Splunk Enterprise

Why is TA_inix app generating false positive alerts?

glpadilla_sol
Path Finder

Hello everyone, 

We are using the Ta_nix add-on to get some logs from the Linux servers.

But we notice that at the Monitor console when we run the Health Check we get this Alert

glpadilla_sol_0-1644944569755.png

That index comes from that specific app and looks like is generation a lot of sourcetypes. I checked the documentation and I cannot see it as a know issue. 

So I would like to know if this is an expected behavior or if there is any way we can fix this. 

Splunk Enterprise: 8.2.2 - over x86_64 x86_64 GNU/Linux

Splunk_TA_nix : 8.3.1

 

Thank you in advance

Labels (1)
0 Karma

PickleRick
SplunkTrust
SplunkTrust

I'd treat this check as more of a "sanity check" than a really technical one. There is no real technical cons against having those sourcetypes. It's just that if you push many different sourcetypes into a single index, maybe it's a situation in which you'd like to split them into different indexes because the data in those sourcetypes is of completely separate types, uses and so on and you're gonna suddenly discover one day that you might want to limit access to only one of them. That's all.

Another situation where this would be worrying is if the data was getting into that index in an uncontrolled manner - as a default main index or if it was your last resort index.

0 Karma

glpadilla_sol
Path Finder

Thank you so much!

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Some of the health checks are of limited utility.  This is one of them.  Ignore it or tune it so it stops reporting.

---
If this reply helps you, Karma would be appreciated.
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...