request - Data Source tracking (splk-dsm) - Generate and ingest a global dcount host metrics that is not driven by the ingest and is closer to a simple dcount host. #488
trackme-limited/trackme-report-issues#491 - feature - Flex Objects (splk-flx) - New use cases for Splunk Search Head Clusters (SHC) infrastructure monitoring. #491
trackme-limited/trackme-report-issues#493 - feature request - Filter option for acknowledged entities. #493
trackme-limited/trackme-report-issues#495 - enhancement - Adaptive Threshold for Feeds tracking (splk-dsm/splk-dhm) - Use max_auto_delay_sec in case the calculated threshold is higher than max_auto_delay_sec. #495
trackme-limited/trackme-report-issues#496 - enhancement - PersistentFields command (KVstore batch update process) - For splk-dsm/splk-dhm, reject a KVstore record update request if the current KVstore value for data_last_time_seen is bigger than the upstream value from the tracker run. #496
trackme-limited/trackme-report-issues#498 - feature - Data Sources tracking (splk-dsm) - Tags management - Major improvements to the tags policies for splk-dsm: Allow multi-match tags policies, new dedicated Python backend replacing the previous SPL native logic, enhanced UI elements for tags, enhancements tags policies management UI. #498
trackme-limited/trackme-report-issues#499 - feature - Flex Objects / Workload (splk-flx/splk-wlk) - Allows more flexibility for charting type and mode selection in Flex Objects and Workload. #499
trackme-limited/trackme-report-issues#506 - Feature - Entities in blue state show as alert in dashboard. #506
trackme-limited/trackme-report-issues#509 - change - Virtual Tenants wizard - Disable splk-dhm/splk-dhm components by default unless requested. #509
trackme-limited/trackme-report-issues#512 - feature - Outliers engine - New automated training feature, this allows automatically performing an ML model train operation when the backend attempts to render an out-of-date ML model to avoid false positives. #512
trackme-limited/trackme-report-issues#514 - Bulk Acknowledgement unified for all components (Allows bulk Ack with expiration selection similarly to splk-dsm). #514
trackme-limited/trackme-report-issues#515 - change - Tags for Data Sources (splk-dsm) - Include tags as part of minimal events indexed with trackme:state events by default #515
trackme-limited/trackme-report-issues#516 - feature - Bulk actions - Provide various bulk actions capabilities for Outliers management (reset Outliers status, enable/disable Outliers detection, run mltrain / mlmonitor) #516
trackme-limited/trackme-report-issues#517 - change - Logging - Outliers error message “The ML search is not yet available for rendering” should be rendered as warning rather than errors #517
Version 2.0.83 - build 1706721363 (31/01/2024)¶
Hint
Splunk 8.1.x and later, Linux, Python3 support only
SHA256: 7348149f074e719719bce7cad50c1861ee1c46646b03b1bd1294726c07924e92
Fixed issues:
trackme-limited/trackme-report-issues#451 - bug - Hybrid Trackers / Flex Object trackers - latest_time is not used during tracker creation #451
trackme-limited/trackme-report-issues#456 - bug - Logical Group - object is red even though logical group has sufficient green members #456
trackme-limited/trackme-report-issues#459 - bug - Decision Maker - If both out of monitoring days and monitoring hours are True, a dplicated message is generated in status_message and status_message_json #459
trackme-limited/trackme-report-issues#461 - bug - User Interface - In some conditions, the status message screen may not allow access to the footer management buttons due to the timeline component #461
trackme-limited/trackme-report-issues#462 - bug - Data Hosts tracking (splk-dhm) - Outliers status should be looked up before the Decision Maker is called for the anomaly_reason and status_message to be reflected in the KVstore (which however has no impact on the detection) #462
trackme-limited/trackme-report-issues#465 - bug - Data Hosts tracking (splk-dhm) - outliers_readiness is not preserved while running DHM trackers, leading the ML screen to display ML not ready message altrhough ML is actually ready #465
Enhancements, changes and new features:
trackme-limited/trackme-report-issues#457 - feature - Virtual Tenant - Introducing a tenant alias concept, this allow assigning an alias per tenant which can be updated via the Configure UI, this value is now used in the Virtual Tenant UI rather than the tenant_id which is immutable #457
trackme-limited/trackme-report-issues#458 - feature - Logical Groups - Extend Logical Groups to Flex Object (splk-flx) #458
trackme-limited/trackme-report-issues#460 - enhancement - Logical Groups - Major rewrite of the backend management for Logical Groups which is now full taken in charge by the Decision Maker, we also automatically detect and purge orphans logical group members (via the health tracker), major improvements and immediate change reflection via the Decision Maker #460
trackme-limited/trackme-report-issues#463 - enhancement - SmartStatus - Extend SmartStatus to Flex Object, various improvements to the SmartStatus backend for automatic search retry, improved search management and search use cases for all components, more consistent approach with normalized ML UC #463
trackme-limited/trackme-report-issues#464 - enhancement - Virtual Tenants UI - show/hide spinner while loading tenant’s knowledge objects until API call is over #464
trackme-limited/trackme-report-issues#466 - change - Virtual Tenants UI - Disable by default the splk-mhm when creating a new feeds tenant, unless instructed otherwise in the wizard #466
trackme-limited/trackme-report-issues#467 - enhancements - Flex Objects (splk-flx) - Improving inline documentation and added max_sec_inactive as well as time_factor in ML models generation #467
trackme-limited/trackme-report-issues#468 - enhancement - Flex Object library (splk-flx) - Improving the Splunk DMA builtin use case #468
trackme-limited/trackme-report-issues#469 - enhancement - Flex Object (splk-flx) - Allowing a max_sec_inactive = 0 to disable automated red trigger based on detected inactivity #469
trackme-limited/trackme-report-issues#470 - feature - Logical Groups - Add new management screen allowing to add / update / delete Logical Groups with easier access and management #470
trackme-limited/trackme-report-issues#471 - feature - Health Tracker - Implement a new context called inspect_collection which ensures that object statuses in KVstore collections are always consistent with the Decision Maker, this also addresses some specific use case where there could be an inconsistent object_state in the KVstore collection #471
Version 2.0.82 - build 1705991568 (23/01/2024)¶
Hint
Splunk 8.1.x and later, Linux, Python3 support only
SHA256: c7b039911bf8f9506096b5b1b03f98edf9a53d6ea0d4b7f22edfc68e80b66935
Fixed issues:*
trackme-limited/trackme-report-issues#452 - bug - Adaptive delay audit dashboard - remaining typo and dead link in the navigation menu #452
trackme-limited/trackme-report-issues#453 - bug - Maintenance mode & Maintenance Knowledge DataBase - Prevents failure to load the Knowledge DataBase UI when the maintenance mode was enabled through a REST call #453
trackme-limited/trackme-report-issues#454 - bug - Maintenance mode & Maintenance Knowledge DataBase - Retro-compatbility for older version of Firefox due to issues with the datetime-local input selector #454
Enhancement, changes and new features:
trackme-limited/trackme-report-issues#455 - enhancement - Splunk Remote Search - Improve logging and error handling when testing / configuration / using Splunk Remote Search in TrackMe #455
Version 2.0.81 - build 1705906378 (22/01/2024)¶
Hint
Splunk 8.1.x and later, Linux, Python3 support only
SHA256: 3c33e18c7fb3920523eebaf795dfb02c9f80220292353ed6fc99f8d44c5b452d
Fixed issues:
trackme-limited/trackme-report-issues#447 - bug - Typo in the new adjustements dashboard for Adaptive audit #447
Enhancement, changes and new features:
trackme-limited/trackme-report-issues#448 - enhancement - Adaptive delay adjustment audit dashboard user experience improvements #448
trackme-limited/trackme-report-issues#449 - enhancement - Acknowledgment management REST API endpoints - code and behaviour enhancements, allows listing all Ack, better management and new API endpoint for the UI purposes #449
trackme-limited/trackme-report-issues#450 - enhancement - UI Acknowledgement - Enhanced Ack management screen relying on direct REST integration for faster and richer user experience #450
Version 2.0.80 - build 1705650542 (19/01/2024)¶
Hint
Splunk 8.1.x and later, Linux, Python3 support only
SHA256: 06bba3369ad7fa358e026bcbec3bc7e604b20cc47e648308b63ad1944d9fc0b3
Fixed issues:
trackme-limited/trackme-report-issues#446 - change - Splunk Base failure to properly initiate Appinspect vetting request #446
Version 2.0.79 - build 1705620290 (18/01/2024)¶
Hint
Splunk 8.1.x and later, Linux, Python3 support only
SHA256: bf29cb3fe4d65e1decbb958dfe2b32c625a3950ed58d2e38fadb4dc3bb9b2cd5
Fixed issues:
trackme-limited/trackme-report-issues#439 - bug - Logging system - missing log_level search time extraction for alert actions logs #439
trackme-limited/trackme-report-issues#440 - bug - Bulk edit Acknowledgment - The Ack period selected is interpreted in seconds instead of days when doing Ack through Bulk editing #440
trackme-limited/trackme-report-issues#441 - bug - Acknowledgement backend logging - Avoid improperly generating the message “no object state information could be retrieved” #441
trackme-limited/trackme-report-issues#442 - bug/enhancement - Decision Maker for Data Hosts tracking (splk-dhm) - logic adjustementfor entity level thresholds management #442
Enhancements, changes and new features:
trackme-limited/trackme-report-issues#437 - Feature request - Allow to define if automated acknowledgements should be sticky or unsticky within TrackMe’s builtin alert action #437
trackme-limited/trackme-report-issues#438 - enhancement - Flex Object Library - Last Chance Index use case improvements #438
trackme-limited/trackme-report-issues#443 - feature request - Data Source monitoring (splk-dsm) - Overview chart series selection improvements to allow more choices and alertnatively hide the delay and/or latency series #443
trackme-limited/trackme-report-issues#444 - feature - Adaptive Threshold - Adding a new Audit dashboard focusing on reviewing the adjustments made by TrackMe #444
trackme-limited/trackme-report-issues#445 - enhancement - Logging backend - Retrieve report and macros details and log them before attempting to delete knowledge objects when requested to do so #445
Version 2.0.78 - build 1705310134 (14/01/2024)¶
Hint
Splunk 8.1.x and later, Linux, Python3 support only
SHA256: 71ae1311bc9fc6bd87b01f60da8b80c727094766d9c92fc9f0b8a8769eac7bd6
Fixed issues:
trackme-limited/trackme-report-issues#429 - bug - Adaptive Delay backend - prevent UnboundLocalError errors when mstats returned no results in some conditions #429
trackme-limited/trackme-report-issues#430 - bug - trackmepersistentfields (TrackMe persistent fields) - prevent exception message=”could not convert string to float: “ if tracker_runtime is unexpectly empty #430
trackme-limited/trackme-report-issues#431 - bug - Cribl Logstream Flex Object use cases for inputs and outputs health check should take into account green/yellow/red returns from Cribl #431
trackme-limited/trackme-report-issues#432 - bug - Data Hosts/Metric Hosts (splk-dsm/splk-mhm) - Avoid error “gen_metrics” failed with exception ‘NoneType’ object has no attribute ‘get’ #432
trackme-limited/trackme-report-issues#435 - bug - Adaptive Delay (Data Sources / Data Hosts tracking - splk-dsm/splk-dhm) - TrackMe does not honour properly allow_adaptive_delay #435
trackme-limited/trackme-report-issues#436 - enhancement - Adaptive Delay (splk-dsm/splk-dhm) - Improved logic and logging for the management of ML based adaptive delay tresholding #436
Enhancements, changes and new features:
trackme-limited/trackme-report-issues#433 - enhancement - Flex Object Library - Splunk Queues filling use case review and improvements #433
trackme-limited/trackme-report-issues#434 - feature - Flex Object Library - New use case for Splunk Search Heads key activity tracking #434
Version 2.0.77 - build 1704838956 (09/01/2024)¶
Hint
Splunk 8.1.x and later, Linux, Python3 support only
SHA256: fe1d3723cd2a091781a71992b13255884275170ee8d23b5b22f9b2ca6e375706
Fixed issues:
trackme-limited/trackme-report-issues#425 - bug - Workload / Flex Objects - muliselect dropdown should automatically refresh when the time range is changed #425
trackme-limited/trackme-report-issues#428 - bug - Decision Maker - regression with custom wdays / hours ranges parameters not properly taken into account #428
Enhancements, changes and new features:
trackme-limited/trackme-report-issues#392 - enhancement - Future data detection - Take into account a negative latency as a likely data in the future use case and turn entity orange as expected when future detection is operated against _time #392
trackme-limited/trackme-report-issues#423 - enhancement - Status message improvements with a new native JSON structure and enhanced viz mode #423
trackme-limited/trackme-report-issues#424 - enhancement - CIM compliance - extend week days & hours ranges concepts to CIM compliance tracking #424
trackme-limited/trackme-report-issues#426 - enhancement - Cribl Logstream - Flex Object library use cases improvements, enhanced syntax and improved logic, better use ML Outliers rather than basic thresholds for some of the use cases, globally improved use cases #426
