I went into the lookup definitions and there was no entry for sonicwall_os_guess.
Also, I've been receiving messages in splunk stating "received event for unconfigured/disabled/deleted index='sonicwall_summary' with source='source::total_mb' host='host::ERMCO-BS1' sourcetype='sourcetype::stash' (1 missing total)"
I'm not sure if this is related or not.
... View more