Splunk Search

signature not searchable

trevlix
New Member

I have an odd problem. I just set up a splunk instance and its only monitoring local linux logs at the moment. The logs contain iptables logs that are feeding in correctly as I see the right fields (eventtype, signature, dst, dpt, src, action, etc.)

However, the odd thing is when I try to search on the eventtype or signature for iptables (eventtype=firewall-deny or signature=firewall), nothing comes back. This is despite the fact that when I hover over the signature field in the field discovery panel is shows 200+ events for signature=firewall.

I'm assuming the eventtype=firewall-deny is not working because it depends on signature working.

So, am I doing something wrong or is there something I need to do in order to get it working correctly?

Tags (2)
0 Karma

Unister
Explorer

I know my answer is a little late, but maybe it is helping someone else. If you started the search exactly like you showed, the or must be in uppercase:

eventtype=firewall-deny OR signature=firewall
0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...