trackme-limited/trackme-report-issues#427 - enhancement - Flex Object library - review use case splk_splunk_cloud_svc_usage_by_app and base threshold on ML Outliers #427
Version 2.0.76 - build 1704492296 (05/01/2024)¶
Hint
Splunk 8.1.x and later, Linux, Python3 support only
SHA256: d6c01dc0e902605422c7375cc920172e01595d3f44689fb5f8cc8e03d0dc117f
Fixed issues:
trackme-limited/trackme-report-issues#422 - bug - Decision Maker - regression when red on outliers or red on sampling is turned off on the tenant but an an actual outliers or sampling alert is active #422
Version 2.0.75 - build 1704475839 (05/01/2024)¶
Hint
Splunk 8.1.x and later, Linux, Python3 support only
SHA256: 5436020d80f4cb2c7cc55ead436e3c3d4ccd0102fe6797fa87233f9903de573f
Fixed issues:
trackme-limited/trackme-report-issues#416 - bug - Timezone offset management - properly handle time information management honoring users & system timezone offsets #416
trackme-limited/trackme-report-issues#420 - bug - trackmesplkoutlierstrain - this command should not call directly the component register when raising an exception (leading to unexpected error logging) #420
Enhancement, changes and new features:
trackme-limited/trackme-report-issues#410 - enhancement - Workload (splk-wlk) - Improved and safer scheduler and introspection tracking logic to avoid missing execution traces and false positive execution delayed alerts #410
trackme-limited/trackme-report-issues#411 - enhancement - Outliers Adaptive Thresholding (splk-dsm/splk-dhm) - adjustments of the logic for enhanced behaviour #411
trackme-limited/trackme-report-issues#398 - Feature Request: Acknowledgement overlay in Tabulator tables (right click context popover) #398
trackme-limited/trackme-report-issues#414 - feature - Add row click popover context for Outliers and Data Sampling #414
trackme-limited/trackme-report-issues#415 - feature - Introducing TrackMe decision maker backend, this new concepts replaces SPL based complex evaluations to define the status of TrackMe entities depending on the context and components, for a safer and more robust decision making #415
trackme-limited/trackme-report-issues#417 - feature - Allows enabling/disabling at the tenant level the adaptive delay threshold feature (via a Virtual Tenant account switch) #417
trackme-limited/trackme-report-issues#418 - enhancement - Flex Object - Complete popover context menu (Outliers status, status message and anomaly_reason) #418
trackme-limited/trackme-report-issues#419 - change - Data Sources tracking (splk-dsm) - Do not include the remote account information in the definition of the alias #419
trackme-limited/trackme-report-issues#421 - enhancement - Workload (splk-wlk) - Improved logic for detection and purge of any duplicated entities in Workload #421
Version 2.0.74 - build 1703259037 (22/12/2023)¶
Hint
Splunk 8.1.x and later, Linux, Python3 support only
SHA256: d2a7e5c5447741cc166256589174e31eb01d9e658fcedd54f24264f9c5f92f15
Fixed issues:
trackme-limited/trackme-report-issues¢12 - bug - Workload - Regression issue with outliers definition when performing the schema migration, leading to invalid eval and interrupting the Workload detection - #412
Version 2.0.73 - build 1703095950 (20/12/2023)¶
Hint
Splunk 8.1.x and later, Linux, Python3 support only
SHA256: ddb21e231b5ba7d4f0fc31306ce538a9466b1801e3f3dfe67fcdccba633663f2
Fixed issues:
trackme-limited/trackme-report-issues#408 - bug - Virtual Tenants UI - regression on the listing of reports in TrackMe Tenants Operational health statuses #408
trackme-limited/trackme-report-issues#409 - bug - Virtual Tenants UI - Tenants Operational health statuses can show empty last_exec under some conditions #409
Version 2.0.72 - build 1703080417 (20/12/2023)¶
Hint
Splunk 8.1.x and later, Linux, Python3 support only
SHA256: 99c071e498886209e5a231f9443f96741e5ed7026fbb9aa1ded365774c6a174a
Fixed issues:
trackme-limited/trackme-report-issues#379 - bug - Data Source tracking (splk-dsm) - regression in the simulate thresholds screen due to the migration to restricted summary state events in TrackMe 2.0.68 #379
trackme-limited/trackme-report-issues#380 - bug - Configuration UI - title wording is not consistent for thresholds default configuration management #380
trackme-limited/trackme-report-issues#381 - bug - Workload (splk-wlk) - Outliers are set with lower breached enabled unexpectly with elapsed KPI, shema version upgrade will address this issue automatically #381
trackme-limited/trackme-report-issues#387 - fix - Avoid permissions issues for the Health tracker shema upgrade when handling TrackMe’s knowledge upgrade #387
trackme-limited/trackme-report-issues#394 - bug - Workload/Flex (splk-wlk/splk-flx) - Metric dropdown populating search use static -24h earliest time range #394
trackme-limited/trackme-report-issues#395 - bug - Outliers - Permissions issues for Power users in different advanced Outliers related actions such as resetting or force training models #395
trackme-limited/trackme-report-issues#399 - bug - Flipping status detection - Non unicode chars can lead to continuous discovery #399
trackme-limited/trackme-report-issues#401 - bug - Elastic processing backend - error message local variable ‘count_processed’ referenced before assignment when no entities to be processed #401
trackme-limited/trackme-report-issues#403 - bug - User Interface - Auto-refresh should be disabled automatically when performing bulk edition & inline edition #403
Enhancements, changes and new features:
trackme-limited/trackme-report-issues#372 - change - Allow assigning an Ack to a blue state entity #372
trackme-limited/trackme-report-issues#373 - enhancement - Least privileges & permissions - Some ingest related activities (health tracker & Notables) require the edit_tcp capability, which can be avoided by controled TrackMe capabilities #373
trackme-limited/trackme-report-issues#374 - feature - Manage permanently deleted entities through a builtin UI screen from components #374
trackme-limited/trackme-report-issues#376 - enhancement - Flex Objects - Add a group filter option in the Tabulator #376
trackme-limited/trackme-report-issues#382 - enhancement - Workload (splk-wlk) - Take into account status delegated_remote_error as parts of scheduler excution failures, existing trackers will be updated automatically by the schema upgrade #382
trackme-limited/trackme-report-issues#383 - change - Workload (splk-wlk) - Increase the SmartStatus earliest time from -24h to -7d for the execution error search #383
trackme-limited/trackme-report-issues#384 - feature - Adaptive delay - Introducing the Adaptive delay feature to allow managing automatically delay threshold value for Data Sources and Hosts tracking (splk-dsm/splk-dhm) #384
trackme-limited/trackme-report-issues#385 - enhancement - Outliers - Add more context information in the isOutlierReason field when an Outlier is triggered #385
trackme-limited/trackme-report-issues#386 - feature - Machine Learning Outliers - Introducing the confidence concept to reduce false positive and identify low confidence models and entities #386
trackme-limited/trackme-report-issues#388 - feature request - Overview Table: Column for human readable thresholds #388
trackme-limited/trackme-report-issues#389 - change - User Interfaces - Increase 90% width modal screens to 96% of the screen as a basis for enhanced user experience #389
trackme-limited/trackme-report-issues#390 - enhancement - Flex Objects / Workload / CIM compliance (splk-flx/splk-wlk/splk-cim) - Include the Outliers column in the Tabulator view #390
trackme-limited/trackme-report-issues#391 - feature - Maintenance Knowledge DataBase - Intoducing a concept of a maintenance knowledge database, which can be used in association with the maintenance mode or independently to influence the SLA calculations by injecting knowledge of planned or unplanned operations that have lead to an impact on TrackMe entities #391
trackme-limited/trackme-report-issues#393 - feature - Add Ack duration and Ack type as customizable options for bulk edit actions #393
trackme-limited/trackme-report-issues#396 - feature - Introducing a new command “trackmesplkoutliersgetdata” to get easier access to Outliers results #396
trackme-limited/trackme-report-issues#397 - change - Virtual Tenants - code improvements for the managment of boolean options when creating tenants #397
trackme-limited/trackme-report-issues#400 - feature - Outliers - Allowing to set the time_factor to none which enables TrackMe to apply a simpler LowerBound/UpperBound with no seasonability variations #400
trackme-limited/trackme-report-issues#402 - change - Workload (splk-wlk) - define the Outliers by default based on time factor with no seasonability for elapsed based metrics for enhanced results #402
trackme-limited/trackme-report-issues#404 - feature - Workload (splk-wlk) - Automatically process a diff of the 3 main search Metadata (search, earliest, latest) and attempt to identify the user who performed the change and the time of the change when detecting a saved search version change #404
trackme-limited/trackme-report-issues#406 - enhancement - Virtual Tenant - Health Status reporting - enhanced Tabulator view #406
trackme-limited/trackme-report-issues#407 - change - Tenants & knowledge objects creation ownership - switch the default owner from admin to nobody #407
Version 2.0.71 - build 1700472127 (20/11/2023)¶
Hint
Splunk 8.1.x and later, Linux, Python3 support only
SHA256: 174868c183c78036487881576355a9bc7de228e6295811caf5ac8d3428af8fc8
Fixed issues:
trackme-limited/trackme-report-issues#364 - bug - Typo in distinct count #364
trackme-limited/trackme-report-issues#370 - bug - Replica tenants - Do not attempt to perform the replica tracker for a disabled tenant #370
Enhancements, changes and new features:
trackme-limited/trackme-report-issues#365 - enhancement - Workload (splk-wlk) - Handle use cases when Splunk incorrectly logs scheduler activity with no user context, introducing a new dynamic get owner retrieval component, scheduler trackers are updated automation during the schema upgrade #365
trackme-limited/trackme-report-issues#366 - enhancement - Review of timeout policies in TrackMe, ensures all service definition and Python request define a timeout #366
trackme-limited/trackme-report-issues#367 - enhancement - Flex Objects library - Improvement of the splk_kvstore_size use case for Flex #367
trackme-limited/trackme-report-issues#368 - enhancement - Feeds tracking - Improving the status message for latency & delay alerts (including durations, incude both thresholds, round to 3 decimals) #368
trackme-limited/trackme-report-issues#369 - feature - Data Sources tracking (splk-dsm) - Allow choosing between any of the dcount metrics to define minimal distinct count host thresholds rather than the default mandatory choice (latest_dcount_host_5m) #369
Version 2.0.70 - build 1700087843 (15/11/2023)¶
Hint
Splunk 8.1.x and later, Linux, Python3 support only
SHA256: 4690b0653623f7a96b9347a493a24806c3120bf098fd95fcd2a75d939b369f24
Fixed issues:
trackme-limited/trackme-report-issues#362 - bug - healthtracker - errors generating the expected audit events in trackme_audit for the health tracker itself due to a regression #362
trackme-limited/trackme-report-issues#363 - bug - last_exec is reported as null in the component register audit events #363
Enhancements, changes and new features:
trackme-limited/trackme-report-issues#360 - enhancement - When missing the right permissions and capabilities, show a clearly understandable message for admins to take actions #360
trackme-limited/trackme-report-issues#361 - feature - Workload component (splk-wlk) - Introducing the overgroup feature, allowing to override the per application grouping and allowing to colocate multiple Search tiers in the same tenant #361
Version 2.0.69 - build 1699886135 (13/11/2023)¶
Hint
Splunk 8.1.x and later, Linux, Python3 support only
SHA256: dd9ca1df32eb23008db8d128f7dee9665562224e93aa2fe5e384af64ffc3808e
Fixed issues:
trackme-limited/trackme-report-issues#352 - bug - Shared Elastic - minor logging errors #352
Enhancements, changes and new features:
trackme-limited/trackme-report-issues#353 - enhancement - Elastic Dedicated - improve the manage screen rendering #353
trackme-limited/trackme-report-issues#354 - feature - Migrate component register tracker run time to TrackMe’s metric store for faster queries, and better retention than from the _internal only #354
trackme-limited/trackme-report-issues#355 - feature - Bootstrap icons / Emoji ascii compatibility mode - provide a configurable option for both Vtenants UI / Home UI to switch between Emoji ascii based statuses icons and Bootstrap based icons, this addresses compatibility issues for some customers on Wndows not supporting Emoji ascii fonts #355
trackme-limited/trackme-report-issues#356 - enhancement - Flex Objects library - Enhancement search for the DMA use case #356
trackme-limited/trackme-report-issues#357 - feature - Flex Object library - New use case for Splunk large lookup files detection #357
trackme-limited/trackme-report-issues#359 - change - Increase minimal time betweem two ML training per entity from 24 hours to 7 days for TrackMe footprint reduction #359
Version 2.0.68 - build 1699407909 (08/11/2023)¶
Hint
Splunk 8.1.x and later, Linux, Python3 support only
SHA256: 939013c951a1884369efeb934f12cad919c1d41a22411de8fd1c09a1f3a25ee7
Note
SLA to metrics migration
