All Apps and Add-ons

After adding a field to Splunk Add-on for Unix and Linux - interfaces.sh, why am I now seeing the headers in my search results?

mikelanghorst
Motivator

I needed the results of dropped packets on an interface, so I modified the default interfaces.sh script to include those fields. I tested deploying to a small number of dev hosts and everything looked fine.

When I moved it to a bigger set of servers this morning, I started seeing the header in the search results. Since Splunk is now passing that and other *nix source types to "|multikv" by default, what could be going on here? Not sure where to look for this.

0 Karma

jcoates_splunk
Splunk Employee
Splunk Employee

what is the modification that you made?

0 Karma
Get Updates on the Splunk Community!

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...

What’s New in Splunk Observability – September 2025

What's NewWe are excited to announce the latest enhancements to Splunk Observability, designed to help ITOps ...

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...