Splunk Diag Doctor

Root-cause a Splunk deployment from diag files. Crawls one or many Splunk diags (extracted folders or .tar.gz) sitting in the repo, correlates splunkd.log, metrics.log, systeminfo.txt, and the conf layer into an evidence-backed root cause, then writes a remediation plan with ready-to-apply conf stanzas and CLI. Use this skill whenever a Splunk diag is present or mentioned, whenever the user uploads or points at a `diag-*` folder or tarball, and whenever they describe a Splunk problem — indexing lag, blocked queues, skipped searches, crashes, KVStore or mongod failures, SSL/cert errors, cluster bucket fixup, replication factor not met, license violations, forwarder connection failures, high CPU or memory, disk pressure, duplicate or missing events — and expect the answer to come from diag data rather than a live search. Also use it for "why is this indexer slow", "what's wrong with this search head", "review this diag", "triage this support case bundle", or any request to compare diags across a cluster.

shanemullens Updated

File contents

shanemullens/shane-cursor-skills/tree/main/skills/splunk-diag-doctor commit 84ba6f6458

Frequently asked questions

npx skillmds@latest add shanemullens/splunk-diag-doctor