This new release introduces the migration for SLA metrics to metrics based indexes instead of the previous SLA calculations based on the state events
This allows slightly reducing the size and volume of state events, reducing storage and licensing costs for TrackMe, as well as performing much faster queries and allowing much longer retentions
If you wish to backfill the existing SLA knowledge after you have migrated to TrackMe 2.0.68, run the following Splunk search to backfill SLA metrics using
mcollectWe made the choice not to automate the SLA migration such that you can decide to do it or not, and control its execution process
Use this search after the migration to TrackMe 2.0.68 to backfill SLA metrics (this search can takes a while, think about modifying indexes if necessary, reduce the timerange if you do not care about all metrics, and send this to the background for the best control of its excution)*
index=trackme_summary sourcetype="trackme:state" object_category=* object=* key=* tenant_id=* current_state=* earliest=-90d
| fields _time, tenant_id, object_category, object, alias, current_state, monitored_state, priority, key
| bucket _time span=1m
| stats latest(current_state) as object_state, latest(alias) as alias, latest(monitored_state) as monitored_state, latest(priority) as priority by _time, tenant_id, object_category, object, key
``` convert string status to numerical ```
| eval object_state=case(
object_state = "green", 1,
object_state = "red", 2,
object_state = "orange", 3,
object_state = "blue", 4,
1=1, 5
)
``` rename to the metric_name target, key is objct_id in the new metrics schema ```
| rename object_state as trackme.sla.object_state, key as object_id
``` use mcollect to backfill metrics ```
| mcollect index=trackme_metrics split=t tenant_id, object_category, object, object_id, alias, monitored_state, priority
Note
Introducing the TrackMe stats events minimal mode
This new release introduces a major reduction of the TrackMe state events (sourcetype=trackme:state) in terms of volume and size, as well as a consistent schema
This change was made possible in association with the SLA to metrics migration
You can control in the Configuration screen the mode of generation, minimal (default) or full (as prior to 2.0.68), as well as the list of fields to allow (minimal mode) or block (full mode)
These options are available in the General Configuration tab (Minimal state events, allowlist fields (minimal), In full, block list fields)
There are no actions required to benefit from this change, unless you had some custom reporting or alerting based on the state events, in which case you should review your use cases and adapt them to the new schema
Fixed issues:
trackme-limited/trackme-report-issues#339 - bug - Virtual Tenant UI regression on dynamic theme system level preferences application (flex cards should turn red properly) #339
trackme-limited/trackme-report-issues#342 - bug - Health Tracker (inactive entities tracking) - handle if tracker_runtime is null #342
trackme-limited/trackme-report-issues#343 - bug - Health Tracker (inactive entities tracking) - offline abstract macros should not exclude permanently deleted entities #343
trackme-limited/trackme-report-issues#344 - bug - command trackmepersistentfields - logic assignement error in persistent fields definition #344
trackme-limited/trackme-report-issues#346 - bug - Elastic Sources - Addressing various issues in this release (eventcount not parsed with from lookups, results duplicated in simulation, code weakness) #346
trackme-limited/trackme-report-issues#348 - bug - Virtual Tenants - Issues with underscores in tenant identifiers when created through the REST API #348
trackme-limited/trackme-report-issues#350 - bug - Virtual Tenant - Enabling a previously tenant that has splk-dhm/wlk will report a failure on enabling some macros #350
trackme-limited/trackme-report-issues#351 - bug - Data Sources tracking (splk-dsm) - regression on honoring not including the host in the tstats root break by fields #351
Enhancements, changes and new features:
trackme-limited/trackme-report-issues#337 - change - Tabulator update to version 5.5.2 #337
trackme-limited/trackme-report-issues#338 - feature - Flex Objects - Introducing the Splunk practices use cases for the Flex Objects component #338
trackme-limited/trackme-report-issues#340 - feature / enhancements - Introducing major improvements for the Elastic Sources Shared backend with parallel muti-processing, automated job max runtime definition, ordering of execution and improved logging #340
trackme-limited/trackme-report-issues#341 - feature/enhancement - SLA metrics - For enhanced performances and better management, SLA calculations are moving to true metrics #341
trackme-limited/trackme-report-issues#345 - enhancement - Logging - standardize run_time logging to 3 decimals for all TrackMe backends #345
trackme-limited/trackme-report-issues#349 - feature - State events minimal mode - Major reduction in the state events volume and size to reduce the impact on storage and license (migrates splk-dhm/mhm to full metrics, introducing the state event minimal configuration to ingest minimal state events) #349
Version 2.0.67 - build 1698669312 (30/10/2023)¶
Hint
Splunk 8.1.x and later, Linux, Python3 support only
SHA256: 4c6c90fcad4bf91dbdc17c434d19e4c00de5f18dab7860c18d4f72b9c059fb66
Fixed issues:
trackme-limited/trackme-report-issues#329 - bug - Persistentfields - Python exception if the mtime or tracker_runtime is not in the expected format #329
trackme-limited/trackme-report-issues#330 - bug - Workload (splk-wlk) - Non ASCII characters in knowledge objects names such as foreign accents are not properly handled #330
trackme-limited/trackme-report-issues#331 - bug - Maintenance mode - Failure when attempting to enable the maintenance mode #331
trackme-limited/trackme-report-issues#332 - bug - Missing arguments in searchbnf.conf for the Data Sampling tracker executor #332
trackme-limited/trackme-report-issues#333 - bug - Flex Objects / CIM compliance - missing filehandler rotation in Python lib leads to the log file not being rotated #333
trackme-limited/trackme-report-issues#336 - bug - Flex Objects - properly handle some problematic escaped rex sequences when running remote searches #336
trackme-limited/trackme-report-issues#304 - bug - Virtual Tenant UI - Dropdown text search is not working (affects initial creation and RBAC update modal screens) #304
Enhancements, changes and new features:
trackme-limited/trackme-report-issues#334 - feature - Adding the new command trackmesplkoutliersexpand to expand ML outliers results for further processing #334
trackme-limited/trackme-report-issues#335 - feature - Adding a new expending streaming command for Flex Objects (trackmesplkflxexpandextra), its purpose is to expand the extra_attributes for new use cases management in the Flex Object library #335
Version 2.0.66 - build 1698184235 (24/10/2023)¶
Hint
Splunk 8.1.x and later, Linux, Python3 support only
SHA256: 2593a02f2a8f2a475a6e0318bddd48d94b31fc014a8441cfef10c1168dc495f6
Fixed issues:
trackme-limited/trackme-report-issues#328 - bug - Data Sources tracking (splk-dsm) - The overview single average latency and percentile 95 incorrectly show the same metric (regression from 2.0.65) #328
Version 2.0.65 - build 1698103284 (24/10/2023)¶
Hint
Splunk 8.1.x and later, Linux, Python3 support only
SHA256: e14d7b9e4e198cf79680c2ea6dd598ab3b2b58450077127bc3dbba4f4bedd728
Fixed issues:
trackme-limited/trackme-report-issues#324 - bug - Data Hosts tracking (splk-dhm) - regression on alias value definition at discovery #324
trackme-limited/trackme-report-issues#325 - bug - Ack - wrong audit message #325
trackme-limited/trackme-report-issues#326 - bug - Flex Objects library - error in default cron schedule for lastchanceindex use case #326
trackme-limited/trackme-report-issues#327 - bug - Data Sources tracking (splk-dsm) - If adding host in the custom break by field, the hybrid tracker incorrectly defines entities #327
Version 2.0.64 - build 1698044829 (23/10/2023)¶
Hint
Splunk 8.1.x and later, Linux, Python3 support only
SHA256: 2a0981f700bf2d3c759bb37839578e35876dd5aa7947b17aaf0f15b30d3b816e
Fixed issues:
trackme-limited/trackme-report-issues#317 - bug - Data Sources/Data Hosts tracking (splk-dsm/splk-dhm) - fix discrepency between banner delay and single form delay as well as the Tabulator delay (ensures last delay is refreshed against now) #317
trackme-limited/trackme-report-issues#318 - bug - Data Hosts tracking (splk-dhm) - Issue in the offline abstract macro called by the health tracker (execution fails due to missing pipe when called) #318
trackme-limited/trackme-report-issues#320 - bug - Data Hosts tracking (splk-dhm) - Alias is not correctly persisted when the entity goes out of the trackers range #320
Enhancements, changes and new features:
trackme-limited/trackme-report-issues#319 - change - Data Sources/Hosts tracking (splk-dsm/splk-dhm) - decomission the delayed entities tracker which features are now better handled by the health tracker #319
trackme-limited/trackme-report-issues#321 - enhancement - Data Sources/Hosts tracking (splk-dsm/splk-dhm) - maintain the generation of the delay metric (lag_event_sec) when entities are out of the range of trackers #321
trackme-limited/trackme-report-issues#322 - enhancement - Data Sources / Data Hosts tracking (splk-dsm/splk-dhm) - Extend the auto-lagging screen to include both ingest latency and delay concepts #322
trackme-limited/trackme-report-issues#323 - enhancement - Data Sources/Hosts tracking - show the delay metric (lag_event_sec) in the overview timechart #323
Version 2.0.63 - build 1697650503 (18/10/2023)¶
Hint
Splunk 8.1.x and later, Linux, Python3 support only
SHA256: 1c506fe8b6535228631f8e5c72a817bb00e0a6fac7da886912e30c9932fb2ce6
Fixed issues:
trackme-limited/trackme-report-issues#310 - bug - ML Outliers - Avoid generating an error message when attemping to load the period of exclusion if not a list (add safety) #310
trackme-limited/trackme-report-issues#313 - bug - Workload (splk-wml) - TrackMe should not attempt to perform replacement for app stanza criterias any more if target is remote as these are now explicit in the creation process #313
trackme-limited/trackme-report-issues#314 - bug - Ingest - Since the migration to INGEST_EVAL in 2.0.60, some expected key indexed fields in trackme:state and others are not indexed any longer #314
trackme-limited/trackme-report-issues#315 - bug - SmartStatus - ingested alert actions are lacking the tenant_id and object_category fields, breaking the indexed key consistency scheme in TrackMe #315
trackme-limited/trackme-report-issues#316 - bug - Fix splunkd WARN message “with request data but no Content-Type: header; not parsing POST arguments” #316
Enhancements, changes and new features:
trackme-limited/trackme-report-issues#311 - feature - Allow defining the default sharing level (app or global) when TrackMe creates or manages Splunk Knowledge Objects #311
trackme-limited/trackme-report-issues#312 - change - INGEST_EVAL - Add a safety fail back condition for ingest evals defining the index target #312
Version 2.0.62 - build 1697551318 (17/10/2023)¶
Hint
Splunk 8.1.x and later, Linux, Python3 support only
SHA256: b2f8e6fb03716ce1d9950ca39be0d40c6ded740e7a64035fcf34ef2a3cc9ea24
Fixed issues:
trackme-limited/trackme-report-issues#303 - TrackMe bug report - Hybrid Tracker cron no applied in the report schedule #303
trackme-limited/trackme-report-issues#307 - bug - ML Outliers - Auto Correct should not allow lowerBound and upperBound to be equals #307
Enhancements, changes and new features:
trackme-limited/trackme-report-issues#306 - change - Dark theme compatibility - Enable dark theme compatibility in app.conf #306
trackme-limited/trackme-report-issues#305 - change - ML Outliers - Disable by default the generation of the latency based model for Feeds which is not a great candidate in most of the use cases #305
trackme-limited/trackme-report-issues#308 - enhancement - ML Outliers - inherit earliest and latest from the time range picker rather than explicitely for the ML rendering commands #308
trackme-limited/trackme-report-issues#309 - feature - ML Outliers - Capability to add or delete a period of time for exclusions in the ML models training #309
Version 2.0.61 - build 1697150459 (12/10/2023)¶
Hint
Splunk 8.1.x and later, Linux, Python3 support only
Note
Inheritance support for RBAC
This release introduces support for roles inheritance for RBAC in TrackMe
Virtual Tenants are Splunk Remote Accounts can be accessed, managed and administrated by inheriting roles according to your configuration
SHA256: ad69875eba15dd7680add23d5fba72131916ea04ec862d04df3479fd9e56bf21
Fixed issues:
trackme-limited/trackme-report-issues#294 - bug - Workload / Flex Objects - When more than a single Outliers model is in anomaly, the status_message comes back null as the macro did not expect the multivalue nature of these fields #294
trackme-limited/trackme-report-issues#300 - bug - SLIM Packing for Splunk Cloud Classic - spec files are not instructing the partitioning properly #300
trackme-limited/trackme-report-issues#301 - bug - Data Sources tracking (splk-dsm) - UI token manipulation related issues leads to a null search eating the user disk quota under some circumstances #301
Enhancements, changes and new features:
trackme-limited/trackme-report-issues#290 - enhancement - Flex Objects (splk-flx) - improvement of the use case splk_splunk_enterprise_cluster_peers_status (calculate buckets inbalance deviation and alert) #290
