What's New: Splunk Enterprise 8.2

 

Splunk Enterprise 8.2, has focused their development offers across a number of themes: insights, admin productivity, data infrastructure, and performance. Be sure to check out Splunk Docs for a complete and definitive guide on how and where you can access and use these new features.

Insights

Dashboard Studio is now generally available (GA) and is now integrated directly into Search & Reporting, alongside the Classic Dashboard experience. Dashboard Studio is the new and intuitive dashboard-builder for creating visually-compelling dashboards with advanced visualization tools and fully customizable formats. Also, Splunk Secure Gateway (SSG) App is now delivered as part of Splunk Enterprise. SSG lets you configure your Connected Experiences mobile deployment and register devices to a Splunk instance.




Dashboard Studio in action

Admin Productivity

Spunk has done a lot in this release to help admins do more with less. The Splunk Health Report also now displays information rolled up in a distributed environment so that you don’t have to login to every node. It is added a way to monitor I/O Wait and Ingestion Latency in the Splunk Health Report. 



Distributed Health Report

Splunk is also introducing a new set of internal logs that track configuration file changes at the filesystem level for auditing purposes. Additionally, check out a new app “Knowledge Object Management” on Splunkbase for tracking asset usage and reporting. Look for more updates in the future on improved experience with auditing.

Infrastructure & Data

A key capability shipping in this release is Federated Search in hybrid deployments. There may be times when you want to run a single query across different Splunk deployments. This may especially apply if some deployments require regional presence or are subject to data policies. Federated Search in Splunk Enterprise 8.2 supports searching for On-prem to On-prem environments, and On-prem to Splunk Cloud.  

Also new is the support for merging buckets in standalone (single node) instances. This is one step in a series of enhancements that are expected to address indexer clustering performance and stability following system activities such as restarts. This should start to enable customers to achieve larger bucket sizes to more optimally and smoothly scale their deployments. 

Performance

As always, Splunk continue to make advancements in the performance of the software. We have a host of improvements in this release. Customers can expect up to 10X faster scheduling of searches, especially in cases where large a number of searches are scheduled every minute and saved search configuration files are updated frequently. Splunk has also improved schedule report performance. Now they provide an option for durable search processing to achieve delivery guarantee, and ensures that scheduled reports do not lose events over time, even when errors occur. Improvements to speed up searchable rolling restarts, whenever deployment architecture allows it are made. Other improvements include improved kvstore backup and restore experience, and compression techniques for bundle pushes, improving the availability and resilience of Splunk. Be sure to check out our release notes for more!

 

Reference link

A.K

Comments

Popular posts from this blog

CISA and ENISA enhance their Cooperation

Top Five Most Exploited Vulnerabilities in January 2024

SmartScreen Vulnerability: CVE-2024-21412 Facts and Fixes