All Apps and Add-ons

Missing source and sourcetype in selected and interesting fields

balmeida
Explorer

Hi,

Somehow, when the Linux Auditd Technology Add-On is installed on our SplunkCloud deployment, the source and sourcetype fields disappear from selected fields or interesting fields whenever a linux:audit event is present in the search results.

I can still use them in the search.

As soon as I disable the addon, the fields return

Assuming this search always contains linux:audit data, this is the behaviour I am seeing:

# Fields missing:
host=ip-10-231-16-14 index=test

# Fields missing:
host=ip-10-231-16-14 index=test sourcetype=linux:audit

# Fields appear correctly:
host=ip-10-231-16-14 index=test sourcetype!=linux:audit

I've never seen this kind of behaviour, any ideas what's going on?

Thanks

0 Karma

doksu
Contributor

@balmeida that's super weird. Thanks for bringing it to my attention. Could you please open a ticket with support as that sounds like a Splunk bug.

0 Karma
Get Updates on the Splunk Community!

Splunk Observability Cloud's AI Assistant in Action Series: Auditing Compliance and ...

This is the third post in the Splunk Observability Cloud’s AI Assistant in Action series that digs into how to ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

What You Read The Most: Splunk Lantern’s Most Popular Articles!

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...