Splunk Enterprise Security

Enterprise Security: why is sourcetype="bluecoat:proxysg:admin:file" tagged as error

danielbb
Motivator

The bluecloat sourcetype "bluecoat:proxysg:admin:file" is tagged as error. It's also not listed at Sourcetypes for the Splunk Add-on for Symantec Blue Coat ProxySG

Why is it?

0 Karma

aholzel
Communicator

The eventtype "err0r" from the Splunk_SA_CIM is a very broad search.. that is almost a catch all

gjanders
SplunkTrust
SplunkTrust

Do you happen to have the Splunk TA *nix app installed? That has some very open tag=error searches.
You can see this by checking the eventtypes involved where you see tag=error....

Get Updates on the Splunk Community!

.conf24 | Day 0

Hello Splunk Community! My name is Chris, and I'm based in Canberra, Australia's capital, and I travelled for ...

Enhance Security Visibility with Splunk Enterprise Security 7.1 through Threat ...

 (view in My Videos)Struggling with alert fatigue, lack of context, and prioritization around security ...

Troubleshooting the OpenTelemetry Collector

  In this tech talk, you’ll learn how to troubleshoot the OpenTelemetry collector - from checking the ...