<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: nix_errors casting too wide a net? in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/nix-errors-casting-too-wide-a-net/m-p/25118#M756</link>
    <description>&lt;P&gt;Thanks, araitz.  The removal of the global scope for the eventtypes has really cut down the noise.&lt;/P&gt;

&lt;P&gt;Aside: exptremely tedious to change the 100+ *NIX eventtypes via the GUI. I'm sure there was a better way via the .conf files.  Planning to enroll in some Splunk Admin courses.&lt;/P&gt;</description>
    <pubDate>Thu, 08 Aug 2013 12:17:55 GMT</pubDate>
    <dc:creator>michaelgardner</dc:creator>
    <dc:date>2013-08-08T12:17:55Z</dc:date>
    <item>
      <title>nix_errors casting too wide a net?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/nix-errors-casting-too-wide-a-net/m-p/25116#M754</link>
      <description>&lt;P&gt;Splunk newbie question, I think.&lt;/P&gt;

&lt;P&gt;We have a medium-sized heterogeneous (in terms of OS) environment.  We are getting non-errors reported with the "nix_errors" eventtype and also the "nix-log-files" eventtype, though the log files are actually on a Windows server.  These eventtypes are defined from the "Splunk for Unix and Linux" App.&lt;/P&gt;

&lt;P&gt;The "nix_errors" eventtype is defined as:&lt;/P&gt;

&lt;P&gt;&lt;CODE&gt;NOT sourcetype=stash error OR critical OR failure OR fail OR failed OR fatal&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;What's the proper way for me to handle this?  Suppressing the eventtype throws out too much.&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;&lt;P&gt;Change the definition of the eventtypes in the Manager?  (Will my changes be lost on an upgrade?)   I think I would add an os_type tag and then reference that in the eventtypes.&lt;/P&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;P&gt;um .... leave it as is?&lt;/P&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;P&gt;Better option that I'm not aware of?&lt;/P&gt;&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;I don't want to uninstall the App.  It's useful elsewhere.&lt;/P&gt;

&lt;P&gt;Thanks,&lt;BR /&gt;
Mike&lt;/P&gt;</description>
      <pubDate>Mon, 05 Aug 2013 18:07:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/nix-errors-casting-too-wide-a-net/m-p/25116#M754</guid>
      <dc:creator>michaelgardner</dc:creator>
      <dc:date>2013-08-05T18:07:38Z</dc:date>
    </item>
    <item>
      <title>Re: nix_errors casting too wide a net?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/nix-errors-casting-too-wide-a-net/m-p/25117#M755</link>
      <description>&lt;P&gt;The nix_errors eventtype is too broad, agreed.  You could do a few things:&lt;/P&gt;

&lt;OL&gt;
&lt;LI&gt;Turn off global sharing for this eventtype in Manager&lt;/LI&gt;
&lt;LI&gt;Change the eventtype to be scoped to your unix data (e.g. index=os sourcetype=stash error OR ...)&lt;/LI&gt;
&lt;/OL&gt;</description>
      <pubDate>Mon, 05 Aug 2013 19:47:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/nix-errors-casting-too-wide-a-net/m-p/25117#M755</guid>
      <dc:creator>araitz</dc:creator>
      <dc:date>2013-08-05T19:47:48Z</dc:date>
    </item>
    <item>
      <title>Re: nix_errors casting too wide a net?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/nix-errors-casting-too-wide-a-net/m-p/25118#M756</link>
      <description>&lt;P&gt;Thanks, araitz.  The removal of the global scope for the eventtypes has really cut down the noise.&lt;/P&gt;

&lt;P&gt;Aside: exptremely tedious to change the 100+ *NIX eventtypes via the GUI. I'm sure there was a better way via the .conf files.  Planning to enroll in some Splunk Admin courses.&lt;/P&gt;</description>
      <pubDate>Thu, 08 Aug 2013 12:17:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/nix-errors-casting-too-wide-a-net/m-p/25118#M756</guid>
      <dc:creator>michaelgardner</dc:creator>
      <dc:date>2013-08-08T12:17:55Z</dc:date>
    </item>
  </channel>
</rss>

