Splunk Enterprise

Why is TA_inix app generating false positive alerts?

glpadilla_sol
Path Finder

Hello everyone, 

We are using the Ta_nix add-on to get some logs from the Linux servers.

But we notice that at the Monitor console when we run the Health Check we get this Alert

glpadilla_sol_0-1644944569755.png

That index comes from that specific app and looks like is generation a lot of sourcetypes. I checked the documentation and I cannot see it as a know issue. 

So I would like to know if this is an expected behavior or if there is any way we can fix this. 

Splunk Enterprise: 8.2.2 - over x86_64 x86_64 GNU/Linux

Splunk_TA_nix : 8.3.1

 

Thank you in advance

Labels (1)
0 Karma

PickleRick
SplunkTrust
SplunkTrust

I'd treat this check as more of a "sanity check" than a really technical one. There is no real technical cons against having those sourcetypes. It's just that if you push many different sourcetypes into a single index, maybe it's a situation in which you'd like to split them into different indexes because the data in those sourcetypes is of completely separate types, uses and so on and you're gonna suddenly discover one day that you might want to limit access to only one of them. That's all.

Another situation where this would be worrying is if the data was getting into that index in an uncontrolled manner - as a default main index or if it was your last resort index.

0 Karma

glpadilla_sol
Path Finder

Thank you so much!

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Some of the health checks are of limited utility.  This is one of them.  Ignore it or tune it so it stops reporting.

---
If this reply helps you, Karma would be appreciated.
Get Updates on the Splunk Community!

Splunk Search APIを使えば調査過程が残せます

   このゲストブログは、JCOM株式会社の情報セキュリティ本部・専任部長である渡辺慎太郎氏によって執筆されました。 Note: This article is published in both Japanese ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...