All Apps and Add-ons

G Suite For Splunk

keithpachulski
Engager

On install of the g-suite app I am now receiving the following error on all of my dashboards:

"Eventtype 'gsuite_internal' does not exist or is disabled."

What do I need to do to correct this error?

0 Karma

pablobarquin
Explorer

Hello,

I have exactly the same issue. Weird thing is that Gsuite app is installed since looong time ago with no issues and suddenly this message is appearing in all user's searches/reports/dashboards.
The index we are using is googleapps so I have no idea why this is raising suddenly.
Any ideas?
Thanks!

0 Karma

vhharanpositka
Path Finder

Hi

Actually this error occurred based on the index that you integrate the g-suite data.
The default index will be the main index.

Check the eventtype googleapps which has the search string as (index=main sourcetype=GSuiteForSplunk:error OR sourcetype=gapps:*) OR index=googleapps

If the eventtype and the index is matched then that error will not occur.

Thanks

0 Karma

vhharanpositka
Path Finder

Hi

Actually this error occurred based on the index that you integrate the g-suite data.
The default index will be the main index.

Check the eventtype googleapps which has the search string as (index=main sourcetype=GSuiteForSplunk:error OR sourcetype=gapps:*) OR index=googleapps

If the eventtype and the index is matched then that error will not occur.

Thanks

0 Karma

tbrouwer
New Member

I have the same issue. Hoping someone can answer

0 Karma

vhharanpositka
Path Finder

Hi

Actually this error occurred based on the index that you integrate the g-suite data.
The default index will be the main index.

Check the eventtype googleapps which has the search string as (index=main sourcetype=GSuiteForSplunk:error OR sourcetype=gapps:*) OR index=googleapps

If the eventtype and the index is matched then that error will not occur.

Thanks

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...