trackme-limited/trackme-report-issues#291 - enhancement - Flex Objects (splk-flx) - improvement of the use case splk_splunk_enterprise_cluster_status #291
trackme-limited/trackme-report-issues#292 - enhancement - Flex Objects (splk-flx) - New use case for rolling tracking of license usage per index and pool #292
trackme-limited/trackme-report-issues#293 - bug/enhancement - Machine Learning Outliers detection - Auto correct logic defects leads to avoid generating true positive outliers #293
trackme-limited/trackme-report-issues#295 - enhancement - Flex Object - Cribl integration UC improvements for health inputs and outputs to remove false positive #295
trackme-limited/trackme-report-issues#296 - enhancement - Flex Objects use cases library - UC splk_queues_filling improvement - avoid generating alerts when the queues are inactive
trackme-limited/trackme-report-issues#297 - change - Remove owner=admin as the default in default.meta to avoid Enterprise customers with no admin users to be impacted by the default behavior of TrackMe #297
trackme-limited/trackme-report-issues#298 - enhancement - Roles Based Access Control (RBAC) - Support inheritance globally in TrackMe #298
Version 2.0.60 - build 1695681952 (25/09/2023)¶
Hint
Splunk 8.1.x and later, Linux, Python3 support only
SHA256: 859bd778ac65750a5e4eb05cc3c11a884ddbdedd9fffcb1e33fafd54909dd71b
Fixed issues:
trackme-limited/trackme-report-issues#289 - bug - SLIM partitioning causes ingest issues in Splunk Cloud Classic experience, requires explicit stanza placement in spec files #289
Version 2.0.59 - build 1695559981 (24/09/2023)¶
Hint
Splunk 8.1.x and later, Linux, Python3 support only
SHA256: 67d7a8466af72c68705cfeeca6504589ad732bc01c0961f8597f1e1236059d44
Fixed issues:
trackme-limited/trackme-report-issues#283 - bug - trackmetrackerhealth (Health Tracker) - Hybrid tracker macro update in the KVstore should only happen if the currently known definition differs from system #283
trackme-limited/trackme-report-issues#284 - bug - TrackMe alert actions (notable, SmartStatus, Ack) - failures to run actions in the context of a strict least privilege service account owning the tenant #284
Enhancements, changes and new features:
trackme-limited/trackme-report-issues#285 - change - Health Tracker - Improve logging for inactive entities tracking for splk-dsm/splk-dhm #285
trackme-limited/trackme-report-issues#286 - change - entity_info API endpoints - always return the object and key value in the response to recycle values as needed and ease further processing #286
trackme-limited/trackme-report-issues#287 - change - Reduce the timerange considered by the delayed entity trackers to 24h by default, after this time inactive entities are taken into account by the health tracker #287
trackme-limited/trackme-report-issues#288 - enhancement - Data Sources and Hosts tracking (splk-dsm/splk-dhm) - Ensures that the delayed entities tracker updates last entity Metadata information even if the target search did not return any results #288
trackme-limited/trackme-report-issues#261 - enhancement - Provide cURL examples for each REST API endpoints in the REST API auto-documentation #261
Version 2.0.58 - build 1694716015 (14/09/2023)¶
Hint
Splunk 8.1.x and later, Linux, Python3 support only
SHA256: 90119b248d9a1a820a335254a3d994ab4b45a7839f2468c7d087d3604208a91a
Fixed issues:
trackme-limited/trackme-report-issues#281 - bug - splunkremotesearch - Non meaningful Python exception when calling a non existing account #281
Enhancements, changes and new features:
trackme-limited/trackme-report-issues#282 - enhancement - Workload (splk-wlk) - Workload Virtual Tenant creation wizard improvements #282
Version 2.0.57 - build 1694635429 (13/09/2023)¶
Hint
Splunk 8.1.x and later, Linux, Python3 support only
SHA256: 5febf5ab3f93abf7ce8b0218f192374bdd5e3094d6150cc98f1e1a9b6126470a
Fixed issues:
trackme-limited/trackme-report-issues#275 - bug - Data Hosts tracking (splk-dhm) - error when deleting entity on a per entity basis (list index out of range) #275
trackme-limited/trackme-report-issues#277 - bug - Data Hosts tracking (splk-dhm) - error when trying to update monitoring hours of a given entity due to wrong REST API endpoint path #277
Enhancements, changes and new features:
trackme-limited/trackme-report-issues#276 - feature - Introducing the CMDB integrator feature - Allows queriying an external third data source for contextual information in TrackMe tenants #276 - See: https://docs.trackme-solutions.com/admin_guide_cmdb_integration.html
trackme-limited/trackme-report-issues#279 - change - RBAC - Optimisation for role membership verification #279
trackme-limited/trackme-report-issues#280 - enhancement - Workload (splk-wlk) - Virtual Tenant creation wizard improvements, split the search filters to be specific in the UI for Scheduler / Introspection / Splunk Cloud SVC #280
Version 2.0.56 - build 1694411312 (11/09/2023)¶
Hint
Splunk 8.1.x and later, Linux, Python3 support only
SHA256: d7d5ed282cda25375216de5e47eb770c6b8bc34d5d1c89354d7e123923374879
Fixed issues:
trackme-limited/trackme-report-issues#264 - bug - typo in RBAC ownership view #264
trackme-limited/trackme-report-issues#266 - bug - Workload (splk-wlk) - When creating the main tracker, the SVC usage should be part of the avg_svc_usage is trackmegenjsonmetricsmissing from the calls in #266
trackme-limited/trackme-report-issues#268 - bug/change - INGEST_EVAL migration for all summary events and metric generation workflow, this migration is performed to overcome a Splunk Cloud Classic DMC deployment bug when deploying applications using transforms to override the DEST_KEY - While this issue is Splunk Cloud responsability, this is not going to be fixed in any acceptable timeline, TrackMe therefore turns to a different approach which is not affected by this #268
trackme-limited/trackme-report-issues#271 - bug - Audit events - When using custom indexes per tenant, audit events remain generated in the default TrackMe configured index rather than the tenant specific index #271
trackme-limited/trackme-report-issues#273 - bug - Benchmark Burn Test tends to time out for long run queries in Splunk Cloud due to time out reach in Splunk Cloud Web reverse proxy #273
Enhancements, changes and new features:
trackme-limited/trackme-report-issues#265 - feature - TrackMe SVC usage audit dashboard for Splunk Cloud customers #265
trackme-limited/trackme-report-issues#267 - change - Workload - Switch the default stats mode for the dropdown to max rather than latest to ensure visibility in most use cases #267
trackme-limited/trackme-report-issues#269 - feature - Flex Object library (splk-flx) - New use case to track SVC consumption in Splunk Cloud by application #269
trackme-limited/trackme-report-issues#270 - change - Flex Objects (splk-flx) - Licensing restriction increase to 32 trackers for Enterprise Edition customers #270
trackme-limited/trackme-report-issues#272 - change - Ack behaviour default system wide configuration when returning to green - enables purging Ack by default when returning to non green if non sticky #272
trackme-limited/trackme-report-issues#274 - enhancement - Feeds tracking (splk-feeds) - synchronize macros knowledge hybrid trackers attributes when the macros are updated in Splunk #274
Version 2.0.55 - build 1693924977 (05/09/2023)¶
Hint
Splunk 8.1.x and later, Linux, Python3 support only
SHA256: b22a72485ba6b09d0b01bb0b19c4faf265aafd3e30a41f076fdc4eba75322b2d
Fixed issues:
trackme-limited/trackme-report-issues#263 - bug - Virtual Tenants UI for Feeds tracking - indexes discovery feature does not work as expected due to Javascript regression when configured at the Virtual Creation phase #263
Version 2.0.54 - build 1693744485 (03/09/2023)¶
Hint
Splunk 8.1.x and later, Linux, Python3 support only
SHA256: 1a745c8ae615620d3c526e94742908897a0aa1e85dfa8454b1fb48d84a5b808e
Enhancements, changes and new features:
trackme-limited/trackme-report-issues#42 - feature - Data Sources tracking (splk-dsm) - Tags for Data Source monitoring - Remove tags linked to a tag policy when the tag policy is removed #42
trackme-limited/trackme-report-issues#259 - bug/enhancement - Virtual Tenants UI optimizations with a new unified endpoint for a faster and safer user experience, this also addresses issues observed in Splunk Cloud classic only #259
trackme-limited/trackme-report-issues#260 - change - Update moment.js to version 2.29.4
trackme-limited/trackme-report-issues#262 - enhancement - Virtual Tenants UI - Alphabetically sort tenants in the UI if no positions are preset for the user profile #262
Fixed issues:
trackme-limited/trackme-report-issues#256 - bug - Data Hosts / Metrics Hosts (splk-dhm/splk-mhm) - Cannot filter on tags within the Tabulator #256
trackme-limited/trackme-report-issues#257 - bug - Data Hosts tracking (splk-dhm) - Max global latency & delay per entity should match the highest relevant value between all sourcetypes related to it #257
trackme-limited/trackme-report-issues#258 - bug - logging issues when checking permissions for trackmeload/trackmetenantstatus (not logging the right user name) #258
Version 2.0.53 - build 1692273340 (17/08/2023)¶
Hint
Splunk 8.1.x and later, Linux, Python3 support only
SHA256: 42654231000a4bae75d40d4d9317babd93b8cc5e080e8d2367ebc5d45365333f
Enhancement, changes and new features:
trackme-limited/trackme-report-issues#251 - feature - Data Hosts / Metric hosts preset the alias equal to the raw object without the key(s) addition #251
trackme-limited/trackme-report-issues#252 - feature - Flex Objects - New use cases for CPU and Memory infrastructure tracking via Splunk introspection #252
trackme-limited/trackme-report-issues#253 - feature - Data Hosts and Metric Hosts tracking - enhancement for tags enrichment purposes #253
Version 2.0.52 - build 1692002557 (14/08/2023)¶
Hint
Splunk 8.1.x and later, Linux, Python3 support only
SHA256: 11dc12c922f8005257c1d8bc5eccf0e8d0f3b848b0881a6eabe42ea56944850f
FIxed issues:
trackme-limited/trackme-report-issues#247 - bug - Replica tenants - logic issues when having more than a single replica tracker with the same component leading to the incorrect purge of replica records #247
trackme-limited/trackme-report-issues#248 - bug - Replica tenants - The Flex object inactive entities tracker should not be created for Replica tenants #248
Enhancements, changes and new features:
trackme-limited/trackme-report-issues#249 - feature - Allow pre-defining default owner and defaults admin/power/roles in TrackMe general configuration for the Virtual Tenants user interfaces #249
Version 2.0.51 - build 1691618697 (09/08/2023)¶
Hint
Splunk 8.1.x and later, Linux, Python3 support only
SHA256: 90b21e5cffa2ec91e968def2b857d083f46eb6c0fecfe5cc4f423d3d87168617
Fixed issues:
trackme-limited/trackme-report-issues#245 - bug - All components - In large scale scenarios with more than 50k entities on a per tenant/component basis, the Tabulator is limited to 50k entities due to the underneath oneshot SDK search #245
trackme-limited/trackme-report-issues#246 - bug - Data Sources/Data Hosts tracking (splk-dsm/splk-dhm) - In some rare conditions, a null search can be generated and run unexpectly impacting user quota #246
Version 2.0.50 - build 1691356328 (06/08/2023)¶
Hint
Splunk 8.1.x and later, Linux, Python3 support only
SHA256: 0147f78edb580e0a67229ee7eb42699e211d1b5791e844e6eb280d52fcf66043
Fixed issues:
trackme-limited/trackme-report-issues#242 - bug - SOAR integration custom command trackmesplksoar - issues rendering a POST response rendered as a list #242
trackme-limited/trackme-report-issues#243 - bug - SOAR integration - pagination issues in some circumstances restricts the number of entities returned #243
Enhancements, changes and new features:
trackme-limited/trackme-report-issues#244 - feature - SOAR integration - Manage Automation Brokers High Availability with TrackMe, update SOAR Assets automatically when an Automation Broker is inactive to an active counter part - High Availability for SOAR Automation Brokers via TrackMe #244
Version 2.0.49 - build 1691080561 (03/08/2023)¶
Hint
Splunk 8.1.x and later, Linux, Python3 support only
SHA256: 6bd3ea567f0465a4f9e388c04cd95cb839b17594f3adb84619b01d00311de1b2
Fixed issues:
trackme-limited/trackme-report-issues#236 - bug - SLA dashboard - Dropdowns populating search is using static 24 hours range rather than timerange picker from the dashboard #236
trackme-limited/trackme-report-issues#240 - bug - Flex Objects (splk-flx) - UC Splunk Cloud SVC usage - ensure to generate metrics of SVC usage if the licensed SVCs is null #240
Enhancements, changes and new features:
trackme-limited/trackme-report-issues#237 - enhancement - Flex Objects (splk-flx) - Allows the priority to be defined at the phase of the Flex Tracker execution #237
trackme-limited/trackme-report-issues#238 - change - Workload (splk-wlk) - Increase the last_seen filter to last 90m for the metadata retrieval #238
trackme-limited/trackme-report-issues#239 - enhancement - Flex Objects (splk-flx) - Include pool_quota_gb metrics in the license pool usage tracking #239
trackme-limited/trackme-report-issues#241 - enhancement - Flex Objects (splk-flx) - Simplification and better code for the Deployment Server tracking use case #241
Version 2.0.48 - build 1690973605 (02/08/2023)¶
Hint
Splunk 8.1.x and later, Linux, Python3 support only
SHA256: cc03ecd66725692e332ad6604ce5c3baddd4f3336883ffb65ff7aaad7ee67a42
Fixed Issues:
