All Apps and Add-ons

After adding a field to Splunk Add-on for Unix and Linux - interfaces.sh, why am I now seeing the headers in my search results?

mikelanghorst
Motivator

I needed the results of dropped packets on an interface, so I modified the default interfaces.sh script to include those fields. I tested deploying to a small number of dev hosts and everything looked fine.

When I moved it to a bigger set of servers this morning, I started seeing the header in the search results. Since Splunk is now passing that and other *nix source types to "|multikv" by default, what could be going on here? Not sure where to look for this.

0 Karma

jcoates_splunk
Splunk Employee
Splunk Employee

what is the modification that you made?

0 Karma
Get Updates on the Splunk Community!

Aligning Observability Costs with Business Value: Practical Strategies

 Join us for an engaging Tech Talk on Aligning Observability Costs with Business Value: Practical ...

Mastering Data Pipelines: Unlocking Value with Splunk

 In today's AI-driven world, organizations must balance the challenges of managing the explosion of data with ...

Splunk Up Your Game: Why It's Time to Embrace Python 3.9+ and OpenSSL 3.0

Did you know that for Splunk Enterprise 9.4, Python 3.9 is the default interpreter? This shift is not just a ...