Atlas Assessment
Overview
Atlas Assessment is a powerful and free tool designed to evaluate the state of your Splunk environment and identify areas for improvement. With Assessment, you gain visibility into your Splunk environment's health and discover how Atlas can enhance it. It's recommended to begin any Atlas install with an assessment to identify improvement areas in your current Splunk deployment and where Atlas can deliver immediate results. Following assessment recommendations can improve Splunk search speeds, increase data stability, reduce costs, and greatly enhance Splunk adoption.
Requirements
-
Atlas Assessments is a feature on the Atlas Platform. It is free and requires no License to activate.
-
For the best results, you should run Atlas Assessment as a Splunk administrator.
-
You should run Atlas Assessment in your production Splunk Enterprise or Splunk Cloud environment.
If you are a Splunk Cloud customer, you must install Atlas Assessment using SplunkBase.
Capabilities
- Automated checks against your Splunk Environment to identify issues that should be reviewed
- Ability to schedule Assessments and view their results
- Issue analysis that rates severity and indicates where an issue exists
- Explanations of impact and recommendations for solutions
- Exportable findings and recommendations for tracking
All findings from Assessment are stored locally and no reports or data is shared with external parties.
Configuration
Use the Configure button in the top-right corner of Atlas Assessment to update settings that control how Assessment runs and where it stores its results. This action requires the Atlas Admin role.
To update the configuration:
- Select Configure from the Atlas Assessment page.
- Update one or both configuration options.
- Select Save Configuration.
The Configuration modal includes the following settings:
- Assessment Check Timeout: Sets the maximum number of seconds Atlas allows an individual assessment check to run before it is stopped. The default is
600. Increase this value for larger or slower Splunk environments. - Metric Index Selection: Selects the metrics index where Atlas stores assessment results and historical assessment data. The default is
_metrics.
The Metric Index Selection setting is shared with Atlas Settings. To update the same value from Settings, select the Configuration tab, expand Metric Index Configuration, and edit the Assessment setting. Changes made from either location are reflected in both places.
Assessment Dashboard
Assessment categories
Atlas Assessment evaluates your Splunk environment across five key categories, each represented by its own panel on the dashboard. Selecting a panel will filter to those checks
- Search Performance: Evaluates the health of your search scheduler and identifies issues that could negatively impact Splunk performance
- System Performance: Assesses the health of common system performance items
- Data Source Integrity: Evaluates aspects of the data sources coming into your environment and how well they are managed
- Splunk Adoption: Measures how well your Splunk environment is being adopted by your user community
- License Utilization: Checks how your data is being utilized with respect to your license capacity
Run an Assessment
To run a new assessment:
- Click the Run Assessment button in the top right corner of the dashboard.
- Atlas Assessment will check if you have correct permissions. Any issues will be identified on the Run Assessment modal.
- Optionally: Select what categories you wish to run an assessment against.
- The assessment will execute a series of searches in the background and evaluate the results.
- As the process runs, you'll see a status indicator that allows you to cancel the assessment if needed.
- Only one assessment can be executed at a time. You can navigate away from the interface while an assessment is running, and it will continue in the background.
- Assessment results are displayed for the most recently executed assessment. To view historical assessments, change the Assessment ID filter on the top left.
Schedule an Assessment
Scheduled Assessments enable the Splunk Admin team to run longer assessments in 'off hours', and to track ongoing improvements or health of the environment.
To schedule a reoccurring Assessment:
- Select the Schedule Assessment button in the top right corner of the dashboard.
- Enable the Automation.
- Input the next time this search should execute in Start Time.
- Select the cadence on when to repeat the schedule.
- Select the total time range for checks that leverage index searching.
- Select Save.
- Return to Assessment after the scheduled search has executed to confirm it succeeded.
Review Assessment Results
The main assessment results table provides a detailed view of all checks performed. For each check, you can see:
- Category: The assessment category the check belongs to.
- Status: The result of the check (pass, warning, alert, or informational).
- Check Name: The specific aspect being evaluated.
- Value: The current value found in your environment.
- Description: Details about what was being evaluated in the Splunk environment.
- Actions: Additional options related to the check.
Assessment results are rated based on best practices set forth by Splunk or recommended by the Atlas platform:
- Pass (green) ; The check returned values within acceptable thresholds.
- Warning (yellow) : The check results are trending in a negative direction and should be evaluated.
- Alert (red) : The check has determined you are outside of recommended thresholds and action should be taken.
- Informational (blue) : The check provides valuable information about a Splunk configuration or general element.
Explore Check Details
Clicking on any check dropdown in the table expands it to reveal additional details, showcasing thresholds, additional details, the time range that the search was executed under, and any Atlas recommendations, which will point out how Atlas can assist with the issue. Users can also select the Columns button above the table to add the row expansion fields to the main view. Columns can be re-sized and re-ordered to the user's choice.
The Actions column contains the following features:
- Open in Search: Opens the saved search that powers the check. Some Assessment checks leverage base searches so these may not always work as expected.
- View History: Opens a Splunk search that reports on previous results from this check.
Export Assessment Results
Assessment results can easily be exported in four ways:
- CSV: Exports all related fields, including row expansions, into a CSV document.
- Excel: Exports all selected columns, ignoring row expansions, into a formatted Excel document.
- PNG: Exports the entire table as a PNG snapshot, includes any checks row expanded.
- PDF: Exports all checks into a templated PDF for consumption. Includes summary by category and an appendix with all checks.
Simply wait until all checks have finished returning results, then click the Export button above the table on the top left.
History Dashboard
The History dashboard allows Atlas Assessment users to view previous assessment results. This is a useful tool when paired with regularly scheduled assessments.
Users can filter results to specific Assessment Spans within a specific time range to ensure assessments are being compared to similar assessments.
Assessment History Visual
This visual populates with a historic bar graph of previously ran Assessments.
Past Assessment Report Table
This table identifies which checks have changed over historic runs. It compares each assessment to the previous run, enabling users to track environmental improvements.
After two assessments have been ran, specific checks can be investigated to track historic differences, with buttons enabling the user to go directly to that assessment and check on All Checks dashboard.