trackme-limited/trackme-report-issues#219 - bug - Feeds Tracking (splk-dsm) - The delayed entities trackers re-generates non merged entities in a hybrid context of merged / non merged and does not track merged entities properly #219
trackme-limited/trackme-report-issues#221 - bug - Virtual Tenants UI - Addresses some issues with theming and user preferences, more consistent management of preferences
trackme-limited/trackme-report-issues#222 - bug - Workload (splk-wlk) - error in trackmesplkwlkgetreportsdefstream for metadata retrieval when using remote target multiple load balanced search head targets #222
trackme-limited/trackme-report-issues#224 - bug - Workload (splk-wlk) - simulation fails for Splunk Cloud SVC when running through the UI due to incorrect quote #224
trackme-limited/trackme-report-issues#225 - bug - Workload (splk-wlk) - Back button not working from create hybrid trackers #225
trackme-limited/trackme-report-issues#230 - bug - incorrect report names for the mltrain reports when adding to the report state register component #230
trackme-limited/trackme-report-issues#231 - bug - Workload (splk-wlk) - Under some circumstances an entity generating execution errors could lead to incorrect definition of the user and looping with multivalue fields gnerating bad objects #231
Enhancements, changes and new features:
trackme-limited/trackme-report-issues#223 - enhancement - Outliers engine - When requesting reset ML, the endpoint performs a search, if the max concurrency is searched on the Search Head this can lead to an unexpected failure, ensures we attempt automated retry if it is the case before failing permanently if necessary #223
trackme-limited/trackme-report-issues#226 - feature - Flex Object (splk-flx) - new use case for tracking KVstore collections size #226
trackme-limited/trackme-report-issues#227 -enhancement - Allows a service account owner to be using the minimal level of permissions and capabilites to own and run properly TrackMe objects #227
trackme-limited/trackme-report-issues#228 - enhancement - Python code sanitization, auto-formatting and unit testings for automated bug identification #228
trackme-limited/trackme-report-issues#229 - enhancement - Fix any hard coded reference to localhost for the communication with splunkd using best practice Python splunkd uri inherited URI #229
trackme-limited/trackme-report-issues#232 - enhancement - Data Sources/Data Hosts tracking (spl-dsm/splk-dhm) - Health tracker maintains untracked entities which are out of the scope of any tracker to update and maintain state consistency #232
trackme-limited/trackme-report-issues#233 - feature - Flex Object (splk-flx) - Use Case for Splunk Enterprise license pool usage tracking #233
trackme-limited/trackme-report-issues#234 - enhancement - Splunk SOAR integration - Allows a least privilege approach for SOAR interactions #234
trackme-limited/trackme-report-issues#235 - change - Feeds Tracking - delayed entities tracker switch to False for break by splunk_server and host which is the default now in TrackMe #235
Version 2.0.47 - build 1690295356 (25/07/2023)¶
Hint
Splunk 8.1.x and later, Linux, Python3 support only
SHA256: bcdf0903d3fe531786764ff009911ade7a1a3ca779193733ea3771806d6ef0e3
fixed issues:
trackme-limited/trackme-report-issues#220 - bug - regression in trackmeapiautodocs introduced in 2.0.46 when Splunk App for SOAR is not installed on the Search Tier #220
Version 2.0.46 - build 1690266086 (25/07/2023)¶
Hint
Splunk 8.1.x and later, Linux, Python3 support only
SHA256: c62b857fc20638a97e3b17fd03e9cb5f6fb0d76c5027c8d95ba5cb661bc88fb0
fixed issues:
trackme-limited/trackme-report-issues#210 - bug - Flex Objects (splk-flx) - When a given entity turns red due to inactivity, a summary state event should also be generated to properly influence the SLA percentage calculation #210
trackme-limited/trackme-report-issues#213 - bug - Virtual Tenants - endpoint post_vtenants_accounts should not return an exception when there are no tenants yet #213
trackme-limited/trackme-report-issues#215 - bug - Workload (splk-wlk) - status_message can come back null in some circumstances #215
trackme-limited/trackme-report-issues#216 - bug - Virtual Tenants - deleting a component should clean up the vtenant summary record #216
Enhancements, changes & new features:
trackme-limited/trackme-report-issues#211 - feature - Flex Objects - Splunk SOAR native integration (UCs for SOAR monitoring) #211
trackme-limited/trackme-report-issues#214 - feature - Flex Object (splk-flx) - lastchanceindex use case for Splunk data_collection #214
trackme-limited/trackme-report-issues#217 - change - Data Hosts tracking - automatically restrict the indexes to the main and internal indexes for splk-dhm if indexes is left unconfigured at the tenant creation phase with Hybrid tracker creation enabled (click next disease) #217
Version 2.0.45 - build 1689676533 (18/07/2023)¶
Hint
Splunk 8.1.x and later, Linux, Python3 support only
SHA256: 2b394e1617836c6e5757cac1ad9c2896d5d1340e008d23d403c47ba52c23f78d
Fixed issues:
trackme-limited/trackme-report-issues#201 - bug - Flex UC splk_splunk_enterprise_cluster_status - wrong term Down rather than Stopped #201
trackme-limited/trackme-report-issues#206 - bug - Flipping REST API issue (hitting Splunk CIM) #206
trackme-limited/trackme-report-issues#207 - bug - CIM Tracking - regression in ML Outliers model generation #207
trackme-limited/trackme-report-issues#208 - bug - CIM Tracking - deletion of entities in bulk fails since 2.0.40 #208
trackme-limited/trackme-report-issues#209 - bug - CIM Tracking - failure to generate the initial discovered flipping event #209
Enhancements and new features:
trackme-limited/trackme-report-issues#202 - feature - Flex Objects - Cribl Logstream use cases for deep monitoring of Cribl Logstream in TrackMe #202
trackme-limited/trackme-report-issues#203 - enhancement - Flex Objects - allow multiselect metrics in entity overview #203
trackme-limited/trackme-report-issues#204 - enhancement - Flex Object - preset the alias of the entity as the short value of the object (without the group) and allows defining custom values for the alias at the entity discovery phase of the tracker #204
trackme-limited/trackme-report-issues#205 - enhancement - Flex Objects (splk-flx) - Manage inactive entities #205
Version 2.0.44 - build 1689362642 (14/07/2023)¶
Hint
Splunk 8.1.x and later, Linux, Python3 support only
SHA256: 7602e39ffcdfa299100fb33e0b25363a11ae25da6a5d3ec5051a8bad3bbb235c
Enhancement and new features:
trackme-limited/trackme-report-issues#191 - feature - Flex Objects tracking - Introducing the Flex Objects use case library and major component features improvements #191
Version 2.0.43 - build 1689342033 (14/07/2023)¶
Hint
Splunk 8.1.x and later, Linux, Python3 support only
Hint
Workload upgrade:
review the release special instructions if you are using the workload component
SHA256: 2af481f61b93eaa3c5811856e29871742c50ea176f59446ef39948cac5075cdf
Fix issues
trackme-limited/trackme-report-issues#195 - bug - Workload (splk-wlk) - In some circumstances the Splunk scheduler logs can lack app and user context leading to the creation of new entities in case of execution errors detected #195
trackme-limited/trackme-report-issues#198 - bug - Data Sources (splk-dsm) - enable/disable entities in bulk fails due to regression (object not defined) #198
trackme-limited/trackme-report-issues#199 - bug - Outliers - regression due to the ds_account field decommisioning leading to failures in generating Outliers rules for new entities #199
trackme-limited/trackme-report-issues#200 - bug - Remove the characters length restrictions in the Vtenant configuration in UCC #200
Enhancements and new features:
trackme-limited/trackme-report-issues#197 - enhancement - All components - Execution of TracKers via the UI and when permited via RBAC should be executed as the system user to avoid user related context to impact results consistency #197
Special intructions or notes for this release:
To benefit from the fix of issue #195 related to the Workload, the scheduler tracker should be deleted and re-created for each Workload tenant
This can be achieved via the UI, or via REST API
Version 2.0.42 - build 1688984590 (10/07/2023)¶
Hint
Splunk 8.1.x and later, Linux, Python3 support only
SHA256: 7d4cf2359d629d9f56dd121ab03e981efe0fb1eb2bf98225f1cce6fcb7a882db
fixed issues:
trackme-limited/trackme-report-issues#190 - bug - Workload - the main tracker does not include the count_ess_notable metrics in the metrics summary popup #190
trackme-limited/trackme-report-issues#192 - bug - Data Sources (splk-dsm) - Clear state & run sampling resets the entity for DSM #192
trackme-limited/trackme-report-issues#193 - bug - The number of currently existing trackers should show up in the management UI for Flex Objects and Workloads #193
trackme-limited/trackme-report-issues#194 - bug - Data Hosts Tracking (splk-dhm) - summary level sourcetype state does not honour properly the latency/delay independently as expected #194
Version 2.0.41 - build 1688538958 (05/07/2023)¶
Hint
Splunk 8.1.x and later, Linux, Python3 support only
SHA256: 9ee5384747ee3d022a3a3d8aaf0ae3794dffb9a501de0ce9e9c4a4002ac593a4
Fixed issues:
trackme-limited/trackme-report-issues#189 - bug - splk-dsm (Data Source) bulk edit regression for enable/disable monitoring via bulk edit due to change #182 #189
Version 2.0.40 - build 1688457335 (04/07/2023)¶
Hint
Splunk 8.1.x and later, Linux, Python3 support only
SHA256: a163d0b1b0892edecfd09784b39b6ae0ba13aad275b54355d86c92ccb1fa950e
Fixed issues:
trackme-limited/trackme-report-issues#182 - bug - All components - handle entities changes via their unique identifier rather than the object (handles bad entities with unexpected special characters) #182
trackme-limited/trackme-report-issues#183 - bug - Performance issues at large scale of entities for Flex / Workload trackers #183
trackme-limited/trackme-report-issues#186 - bug - splunkremotesearch - splunk-system-user and admin users should be RBAC granted for all configured accounts #186
trackme-limited/trackme-report-issues#187 - bug - Virtual Tenants UI - count=0 is missing from some rest searches, leading to avoid returning all results from the upstream search (ex: user account selection) #187
Enhancements, changes and new features:
trackme-limited/trackme-report-issues#184 - change - Flex Object - allows automated width for the Status description in the Tabulator #184
trackme-limited/trackme-report-issues#185 - feature - SmartStatus for Workload entities, allows the SmartStatus to handle Workload UCs as well as capturing Splunk internal events with a least privileges approach (no need for users to be able to access to the _internal index to review internal scheduler errors through the SmartStatus control) #185
trackme-limited/trackme-report-issues#188 - enhancement - REST API logical groups - allows updating min percent if an existing group via REST without having to have to provide the list of current members #188
Version 2.0.39 - build 1687757627 (26/06/2023)¶
Hint
Splunk 8.1.x and later, Linux, Python3 support only
SHA256: d855a2c6467e7a1d97abfb783a91883a2205b0b59102bef0471aa74aacf49303
Fixed issues:
trackme-limited/trackme-report-issues#176 - bug - User Interface - Using DSM “Show disabled entities” filter clears the “Filter field or function” dropdown #176
trackme-limited/trackme-report-issues#177 - bug - Data Hosts Tracking (splk-dhm) - truncation in trackme:state for entities with a very large amount of related sourcetypes #177
Enhancements and new features:
trackme-limited/trackme-report-issues#178 - enhancement - Do not allow deleting or cloning Virtual tenants accounts in the Configuration UCC UI #178
trackme-limited/trackme-report-issues#179 - enhancement - Check the Splunk Remote account connectivity and authentication at the creation / edit step in the Configuration UI (UCC framework) #179
trackme-limited/trackme-report-issues#181 - change - Data sources/Data hosts (splk-dsm/spl-dhm) - sets break by splunk_server/host by default to False #181
Version 2.0.38 - build 1687154702 (19/06/2023)¶
Hint
Splunk 8.1.x and later, Linux, Python3 support only
Hint
Metrics expansion mode and Workload upgrade:
review the release special instructions for more information about the metrix expansion mode change in this release
review the release special instructions if you are using the workload component
SHA256: 90a6d51fc68b5e78b2b5a523d834fabbc2eea18cbcefb78e34f3f1ac793de04b
Fixed issues:
trackme-limited/trackme-report-issues#151 - bug - Workload - the app filter provided as an example in the tracker search constraint can lead to the non detection of some use cases of execution errors #151
trackme-limited/trackme-report-issues#152 - bug - failure to populate tenants dropdowns in SLA and Data Sampling Dashboard studio dashboards due to earlier changes in trackmeload output #152
trackme-limited/trackme-report-issues#153 - bug - Workload - trackmesplkwlkgetreportsdefstream should call select url function to properly handle multiple Splunk endpoints for a remote account #153
trackme-limited/trackme-report-issues#154 - bug - error in endpoint /splk_dsm/ds_get_dsm_sampling_obfuscation_mode due to obfuscation Virtual tenant account change #154
trackme-limited/trackme-report-issues#155 - bug - Logical group auto group command - flow logic when adding single member groups #155
trackme-limited/trackme-report-issues#158 - bug - Data Hosts (splk-dhm) - logic flow in trackme_dhm_tracker_abstract macro does not preserve per host max latency/delay and does therefore leads to no honouring these settings #158
