Skip to main content

 

Splunk Lantern

Analytics Workspace removal in Splunk platform 10.6

Splunk announced the deprecation of Analytics Workspace in Splunk Enterprise and Splunk Cloud Platform 10.4, and has now removed it in version 10.6. This article explains how to continue working with metrics data and how to locate any alerts you created in Analytics Workspace.

The removal of Analytics Workspace does not affect metrics panels in dashboards, the ability to run mstats SPL searches, or alerts you created from Analytics Workspace. Those continue to work as before.

Searching data in a metrics index

Going forward, you can still search metrics using the mstats SPL command. You can visually analyze the output in search or dashboards.

To view a list of metrics, use the following SPL, as described in Search and monitor metrics:

| mcatalog values(metric_name) WHERE index=*

To replicate the list of metrics that Analytics Workspace displayed, use the following SPL, as described in Troubleshoot the Analytics Workspace:

| mcatalog values(metric_name) AS metrics WHERE NOT
("_dims"="rollup_aggregate" OR "_dims"="rollup_span" OR
"_dims"="rollup_source_index") AND ("index"="*" OR "index"="_*" )
earliest=-1d BY index | mvexpand metrics limit=20000

Managing alerts created using Analytics Workspace

If you created scheduled alerts from Analytics Workspace, you can find and manage them in these locations:

Scheduled alerts can also be managed using the savedsearches.conf configuration file.

If you created streaming alerts from Analytics Workspace, you can manage them in the metric_alerts.conf configuration file.

You can check whether you have any Analytics Workspace alerts in the Health Checks tab of the Monitoring Console, or the Health dashboard of the Cloud Monitoring Console.

Next steps

You might also find the following resources useful: