Splunk Search

Is there any way to prevent additional sourcetypes from being added to the normalized search?

khevans
Path Finder

I'm running a search and I've noticed that there are a ton of additional sourcetypes (like f5_bigip:, pan:, WMI:*) being added into my search. I assume this has something to do with CIM compliance by our Splunk admins.

Is there any way that I can prevent these additional sourcetypes from being added to my search? I do not have administrative permissions, so is there something that I can add into my search query?

My search has nothing to do with those sourcetypes and my index does not contain data that's relevant to that. I am worried that it may degrade the performance of my query, which is sparse and already a bit slow.

0 Karma
Get Updates on the Splunk Community!

Using Machine Learning for Hunting Security Threats

WATCH NOW Seeing the exponential hike in global cyber threat spectrum, organizations are now striving more for ...

Observability Newsletter Highlights | March 2023

 March 2023 | Check out the latest and greatestSplunk APM's New Tag Filter ExperienceSplunk APM has updated ...

Security Newsletter Updates | March 2023

 March 2023 | Check out the latest and greatestUnify Your Security Operations with Splunk Mission Control The ...