All Apps and Add-ons

Missing source and sourcetype in selected and interesting fields

balmeida
Explorer

Hi,

Somehow, when the Linux Auditd Technology Add-On is installed on our SplunkCloud deployment, the source and sourcetype fields disappear from selected fields or interesting fields whenever a linux:audit event is present in the search results.

I can still use them in the search.

As soon as I disable the addon, the fields return

Assuming this search always contains linux:audit data, this is the behaviour I am seeing:

# Fields missing:
host=ip-10-231-16-14 index=test

# Fields missing:
host=ip-10-231-16-14 index=test sourcetype=linux:audit

# Fields appear correctly:
host=ip-10-231-16-14 index=test sourcetype!=linux:audit

I've never seen this kind of behaviour, any ideas what's going on?

Thanks

0 Karma

doksu
Contributor

@balmeida that's super weird. Thanks for bringing it to my attention. Could you please open a ticket with support as that sounds like a Splunk bug.

0 Karma
Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Wondering How to Build Resiliency in the Cloud?

IT leaders are choosing Splunk Cloud as an ideal cloud transformation platform to drive business resilience,  ...

Updated Data Management and AWS GDI Inventory in Splunk Observability

We’re making some changes to Data Management and Infrastructure Inventory for AWS. The Data Management page, ...