Splunk Search

metadata command returns duplicate sourcetypes - "WinEventLog"

Path Finder


I have this command:

| metadata type=sourcetypes index=wineventlog

The problem is that there are returned multiple lines for  "WinEventLog" sourcetype so I dont understand why that when the names are absolutely same.

I expect to get 1 line per sourcetype.

If I search with index=wineventlog and stats by sourcetype - there is no problem so it is something with metadata command

Same issue  for "wineventlog" sourcetype

Labels (1)
0 Karma

Super Champion

Can you share sourcetypes returned from the search?

If this helps, give a like below.
0 Karma

New Member


It could be because you have multiple sources. Check with:

| metadata type=sources index=wineventlog

 It will likely show WinEventLog:Security, WinEventLog:System, etc.

0 Karma
.conf21 Now Fully Virtual!
Register for FREE Today!

We've made .conf21 totally virtual and totally FREE! Our completely online experience will run from 10/19 through 10/20 with some additional events, too!