trackme-limited/trackme-report-issues#150 - bug - Elastic Sources - metrics generation fails for raw/from based Elastic Sources definition (shared and dedicated) #150
trackme-limited/trackme-report-issues#159 - bug - Common Information Model tracking (splk-cim) - button horizontal alignment issue in TrackMe UI #159
trackme-limited/trackme-report-issues#163 - bug - Vtenant UI - Prevents the running spinner to be removed (due to auto-refresh) before then end of the operation when executing long run operations such as tenants creation #163
trackme-limited/trackme-report-issues#164 - enhancement - avoids running trackers during the Virtual Tenant creation phase to reduce time required for its creation (multiops endpoints) #164
trackme-limited/trackme-report-issues#165 - bug - HTML duplicated ids, issues in label definition, various UI related issues #165
trackme-limited/trackme-report-issues#166 - bug - Workload (splk-wlk) - indentation issues when creating Workload trackers, failures in the tracker creation UI to check remote connectivity #166
trackme-limited/trackme-report-issues#167 - bug - Acknowledgments - typo when creating Ack manually leads to unstricky rather than unsticky status for Ack, prevent their proper expiration #167
trackme-limited/trackme-report-issues#168 - bug - Workload (splk-wlk) - Orphan tracker enhancements from Issue#117 were lost during the transition to least privileges #168
trackme-limited/trackme-report-issues#171 - bug - missing props definition for the command trackmeprettyjson #171
New features and enhancements:
trackme-limited/trackme-report-issues#156 - enhancement - Logical Groups - round the percentage of current group status commitment, allows filtering on Blue entities for splk-dsm/dhm/mhm #156 enhancement - User Interface minimal mode and context popup approach to improve readibility for all eligible components #157
trackme-limited/trackme-report-issues#160 - enhancement - Health Tracker - automatically detect when a TrackMe object no longer exists and cleanup the register knowledge #160
trackme-limited/trackme-report-issues#161 - bug - mlmonitor reports are not registered with the right name in the component register #161
trackme-limited/trackme-report-issues#162 - enhancement - Workload - Adding the notable type tracker to allow tracking the number of Enterprise Security notable events per correlation search #162
trackme-limited/trackme-report-issues#169 - enhancement - Flex Objects (splk-flx) - The tracker wizard should allow trackers not returning any entities to be created, as lookling only bad conditions can be a use case #169
trackme-limited/trackme-report-issues#170 - enhancement - splunkremotesearch - handle Splunk automated extractions when fields resuting from remote events are not consistents #170
trackme-limited/trackme-report-issues#172 - enhancement - Workload (splk-wlk) - provides a deeper visibility with a 3 periods metrics approach of scheduled activity #172
trackme-limited/trackme-report-issues#173 - enhancement - Tabulator component upgrade 5.5 #173
trackme-limited/trackme-report-issues#174 - enhancement - Bulk edit - when clicking on all entities selector, ensures selected entities honour current filters including header filters and add the count number of entities to be impacted in the bulk edit screen #174
trackme-limited/trackme-report-issues#175 - enhancements - Logs inspector dashboard - fixes and improvements for the log inspector dashboard #175
Special instructions for this release:
Default metrics expanded mode
This new release introduces a change in the visibility of eligible components (splk-wlk/splk-cim/splk-flx/splk-dhm/splk-mhm) regarding the default expansion of the metrics column and/or JSON formatted context columns
From 2.0.38, the column is not expanded any longer, a user would see a “right click for popup” message instead, right clicking will provide the expected information in a more context menu, providing better global readibility when dealing with many entities
At anytime in the UI, one can switch to the expanded mode by selecting the “full” visibility in the mode selector dropdown in TrackMe
Also, TrackMe administrators can update the default visbility mode when the tenant is loaded by editing the Vtenant preferences (Configuration / Virtual Tenant account) and defining the default mode for UI prefs - expand metrics
Workload (splk-wlk)
Workload notable tracking:
If you are using Splunk Enterprise Security, you way want to track the notable activity which is a new type of Workload tracker added to this release
The notable track will monitor the number of notable events generated per ES correlation search, and add a new metric “count_ess_notable” which can be used for context and investigations, or Outliers detection eventually.
To add the new notable tracker, run the following command: (replace mytenant with the tenant name, define account according to your context)
| trackme mode=post url="/services/trackme/v2/splk_wlk/admin/wlk_tracker_create" body="{'tenant_id': 'mytenant', 'account': 'local', 'tracker_type': 'notable'}"
Also, you need to add the “count_ess_notable” metric in the main tracker, you can either edit manually the wrapper main report or follow the next instructions to re-create a brand new main tracker
TrackMe schema version update will not perform this for you as you filter preferences (app filters for instance in the root constraints) would be lost and because this can run on a remote target, this cannot be added to a local macro for persistence)
Workload behaviour enhancements:
If you are using the Workload component, you may want to perform the following actions to benefit from some specific updates:
step 1: - Go in the tenant, click on “Manage: Workload Trackers” - Locate the main tracker, and click on Delete
step 2: - Go in a search, run the following command (replace mytenant by the tenant_id, the account is not relevant for main tracker and should always be local):
| trackme mode=post url="/services/trackme/v2/splk_wlk/admin/wlk_tracker_create" body="{'tenant_id': 'mytenant', 'account': 'local', 'tracker_type': 'main'}"
step 3: - Search the following macro: “trackme_wlk_set_status_tenant_<tenant_id>” - Update its content to: (replace the occurences of <tenant_id> with the name of your tenant)
lookup local=t trackme_wlk_orphan_status_tenant_<tenant_id> object OUTPUT orphan, mtime as orphan_last_check | eval orphan_last_check=case(isnotnull(orphan_last_check), strftime(orphan_last_check, "%c"))
| lookup local=t trackme_wlk_versioning_tenant_<tenant_id> object OUTPUT cron_exec_sequence_sec
``` init a status 1```
| eval status=1
``` If there are execution errors detected, status=2, we use periods data from 60m to 4h to 24h, the JSON metrics will not contain the metric if it equals to 0 ```
``` Therefore, if a given search generating errors if fixed and has frequent executions, it likely will turn green in the next 60m from the deployment of the fix ```
| eval status=case(
count_errors_last_60m=0, status,
count_errors_last_4h=0, status,
count_errors_last_24h=0, status,
count_errors_last_60m>0 OR count_errors_last_4h>0 OR count_errors_last_24h>0, 2,
1=1, status
)
``` If there are skipping searches, define two levels of alerting, less than 5% is 3 (orange), more is 2 (red) ```
``` we base the calculation over the 24 period (suffix last_24h) - this can be customised up to your preferences if you wish to used the additional periods ```
| eval status=case(
isnum(skipped_pct_last_24h) AND skipped_pct_last_24h>0 AND skipped_pct_last_24h<5, 3, isnum(skipped_pct_last_24h) AND skipped_pct_last_60m>0 AND skipped_pct_last_24h>=5, 2,
1=1, status
)
``` If we detected the search as an orphan search (not period related) ```
| eval status=if(orphan=1, 2, status)
``` Calculate the delta in sequence between now and the last execution compared against the requested cron schedule sequence, add 1h of grace time, detect if the execution has been delayed ```
| eval status=if(cron_exec_sequence_sec>0 AND ( now()-last_seen > (cron_exec_sequence_sec + 3600) ), 2, status)
``` Set a brief status description, a more granular description will be provided with the anomaly_reason and status_message fields ```
| eval status_description=case(status=1, "normal", status=2, "degraded", status=3, "warning", 1=1, "unknown")
Version 2.0.37 - build 1686088225 (06/06/2023)¶
Hint
Splunk 8.1.x and later, Linux, Python3 support only
Hint
Roles Based Access Control enhancements:
From version 2.0.34, TrackMe implements a new strict least privilege Role Bbased Access Control
A new role trackme_power is now builtin in TrackMe and designed to allow performing updates to entities of a granted tenant
Access to TrackMe is driven by builtin capabilities provided by TrackMe builtin roles (trackme_user, trackme_power, trackme_admin)
The least privilege approach implemented since this release allows granular access to TrackMe without requiring problematic capabilities which have security implications (list_settings, list_storage_passwords)
TrackMe user interfaces automatically adapt its content and provided options depending on the profile of the current user, a normal user will for instance not see write or admin related actions
TrackMe REST API endpoints are now classified in 3 groups, user level endpoints, write level endpoints and admin level endpoints
The TrackMe
splunkremotesearchalso supports Roles Based Access Control, a user calling a given account must be a member of any of the listed roles in the account configuration to be granted access to this accountFor retro-compability purposes, TrackMe will allow access to an existing Remote account that has no RBAC roles setup yet to typical admin users in addition with TrackMe builtin roles (admin, sc_admin, trackme_user, trackme_power, trackme_admin)
When TrackMe is upgraded, the migration of existing tenant is automatically performed by the schema version management, Upgrading TrackMe
For more information, see: Roles & access control
SHA256: 5a0b110099a769abea3af34cb61f4725c686d0554fcf89a1e63ce98486a7cc23
trackme-limited/trackme-report-issues#147 - bug - splk-dsm (Data Source) - regression when call run sampling on a particular entity due to obfuscation change in v2.0.36 #147
trackme-limited/trackme-report-issues#148 - bug - splk-dhm (Data Hosts) - the title of the modal screen incorrectly mentiones splk-mhm #148
trackme-limited/trackme-report-issues#145 - enhancement: Higher width for the status column (which can truncated under Ack circumstances) #145
trackme-limited/trackme-report-issues#149 - bug - Workload / Flex (splk-wlk/splk-flx) - Truncate long description to avoid impacting the view screen #149
Version 2.0.36 - build 1685947587 (05/06/2023)¶
Hint
Splunk 8.1.x and later, Linux, Python3 support only
Hint
Roles Based Access Control enhancements:
From version 2.0.34, TrackMe implements a new strict least privilege Role Bbased Access Control
A new role trackme_power is now builtin in TrackMe and designed to allow performing updates to entities of a granted tenant
Access to TrackMe is driven by builtin capabilities provided by TrackMe builtin roles (trackme_user, trackme_power, trackme_admin)
The least privilege approach implemented since this release allows granular access to TrackMe without requiring problematic capabilities which have security implications (list_settings, list_storage_passwords)
TrackMe user interfaces automatically adapt its content and provided options depending on the profile of the current user, a normal user will for instance not see write or admin related actions
TrackMe REST API endpoints are now classified in 3 groups, user level endpoints, write level endpoints and admin level endpoints
The TrackMe
splunkremotesearchalso supports Roles Based Access Control, a user calling a given account must be a member of any of the listed roles in the account configuration to be granted access to this accountFor retro-compability purposes, TrackMe will allow access to an existing Remote account that has no RBAC roles setup yet to typical admin users in addition with TrackMe builtin roles (admin, sc_admin, trackme_user, trackme_power, trackme_admin)
When TrackMe is upgraded, the migration of existing tenant is automatically performed by the schema version management, Upgrading TrackMe
For more information, see: Roles & access control
SHA256: f0c47447023dca0daf9cb5e5e434dc077a0e8c71bfc75233d73717268eef33a3
trackme-limited/trackme-report-issues#135 - bug - Data Sampling - Creating an mstats based Elastic Source breaks the Data Sampling query execution #135
trackme-limited/trackme-report-issues#136 - bug - Outliers engine - When reseting Outliers models, TrackMe should also reset the data outliers records for a more consistent approach #136
trackme-limited/trackme-report-issues#137 - bug - Acknowledgement - Updating Ack fails due to Python regression introduced in 2.0.34 #137
trackme-limited/trackme-report-issues#138 - enhancement - Add a new command utility trackmeautogroup to allow auto management of logical group association from an upstream SPL logic #138
trackme-limited/trackme-report-issues#139 - bug - SmartStatus - incorrect timechart search in UC delay causes no results to be found #139
trackme-limited/trackme-report-issues#140 - enhancement - SmartStatus - rely on latest known event rather than latest - - trackme-limited/trackme-report-issues#141 - known ingest when defining the earliest for UC delay/latency for better results when looking at an offline entity #140
