Macear
06/19/2023, 5:24 PME0619 02:00:21.501096 33683 eventsubscriberplugin.cpp:705] Found 1106 invalid events (1106 have been successfully erased)Kathy Satterlee
06/19/2023, 5:48 PMMacear
06/19/2023, 6:00 PMMacear
06/19/2023, 6:04 PMprocess_file_events at all. The issue presents on several hosts, not so many. But still..Macear
06/19/2023, 6:07 PMinvalid events? What’s wrong with them?Lucas Rodriguez
06/19/2023, 6:54 PMMacear
06/19/2023, 8:12 PMeventsubscriberplugin.cpp reports the error, I think it’s related to the process_events table. This is the only *_events table we use.Macear
06/19/2023, 8:25 PMMacear
06/20/2023, 7:01 AMlvm syslog app-name. For example from `/var/log/messages`:
# cat /var/log/messages | grep "lvm\[" | tail -n 1
Jun 20 09:13:59 splnk lvm[1242495]: {"name":"pack/InfoSec Events Audit/InfoSec Events Audit: Process","hostIdentifier":"splnk","calendarTime":"Tue Jun 20 06:13:59 2023 UTC","unixTime":1687241639,"epoch":0,"counter":9114,"numerics":false,"decorations":{"host_uuid":"7a103c42-5e68-9c61-950d-ef0d02b11be8","hostname":"splnk"},"columns":{"auid":"4294967295","cmdline":"splunk-optimize -d --msidx-comp-block-size 1024 /mnt/db/dhcp/db/hot_v1_9 -x 375529314816 --log-to--splunkd-log --write-level 1 --tsidx-target-size 1572864000","ctime":"1682590162","cwd":"\"/\"","egid":"1519","euid":"1517","gid":"1519","parent":"2180","path":"/opt/splunk/bin/splunk-optimize","pid":"1985420","time":"1687241628","uid":"1517"},"action":"added"}Macear
06/27/2023, 5:18 AM