All Apps and Add-ons

Missing source and sourcetype in selected and interesting fields



Somehow, when the Linux Auditd Technology Add-On is installed on our SplunkCloud deployment, the source and sourcetype fields disappear from selected fields or interesting fields whenever a linux:audit event is present in the search results.

I can still use them in the search.

As soon as I disable the addon, the fields return

Assuming this search always contains linux:audit data, this is the behaviour I am seeing:

# Fields missing:
host=ip-10-231-16-14 index=test

# Fields missing:
host=ip-10-231-16-14 index=test sourcetype=linux:audit

# Fields appear correctly:
host=ip-10-231-16-14 index=test sourcetype!=linux:audit

I've never seen this kind of behaviour, any ideas what's going on?


0 Karma


@balmeida that's super weird. Thanks for bringing it to my attention. Could you please open a ticket with support as that sounds like a Splunk bug.

0 Karma
Get Updates on the Splunk Community!

.conf24 | Day 0

Hello Splunk Community! My name is Chris, and I'm based in Canberra, Australia's capital, and I travelled for ...

Enhance Security Visibility with Splunk Enterprise Security 7.1 through Threat ...

 (view in My Videos)Struggling with alert fatigue, lack of context, and prioritization around security ...

Troubleshooting the OpenTelemetry Collector

  In this tech talk, you’ll learn how to troubleshoot the OpenTelemetry collector - from checking the ...