uberAgent 5.0.1: Splunk 7.1, Data Model Acceleration Auto-Skewing
We are happy to announce the newest version of our user experience and application performance monitoring product. uberAgent 5.0.1 adds support for Splunk 7.1 and brings many other improvements.
uberAgent now fully supports the significant user interface updates Splunk introduced in version 7.1.
Data Model Acceleration Auto-Skewing
This is something we are particularly proud of: “our” first feature suggestion got implemented in Splunk Enterprise.
uberAgent makes extensive use of accelerated data models for greatly enhanced dashboard search speed (for details see the blog posts to Helge’s Splunk .conf 2015 session).
Put simply, when a data model is accelerated, an additional index is built that is populated by searches that run every five minutes. Without the new auto-skewing feature, all data model acceleration searches were scheduled to run at exactly the same time, which would fail due to concurrency limitations. With version 7.1 Splunk learned to distribute the acceleration searches across the available time range. This promises to effectively get rid of skipped searches – and we are very happy to report that it does exactly that!
Auto-skewing is now enabled for uberAgent’s data model. It causes a (harmless) warning message on Splunk versions prior to 7.1 during a restart of Splunkd. To remove that, simply comment out the setting acceleration.allow_skew in datamodels.conf.
uberAgent is an innovative Windows and macOS user experience monitoring (UXM) and endpoint security analytics (ESA) product.
uberAgent UXM highlights include detailed information about boot and logon duration, application unresponsiveness detection, network reliability drill-downs, process startup duration, application usage metering, browser performance, web app metrics, and Citrix insights. All these varied aspects of system performance and reliability are smartly brought together in the Experience Score dashboard.
uberAgent ESA excels with a sophisticated activity monitoring engine, the uAQL query language, detection of risky activity, DNS query monitoring, hash calculation, registry monitoring, and Authenticode signature verification. uberAgent ESA comes with Sysmon and Sigma rule converters, a graphical rule editor, and uses a simple yet powerful query language instead of XML.
About vast limits
vast limits GmbH is the company behind uberAgent, the innovative user experience monitoring and endpoint security analytics product. vast limits’ customer list includes organizations from industries like finance, healthcare, professional services, and education, ranging from medium-sized businesses to global enterprises. vast limits’ network of qualified solution partners ensures best-in-class service and support anywhere in the world.