Follow the steps below to debug using respective logs:

1.In Splunk Enterprise, navigate to Search & Reporting.

2.Search with the following search queries and a time range that covers the alert triggering time.

Use the query below to search for splunkd service logs. NetworkBrain App logs are included as well.

oindex=_internal sourcetype=splunkd

Add the following keywords into the query above to filter specific logs.

Map Type

Keyword

NetworkBrain Automation - Device

Neighbor map response

NetworkBrain Automation - Multi-Device

Multi_devices map response

NetworkBrain Automation - Site

Site map response

NetworkBrain Automation - Path

Path map response

NetworkBrain Automation - ACI

Context map response

NetworkBrain Automation - Existing Map

Existing map response