All Apps and Add-ons

G Suite For Splunk

keithpachulski
Engager

On install of the g-suite app I am now receiving the following error on all of my dashboards:

"Eventtype 'gsuite_internal' does not exist or is disabled."

What do I need to do to correct this error?

0 Karma

pablobarquin
Explorer

Hello,

I have exactly the same issue. Weird thing is that Gsuite app is installed since looong time ago with no issues and suddenly this message is appearing in all user's searches/reports/dashboards.
The index we are using is googleapps so I have no idea why this is raising suddenly.
Any ideas?
Thanks!

0 Karma

vhharanpositka
Path Finder

Hi

Actually this error occurred based on the index that you integrate the g-suite data.
The default index will be the main index.

Check the eventtype googleapps which has the search string as (index=main sourcetype=GSuiteForSplunk:error OR sourcetype=gapps:*) OR index=googleapps

If the eventtype and the index is matched then that error will not occur.

Thanks

0 Karma

vhharanpositka
Path Finder

Hi

Actually this error occurred based on the index that you integrate the g-suite data.
The default index will be the main index.

Check the eventtype googleapps which has the search string as (index=main sourcetype=GSuiteForSplunk:error OR sourcetype=gapps:*) OR index=googleapps

If the eventtype and the index is matched then that error will not occur.

Thanks

0 Karma

tbrouwer
New Member

I have the same issue. Hoping someone can answer

0 Karma

vhharanpositka
Path Finder

Hi

Actually this error occurred based on the index that you integrate the g-suite data.
The default index will be the main index.

Check the eventtype googleapps which has the search string as (index=main sourcetype=GSuiteForSplunk:error OR sourcetype=gapps:*) OR index=googleapps

If the eventtype and the index is matched then that error will not occur.

Thanks

0 Karma
Get Updates on the Splunk Community!

Index This | When is October more than just the tenth month?

October 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

What’s New & Next in Splunk SOAR

 Security teams today are dealing with more alerts, more tools, and more pressure than ever.  Join us for an ...