Dashboards & Visualizations

abc and xyz events are mixed up in pqr (where pqr is sourcetype)

Praz_123
Path Finder

Hi ,

We are getting the mixed abc and xyz events from sourcetype pqr. Due to this, Network team are getting multiple false tickets . 

Labels (1)
Tags (2)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @Praz_123,

your question is just a little vague!

could you share more details?

which is the sourcetype?

are you using a standard or a ustom Add-On?

Anyway, using a simple search analyze your data to understand which hosts are involved and what's te Add-On that you have to correct, probably you need only to specify the sourcetype in the inputs.conf.

Ciao.

Giuseppe

0 Karma

Praz_123
Path Finder

@gcusello 

only yesterday we had received like mixed event like:

abc and xyz are coming in a same events

Previously it didn't happen like that  

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @Praz_123 ,

as @ITWhisperer asked: did you changed something in your configurations?

I repeat my questions:

are you using a custom sourcetype and add-on?

if not which one?

Ciao.

Giuseppe

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

It sounds like something recently changed - either change it back or change forward to fix it

0 Karma
Get Updates on the Splunk Community!

Get the T-shirt to Prove You Survived Splunk University Bootcamp

As if Splunk University, in Las Vegas, in-person, with three days of bootcamps and labs weren’t enough, now ...

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Wondering How to Build Resiliency in the Cloud?

IT leaders are choosing Splunk Cloud as an ideal cloud transformation platform to drive business resilience,  ...