Splunk Enterprise

Why is TA_inix app generating false positive alerts?

glpadilla_sol
Path Finder

Hello everyone, 

We are using the Ta_nix add-on to get some logs from the Linux servers.

But we notice that at the Monitor console when we run the Health Check we get this Alert

glpadilla_sol_0-1644944569755.png

That index comes from that specific app and looks like is generation a lot of sourcetypes. I checked the documentation and I cannot see it as a know issue. 

So I would like to know if this is an expected behavior or if there is any way we can fix this. 

Splunk Enterprise: 8.2.2 - over x86_64 x86_64 GNU/Linux

Splunk_TA_nix : 8.3.1

 

Thank you in advance

Labels (1)
0 Karma

PickleRick
SplunkTrust
SplunkTrust

I'd treat this check as more of a "sanity check" than a really technical one. There is no real technical cons against having those sourcetypes. It's just that if you push many different sourcetypes into a single index, maybe it's a situation in which you'd like to split them into different indexes because the data in those sourcetypes is of completely separate types, uses and so on and you're gonna suddenly discover one day that you might want to limit access to only one of them. That's all.

Another situation where this would be worrying is if the data was getting into that index in an uncontrolled manner - as a default main index or if it was your last resort index.

0 Karma

glpadilla_sol
Path Finder

Thank you so much!

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Some of the health checks are of limited utility.  This is one of them.  Ignore it or tune it so it stops reporting.

---
If this reply helps you, Karma would be appreciated.
Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer Certification at ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...