trackme-limited/trackme-report-issues#141 - enhancement - vtenants accounts integration scheme for more flexible tenant level configuration management #141
trackme-limited/trackme-report-issues#142 - enhancement - Improvements and minor fixes for user interfaces behaviours when user is a power user (capability: trackmepoweroperations) #142
trackme-limited/trackme-report-issues#143 - bug - splk-dhm (Data Host Tracking) - TrackMe does not honor properly the per sourcetype policy due to evaluation of the state at the table loading time which avoids taking into account the status per sourcetype #143
trackme-limited/trackme-report-issues#144 - feature - Introducing the TrackMe Configuration Manager (TCM) to provides CI/CD capabilities for TrackMe #144
Additional notes: - In version 2.0.36, the data sampling obfuscation macro is deprecated and decommissioned automatically, it is replaced by a much more flexible approach relying on the tenant account setting - To enable the obfuscation mode for a given tenant post-migration, go in Configuration / vtenant preferences and edit the tenant to enable the obfuscation mode
Version 2.0.35 - build 1684913150 (24/05/2023)¶
Hint
Splunk 8.1.x and later, Linux, Python3 support only
Hint
Roles Based Access Control enhancements:
From version 2.0.34, TrackMe implements a new strict least privilege Role Bbased Access Control
A new role trackme_power is now builtin in TrackMe and designed to allow performing updates to entities of a granted tenant
Access to TrackMe is driven by builtin capabilities provided by TrackMe builtin roles (trackme_user, trackme_power, trackme_admin)
The least privilege approach implemented since this release allows granular access to TrackMe without requiring problematic capabilities which have security implications (list_settings, list_storage_passwords)
TrackMe user interfaces automatically adapt its content and provided options depending on the profile of the current user, a normal user will for instance not see write or admin related actions
TrackMe REST API endpoints are now classified in 3 groups, user level endpoints, write level endpoints and admin level endpoints
The TrackMe
splunkremotesearchalso supports Roles Based Access Control, a user calling a given account must be a member of any of the listed roles in the account configuration to be granted access to this accountFor retro-compability purposes, TrackMe will allow access to an existing Remote account that has no RBAC roles setup yet to typical admin users in addition with TrackMe builtin roles (admin, sc_admin, trackme_user, trackme_power, trackme_admin)
When TrackMe is upgraded, the migration of existing tenant is automatically performed by the schema version management, Upgrading TrackMe
For more information, see: Roles & access control
SHA-256: 0fbba6699287c2ac6fdcbeb28d4d6ccfa3d889b351b26f1e5010bd2ba74f8fef
trackme-limited/trackme-report-issues#133 - bug - SmartStatus - regression introduced by version 2.0.34 causes SmartStatus function failure #133
trackme-limited/trackme-report-issues#134 - bug - bad entities containing double quotes lead trackmesplkoutlierstrainhelper and trackmesamplingexecutor to continuously fail running searches for these entities with bad request #134
Version 2.0.34 - build 1684860645 (23/05/2023)¶
Hint
Splunk 8.1.x and later, Linux, Python3 support only
Hint
Roles Based Access Control enhancements:
In this release, TrackMe implements a new strict least privilege Role Bbased Access Control
A new role trackme_power is now builtin in TrackMe and designed to allow performing updates to entities of a granted tenant
Access to TrackMe is driven by builtin capabilities provided by TrackMe builtin roles (trackme_user, trackme_power, trackme_admin)
The least privilege approach implemented since this release allows granular access to TrackMe without requiring problematic capabilities which have security implications (list_settings, list_storage_passwords)
TrackMe user interfaces automatically adapt its content and provided options depending on the profile of the current user, a normal user will for instance not see write or admin related actions
TrackMe REST API endpoints are now classified in 3 groups, user level endpoints, write level endpoints and admin level endpoints
The TrackMe
splunkremotesearchalso supports Roles Based Access Control, a user calling a given account must be a member of any of the listed roles in the account configuration to be granted access to this accountFor retro-compability purposes, TrackMe will allow access to an existing Remote account that has no RBAC roles setup yet to typical admin users in addition with TrackMe builtin roles (admin, sc_admin, trackme_user, trackme_power, trackme_admin)
When TrackMe is upgraded, the migration of existing tenant is automatically performed by the schema version management, Upgrading TrackMe
For more information, see: Roles & access control
SHA-256: ce0d5a73b314c8dc246737149962dc5bd2038f89b313429f13485e3e99e2cd35
trackme-limited/trackme-report-issues#106 - enhancement - Least privilege implementation - TrackMe implementation of a least privileges approach to provide with minimal capabilities requirement and a best practice security implementation #106
trackme-limited/trackme-report-issues#119 - enhancement - All components - Performance optimisations #119
trackme-limited/trackme-report-issues#120 - bug - Compliance Tracking (splk-cim) - UI affected by a previous change (regression from #116) #120
trackme-limited/trackme-report-issues#121 - enhancement - UI behaviours - Call spinner in a more consistent manner when actions are being performed #121
trackme-limited/trackme-report-issues#122 - bug - Flex Object (splk-flx) - Convention for status in the docs explanation is wrong #122
trackme-limited/trackme-report-issues#101 - enhancement - Data Source/Host (splk-dsm/dhm) - Allows managing data in the future detection on a per entity basis #101
trackme-limited/trackme-report-issues#124 - enhancement - major performance improvements for trackmesplkoutlierssetrules #124
trackme-limited/trackme-report-issues#125 - enhancement/bug - major performance improvements for Trackers execution (trackmepersistentfields) #125
trackme-limited/trackme-report-issues#126 - enhancement - major performance enhancements for bulk edit operations in TrackMe #126
trackme-limited/trackme-report-issues#127 - bug - Remove component does not remove some knowledge objects #127
trackme-limited/trackme-report-issues#128 - enhancement - Workload - Allow the component to be added to / deleted from an existing Virtual Tenant #128
trackme-limited/trackme-report-issues#129 - enhancement - splunkremotesearch - Roles Based Access Control support #129
trackme-limited/trackme-report-issues#130 - enhancement - trackmeapiautodocs - Remove redundant resource_spl_example/resource_desc from endpoint usage output #130
trackme-limited/trackme-report-issues#131 - bug - Data sampling & events format recognition - escaped double quotes are incorrectly escaped again leading the sampling generation to fail #131
trackme-limited/trackme-report-issues#132 - bug - Data sampling & events format recognition - Reset loses the preset number of records, sets the number of records would fail if the entity has not been processed yet #132
Version 2.0.33 - build 1683898726 (12/05/2023)¶
Hint
Splunk 8.1.x and later, Linux, Python3 support only
SHA-256: b9e8494d654bc60d1f0e12afe220d10c10f87aab1dd2fd20e517511040f9f9c8
trackme-limited/trackme-report-issues#115 - bug - splk-dsm - tags - tags policies not applied as expected due a native multivalue format when taken into account by TrackMe’s REST API #115
trackme-limited/trackme-report-issues#116 - enhancements - Acknowledgments UI behaviours consistency #116
trackme-limited/trackme-report-issues#117 - enhancement - Workload (splk-wlk) - The Orphan check and maintain search takes too long #117
trackme-limited/trackme-report-issues#118 - bug - Data Host Monitoring (splk-dhm) - max delay and max latency are not honoured properly #118
Version 2.0.32 - build 1683797653 (11/05/2023)¶
Hint
Splunk 8.1.x and later, Linux, Python3 support only
SHA-256: b570f9e6a668cfd895832cb2812e540e8a8e263606b49ae9014900d8e0683137
bug - Workload (splk-wlk) - false positive issues with anomaly_reason=execution_delayed under some specific conditions #113
bug - Workload (splk-wlk) - introspection metrics generation - introduce a bucket _time span=1m to properly aggregate metrics for pct_cpu/memory, sum the scan eventcount #114
Version 2.0.31 - build 1683730441 (10/05/2023)¶
Hint
Splunk 8.1.x and later, Linux, Python3 support only
SHA-256: 32d31b6b3c8eade39c27af09dbe2e5d8497a7cecbc5b374f1ba939555ae59069
bug - ucc-framework issue with urllib3 v2.0.x - latest version of urllib3 require fresher openssl version which builtin Splunk versions do not meet causing issues in alert actions #112
Version 2.0.30 - build 1683715542 (10/05/2023)¶
Hint
Splunk 8.1.x and later, Linux, Python3 support only
SHA-256: 4652676182e6271bef61bc368db1fcdc3c216a26d022d4eb54dd6f28e8ec9168
bug - all components - Tracking Alerts UI always created splk-dsm Alert #110
bug - all components - SLA single should turn red if the entity has never been green since it was discovered #111
Version 2.0.29 - build 1683576225 (08/05/2023)¶
Hint
Splunk 8.1.x and later, Linux, Python3 support only
SHA-256: 60e8e0665f3d924d3f7b636fc372fb8f1c6d4ca9274681913ea795706ac804cb
bug - Workload (splk-wlk) - issues in Metadata collection when using a remote account with more than one member in the account definition #107
bug - Flex Object - demo search for deployment servers should filter for the group when doing the inputlookup back #108
bug - Workload (splk-wlk) - mltrain should be scheduled once per hour, mlmonitor should be scheduled every 20 minutes to prevent skipping searches #109
Version 2.0.28 - build 1682667017 (28/04/2023)¶
Hint
Splunk 8.1.x and later, Linux, Python3 support only
SHA-256: 198ddc37df076de98e42a530bf66aa903eff8ae87c4c7d2e601b0c6316611c5d
bug - splk-wlk (Workload) - If running in remote, introspection and Splunk Cloud SVC queries cannot rely on app fieldaliases #105
Version 2.0.27 - build 1682578920 (27/04/2023)¶
Hint
Splunk 8.1.x and later, Linux, Python3 support only
SHA-256: b226ad96a069f070b5293bfe50fab101503e56c2bdf2c2d2027ed2d06bb8bf50
bug - splk-wlk - Missing field alias for svc-consumer causes SVC consumption not to render expected SVC metrics #104
Version 2.0.26 - build 1682503730 (26/04/2023)¶
Hint
Splunk 8.1.x and later, Linux, Python3 support only
SHA-256: fe68d95983066a1f8a2fcf2a4a60271ad1ce91d457c56f76f228a68418059baa
feature - Introducing the new Splunk Workload component for TrackMe, to monitor your Splunk scheduling activity and take the control back #102
bug - splk-cim - avoids append=t in the very first pipe which causes issues in Splunk Cloud #103
Version 2.0.25 - build 1682069909 (21/04/2023)¶
Hint
Splunk 8.1.x and later, Linux, Python3 support only
Note: Hybrid Trackers need to be re-created to benefit from the latest_eventcount_5m
SHA-256: d992c12d1bb9998bc39be0171c3721d4c3f30ecef2ee0be1bfc1ab93dac29897
bug/enhancement - latest_eventcount_5m from TrackMe metrics should perform an aggregation to properly represent the 5m sum of eventcounts #94
Version 2.0.23 - build 1681985039 (20/04/2023)¶
Hint
Splunk 8.1.x and later, Linux, Python3 support only
SHA-256: e03e25136a8803cea926721d959a2312cdbcdec70f810279de3ffdf9c3cf5043
bug - splk-feeds - Hybrid tracker creation, if breaking by host in splk-dsm, the dcount host leads to wrongly interpreting the host value, issues with burn test in raw mode #99
bug - Outliers detection - incorrect message statement when upperBound is breached #100
Version 2.0.22 - build 1681860827 (19/04/2023)¶
Hint
Splunk 8.1.x and later, Linux, Python3 support only
SHA-256: 08ae4facab3c6c141f0967998562bd1440fe1e1d6fe8ee8c85cef47a0191b81a
bug - ack tracker regression issue introduced in release 2.0.21 #97
bug - alerts creation - incorrect statement when including orange status for entities #95
enhancement - splunkremotesearch - accepts a list of multiple Splunk REST endpoints and address targets randomly with HA and DR #93
bug/enhancement - avoid disabling access to the acnknowledgement if it is still active althrough the entity is back in green state #96
Version 2.0.21 - build 1681766136 (17/04/2023)¶
Hint
Splunk 8.2.x/9.x and Python3 support only
SHA-256: 3b15dff23199adb46b8305cda8172062e25ddc24d3610e8da3a90345e4d08077
bug - regression in trackmecollect for splk-dhm. the field splk_dhm_st_summary is required by the UI for processing #92
Version 2.0.20 - build 1681751403 (17/04/2023)¶
Hint
Splunk 8.2.x/9.x and Python3 support only
SHA-256: 59f122da1acc5728f8192365adf4a8b4f83bbd5e740d87f05d62678bdfaea020
change - disable drilldown in API ref table #78
change - Add skipping search shortcut access in Virtual Tenant (skipping donut screen) #79
bug - mistmatch between custom command log files and associated props stanza #80
bug/enhancement - improve detection of latency at ingest and its sensittivity using TrackMe metrics #81
bug - trackmepersistentfields backend would raise an exception and block the remaining updates if an unexpected error occurs in the update process #82
enhancement - avoids TrackMe custom command to be distributed amongst indexes while it’s unecessary #83
bug/enhancement - reduce the foot print of TrackMe state events stored in the summary indexes, prevents unecessary large fields (metrics summary, etc) #84
