Security

HEC _raw sourcetype

apider
Explorer

Hi,

I have a raw HEC set up as follows (no sourcetype set):

[http://aiwa_request_input]
disabled = 0
index = test
indexes = test
sourcetype =
token = xxxxxxx-xxx-x-x-xx

When I put an event into it and specify the sourcetype in the event it gets indexed as two sourcetypes; httpevent and "my" sourcetype "aiwa:request".

host = aiwa3dev-aiwa3-dev.cumulus.sebank.seindex = testlinecount = 1punct = {"":"--::.","":"","":":","":{"":"","":"","":{"":""source = http:aiwa_request_inputsourcetype = httpevent sourcetype = aiwa:requestsplunk_server = lsp7150c.sebank.se

From above: sourcetype = httpevent sourcetype = aiwa:request

How can I change this to only be the ST in the event itself.
My props & transforms are blank.

Cheers
/F

0 Karma

smisriv
Observer

Did you manage to fix this. I also get two sourceTypes: httpEvent and aws:cloudTrail

0 Karma

apider
Explorer

The problem this is causing me is that I somehow end up with events with TWO sourcetypes, as it seems.

When i search: index=test sourcetype="aiwa:request"
I don't get a match.

But when i do: index=test sourcetype="httpevent"
I DO get a match.

Really confusing, as it looks like the event has BOTH souretypes.
I am posting the event to HEC raw endpoint with sourcetype set to "aiwa:request".

alt text

Is this expected behavior?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

A Four-Part Event Series: Full Stack Observability For the AI Era

As AI reshapes applications, infrastructure, and the way teams operate, the traditional boundaries of ...

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Event Series: Level up your SOC: Advancing with Splunk Enterprise Security

AI has fundamentally raised the stakes for security operations, and this three-part series is your guide to ...