icon/x Created with Sketch.

Splunk Cookie Policy

We use our own and third-party cookies to provide you with a great online experience. We also use these cookies to improve our products and services, support our marketing campaigns, and advertise to you on our website and other websites. Some cookies may continue to collect information after you have left our website. Learn more (including how to update your settings) here.
Accept Cookie Policy

We are working on something new...

A Fresh New Splunkbase
We are designing a New Splunkbase to improve search and discoverability of apps. Check out our new and improved features like Categories and Collections. New Splunkbase is currently in preview mode, as it is under active development. We welcome you to navigate New Splunkbase and give us feedback.

Accept License Agreements

This app is provided by a third party and your right to use the app is in accordance with the license provided by that third-party licensor. Splunk is not responsible for any third-party apps and does not provide any warranty or support. If you have any questions, complaints or claims with respect to this app, please contact the licensor directly.

Thank You

Downloading Detection Backfill (Rerun and Healthcheck)
SHA256 checksum (detection-backfill-rerun-and-healthcheck_152.tgz) a4c72ca2d3ab912b6332b5d7a72df90962e34e683b54454ba278f872756c7216 SHA256 checksum (detection-backfill-rerun-and-healthcheck_151.tgz) bf18b3548d48b12817566e7cdeecf5004aa9af163d4f8829233011b09a150406 SHA256 checksum (detection-backfill-rerun-and-healthcheck_15.tgz) 349b087a7cbcc57f10b77958cb23ba90514a412fd347c7b2a34f166937cbba91 SHA256 checksum (detection-backfill-rerun-and-healthcheck_14.tgz) 5a2d5bc25112f6a56632b040221e4254f39c3e3ab2e1f33c2816905fabb6a559 SHA256 checksum (detection-backfill-rerun-and-healthcheck_13.tgz) 68d6968dabbaa3919457570f31ef5100e1680ac69a2fefc4875d222916f0413f
To install your download
To install apps and add-ons from within Splunk Enterprise
  1. Log into Splunk Enterprise.
  2. On the Apps menu, click Manage Apps.
  3. Click Install app from file.
  4. In the Upload app window, click Choose File.
  5. Locate the .tar.gz file you just downloaded, and then click Open or Choose.
  6. Click Upload.
  7. Click Restart Splunk, and then confirm that you want to restart.
To install apps and add-ons directly into Splunk Enterprise
  1. Put the downloaded file in the $SPLUNK_HOME/etc/apps directory.
  2. Untar and ungzip your app or add-on, using a tool like tar -xvf (on *nix) or WinZip (on Windows).
  3. Restart Splunk.
After you install a Splunk app, you will find it on Splunk Home. If you have questions or need more information, see Manage app and add-on objects.

Flag As Inappropriate

splunk

Detection Backfill (Rerun and Healthcheck)

Overview
This TA can be used to fill in detection gaps following a period of data collection interruption. Once data are recovered in Splunk, this application can be used to restart scheduled searches during this outage.

You can automatically create your list of backfills using a dedicated dashboard based on an outage period and a regexp on savedsearches that need to be rerun.
You can manage the backlog of all your rescheduled searches (backfills are run periodically to avoid performance issues over the platform)
You can monitor the reruns based on the internal logs and a full details of logging provided in the python scripts

Release Notes

Version 1.5.2
Aug. 14, 2024

Release Notes for v1.5.2

  • Fix: Issue with the trigger parameter for rerun searches not taken into account correctly

See the full release notes directly on Github: https://github.com/LetMeR00t/TA-detection-backfill/releases/tag/v1.5.2

Version 1.5.1
April 4, 2024

Release Notes for v1.5.1

  • Fix: Issue with wrong usage of warn/warning function and log type
  • Feature: Provide a way to filter on audittrail logs by filtering on the hosts
  • Perf: Optimize searches CPU/memory usage
  • Refactor: Remove the possibility to dispatch a healthcheck job as an ad-hoc search
  • Refactor: Move the Healthcheck dashboard monitoring to Dashboard Classic

See the full release notes directly on Github: https://github.com/LetMeR00t/TA-detection-backfill/releases/tag/v1.5.1

Version 1.5
April 1, 2024

Release Notes for v1.5

  • Feature: Support for using relative times when preparing rerun jobs
  • Feature: Added the capability to do SPL injection code during rerun jobs
  • Feature: Added the capability to perform healthcheck jobs used to rerun searches after a certain period of time (backlog based)
  • Feature: Added the capability to perform advanced monitoring for healthcheck jobs in order to get deep results analysis (help to know what have changed in the results between the original and the healthcheck job)
  • Feature: Added the possibility to specify the trigger action (True/False) in the lookup for each savedsearch job instead of a global parameter in the custom alert action
  • Feature: Added the ability to set the dispatch TTL to easily manage the retention/expiration time of job results.

See the full release notes directly on Github: https://github.com/LetMeR00t/TA-detection-backfill/releases/tag/v1.5

Version 1.4
Jan. 18, 2024

Release Notes for v1.4

  • Fix: Support lookup replication by updating the lookup through the Splunk REST API

See the full release notes directly on Github: https://github.com/LetMeR00t/TA-detection-backfill/releases/tag/v1.4

Version 1.3
Jan. 13, 2024

Release Notes for v1.3 (same version as v1.2.2 but with cloud vet allowed)

  • Refactor: Support cloud vet

See the full release notes directly on Github: https://github.com/LetMeR00t/TA-detection-backfill/releases/tag/v1.3


Subscribe Share

Are you a developer?

As a Splunkbase app developer, you will have access to all Splunk development resources and receive a 10GB license to build an app that will help solve use cases for customers all over the world. Splunkbase has 1000+ apps from Splunk, our partners and our community. Find an app for most any data source and user need, or simply create your own with help from our developer portal.

Follow Us:
Splunk, Splunk>,Turn Data Into Doing, Data-to-Everything, and D2E are trademarks or registered trademarks of Splunk LLC in the United States and other countries. All other brand names,product names,or trademarks belong to their respective owners.