enhancement - Preparation for the Implementation of least privileges approach in TrackMe and advanced capabilities management #85
enhancements - Python backend enhancements #86
enhancement - Add or Delete components for a TrackMe Virtual Tenant after it was created #87
bug - “Show burn test search” creates a persistent macro #88
bug/enhancenent - splk-feeds - Maintain delayed entities running out of the scope of TrackMe trackers #89
enhancement - massive performance gains in events generating Python backends #90
enhancement - trackmesplkoutlierstrainhelper should implement a max run time sec mechanism to avoid generating skipping search #91
Version 2.0.19 - build 1680519959 (03/04/2023)¶
Hint
Splunk 8.2.x/9.x and Python3 support only
SHA-256: 7f418e954415f4bdd74e8ce685eca7dab1b160ea6706dc6a0170b8fca65b571a
bug - splk-dsm - data_first_time_seen should be part of persistent fields in the macro trackme_dsm_lookup_persistent_fields #75
enhancement - trackmepersistentfields command - in some circumstances, there can be an unexpected duplication of entities, this enhancement ensures that this cannot happen #76
Version 2.0.18 - build 1680475914 (02/04/2023)¶
Hint
Splunk 8.2.x/9.x and Python3 support only
SHA-256: 71dd7ac5314ea3826c19a323844834bad95f3f98de317edb1ea05313761667e3
bug/enhancement - TrackMe metrics generation and vizualisation issues when suffering from latency or low frequency entities #72
bug - Virtual Tenant UI graphical issue when testing remote connectivity #73
bug/enhancement - Improve latency detection by taking into account TrackMe metrics at Hybrid Tracker execution time #74
enhancement - improve consistency of wording for lagging / latency / delay concepts #10
Version 2.0.17 - build 1680257518 (31/03/2023)¶
Hint
Splunk 8.2.x/9.x and Python3 support only
SHA-256: c4c68dc01cf1998db95566c15dc89228478848d969a583eaa617b142ac276547
bug - splk-dsm/splk-flx status flipping will incorrectly continue to see new entities being discovered due to regression in 2.0.15 #71
Version 2.0.16 - build 1680138733 (30/03/2023)¶
Hint
Splunk 8.2.x/9.x and Python3 support only
SHA-256: e07a3f909033b93089541f27b1834ef327910f9f6c50ff11eade33b7e24fbb5c
bug - splk-dsm - bad syntax in screen auto lagging def #68
bug - splk-dsm/splk-dhm - avoid continuing to generate TrackMe metrics for an entity which data flow is interrupted, restrict the metrics scope to the 5 last minutes against the last event of the entity #69
enhancement - Some high scale SHC environments with a large number of entities, especially in Splunk Cloud, were reported to encounter out of sync issues due to ML models update activity, this release reduce the frequency of the ML train activity to avoid this #70
Notes:
Regarding fix #69, Hybrid Trackers need to be re-created, or manually updated:
trackme_dsm_hybrid_abstract_<id>
the break by change may change depending on your context, the fix relies on restricting the the spantime to avoid generating new metrics while the flow is interrupted
| eval spantime=_time | eventstats max(data_last_time_seen) as data_last_time_seen by index,sourcetype | eval spantime=if(spantime>=(now()-300), spantime, null())
Version 2.0.15 - build 1679995508 (28/03/2023)¶
Hint
Splunk 8.2.x/9.x and Python3 support only
SHA-256: affba63ecf9fc7a8b718d5c45894dc64f920ec6d36f1e9794ca7d76f3ca54272
bug / enhancements - introducing the custom command trackmepersistentfields to protect KVstore collection records from conflicting updates and replace the call to outputlookup Splunk command with more control #55
bug - Vtenant creation endpoint should set the current schema_version immediately at the creation phase #56
enhancement - Allow splunkremotesearch command to inherit earliest and latest from the environment (time range picker) #57
bug/enhancement - avoid skipping searches for ML train/monitor and data sampling by reducing the default cron to every 20 when creating a new tenant #58
enhancement - Limit the tenant name identifier to 15 characters max to avoid allowing users from reaching any Splunk limitations, reduce the random digits for trackers to 5 #59
bug/enhancement - splk-dsm and splk-flx, at large scale with large number of concurrent Hybrid Trackers, concurrent loading of whole collections lead to impacts on other entities #60
enhancement - Store the root constraint in a macro when creating the Hybrid Trackers for splk-feeds, for easier design, update and management #61
bug - inherit trackmer_user role in trackme_admin to avoid any non explicit read access #62
bug - If using Federated search in the instance running TrackMe, makeresults duplicates results unexpectly #63
enhancement - splk-feeds Hybrid Tracker creation improvements, new builtin options to control performance denominators, review Burn test search before execution #64
bug - Outliers management issues and enhancements #65
change - Licensing management evolutions #66
bug - log rotation is lacking for the various trackme logs #67
Version 2.0.14 - build 1679295918 (20/03/2023)¶
Hint
Splunk 8.2.x/9.x and Python3 support only
SHA-256: 5cc6306228293260ee82801bbf198a65ca13aedc6bf68bc0bda983b6ba6cae8c
bug - conflict the same object exists already error when attempting to create a lagging class for the same conditions if one exists already for another category #45
feature - splk-flx - Allow to control grouping of entities #46
bug - splk-cim/splk-flx - metric ingestion issues when objects have space characters #47
bug - negative value metrics will be ignored in splk-flx #48
bug - indexes preset by default in tenant creation dropdown regression from 2.0.13 - showing first result index rather than preset index #49
bug/enhancement - detect and degrade a Virtual Tenant using remote splunk account that was removed later on, or if all remote accounts were removed post configuration #50
bug - Virtual Tenant UI - copy spl button may generate trackme SPL commands that cannot be parsed properly #52
feature - Provide a burn test performance benchmark feature while creating Hybrid Trackers to investigate the run time performance ahead of the tracker creation #53
Version 2.0.13 - build 1678259747 (08/03/2023)¶
Hint
Splunk 8.2.x/9.x and Python3 support only
SHA-256: cc4d34f9f54e4fce2dd4299cc4bb549974ec7395a63b6eb4159ee46f2a7b02e5
bug/enhancement - reduce volume of logs in trackme_splk_outliers_train_helper.log #41
bug - lagging classes does not accept splk-dsm / splk-dhm pattern, failures to apply lagging classes against object!=all, various issues affecting lagging classes for splk-dhm #40
bug - timezone issue in REST API and custom command logging events when the user running the command is in a non UTC timezone #43
Version 2.0.12 - build 1678171647 (07/03/2023)¶
Hint
Splunk 8.2.x/9.x and Python3 support only
SHA-256: 001d57ab9960024fde3eabf9439e1643ee118b99626b7f46e1d7ad3797c65378
enhancement - avoids any enabled scheduled report by default including app level management utilities (Ack tracker, backup scheduler, maintenance mode tracker) #33
bug - merged mode for splk-dsm not behaving as expected #34
bug - Virtual Tenants UI regression when deleting the last tenant (should refresh and show up Welcome modal screen) #35
enhancement - reduce the default earliest to -4h instead of -7d when creating Hybrid trackers to limit design requirements for first time users #36
enhancement - improve consistency of wording for lagging / latency / delay concepts #10
bug - missing perc95_latency_5m and stdev_latency_5m metrics for splk-dhm #38
enhancement - Improve global TrackMe experience for splk-feeds with Overview based on TrackMe metrics primarly rather than direct Splunk query (Allows faster query and scalability, enhance RBAC consistency) #37
Version 2.0.11 - build 1677767350 (01/03/2023)¶
Hint
Splunk 8.2.x/9.x and Python3 support only
SHA-256: 16f797f4140bbff976c9d7ff7fb093f5ac519f1b699ff7010aa097e8474c4e8e
bug - Entity remains in red state due to Data sampling detection altrhough the feature has been disabled #28
Version 2.0.10 - build 1677707255 (01/03/2023)¶
Hint
Splunk 8.2.x/9.x and Python3 support only
SHA-256: 423dc06178dd7360ccbffa3741dd7e41ae4ad63eb8cdb9bb703f86828729a3d2
bug - custom indexes not properly used when creating Virtual Tenants from the user interfaces for splk-dsm/dhm/mhm #30
bug - regression from 2.0.9 preventing access to RBAC update from the Virtual Tenant UI #31
Version 2.0.9 - build 1677588126 (28/02/2023)¶
Hint
Splunk 8.2.x/9.x and Python3 support only
SHA-256: edd8c6d22bc6fb80c9b7c08ee46b58d05ea2970f41678c89d6cfbf8f88f3d5d4
bug: Virtual Tenants UI fails to load properly if a Virtual Tenant is disabled and was created with value for its description #21
bug: Virtual Tenant creation error handling issues can lead to undetected failures within the Virtual Tenant user interface #22
bug/enhancement: Virtual Tenants objects creation - avoid and enhance detection and re-attempt if splunkd API is not ready yet to server the newly created object #23
bug/enhancement: disable auto-refresh in Virtual Tenants UI during long run operations to avoid loosing the spinner #24
enhancement: splk-feeds - bulk edit management for Logical groups (splk-dsm/dhm/mhm) #25
feature: introducing the concept of TrackMe schema versioning to allow future automated updates to the Virtual Tenants & Knowledge Objects schema #27
feature: Sticky Acknowledgements #9
bug/enhancement: Single forms and Donut drilldown do not lead to actions (all components) #16
feature: license model update to allow an intermediate pricing plan with the Enterprise Edition #29
Version 2.0.8 - build 1677163367 (23/02/2023)¶
Hint
Splunk 8.2.x/9.x and Python3 support only
SHA-256: 80d0437c355c1ab71930bbf68f6ae0739817994c087712888f65d86d074678b2
bug/enhancement: splk-dsm Data sampling - Tabulator occasionally loads before the modal screen, optimize and avoid multiple REST calls #11
bug/enhancement - splk-flx - simplify the regular expression used in the deploymet server example #12
bug - splk-flx - copy to clipboard button not working for deployment server example from first level modal screen #13
Enhancement - improving naming convention consistancy in status and anomaly_reason #20
Feature request - logical grouping to be made available for splk-dsm component #18
bug - splk-dhm/splk-mhm entity view host Metadata filter do not apply when hybrid tracker was created manually in a tenant (opposed to created during the Virtual Tenant creation phase) #19
Version 2.0.7 - build 1676377640 (14/02/2023)¶
Hint
Splunk 8.2.x/9.x and Python3 support only
SHA-256: 13bc28f5693f9e6f7391ac2f61ddd598818d372c396d4f0d53bc6f5faf4fa865
bug: splk-dsm - dictinct count host issue inconsistency when setting up a dcount_host treshold #1
bug: splk-dsm - Elastic source syntax issue with from datamodel sources - error in identification of remote from searches #5
feature: splk-dsm - Feature request - Simulation of thresholds before applying #3
enhancement: Put a clear RBAC related message in when creating Virtual Tenants regarding membership explicit management
enhancement: TrackMe Alert Suppression/Throttling Enhancements #6
bug/enhancement: bug Tabulator loading modal - all components - In some circumstances, the screen can load before the REST endpoint call return the Tabulator data #7
enhancement: Feature - Disable Ack when an entity goes back to green #8 - You can now enable the option “Remove Ack behaviour” in configuration if you wish to have Ack being disabled automatically when a previously non green entity comes back to green, rather than relying only on the Ack expiration - As well, there has been enhancements on the Ack tracker backend for better reporting and auditing of its activity (generate an audit event per entity)
Notes: - Hybrid/Elastic Trackers need to be re-created to benefit from the new distinct count hosts metrics for splk-dsm (Feeds tracking for Data Sources)
Version 2.0.6 - build 1675851310 (08/02/2023)¶
Hint
Splunk 8.2.x/9.x and Python3 support only
SHA-256: a5bf6e9580ca9924d20ea00c029a4cd61f6bffa700a493a2a8e251934d030bdb
issue with splk-dhm timecharts in Splunk remote deployments when data gaps occur #9
issue with splk-dhm compact mode which should show the sourcetype in addition with the index in the JSON summary #11
wrong label in lagging classes applies to dropdown for splk-dsm/splk-dhm #12
Version 2.0.5 - build 1675711433 (06/02/2023)¶
Hint
Splunk 8.2.x/9.x and Python3 support only
SHA-256: ab77d89634b3debc5d2ddd881243310bbb18b959254efc53dcf6a83a873c5427
Fix - Some REST endpoints are unexpectedly limiting their output to the first 100 records #7
Version 2.0.4 - build 1675617150 (05/02/2023)¶
Hint
Splunk 8.2.x/9.x and Python3 support only
Optimization - function dataset_update_cache should sleep before retrying in case of max concurrent searches run Optimization - function dataset_update_cache should sleep before retrying in case of max concurrent searches run #4
Optimization - avoid logging check license return in non debug mode Optimization - avoid logging check license return in non debug mode #3
Optimization - reduce internal logs from datagen custom command Optimization - reduce internal logs from datagen custom command #6
Version 2.0.3 - build 1675586140 (05/02/2023)¶
Hint
Splunk 8.2.x/9.x and Python3 support only
SHA-256: 661069bc7dfe803c9e6c10021cb693c85e616dce13b54c708f38ddc760848df4
Data sampling engine - syntax error leads custom rule in simulation mode to fail rendering the expected results #1
Version 2.0.2 - build 1675379421 (02/02/2023)¶
Hint
Splunk 8.2.x/9.x and Python3 support only
SHA-256: b5edf46f5bf6a293b318d33b0e4b07c982019dae427d4ad7b7b1b6881fb74145
This the first official release for TrackMe V2