Hi All,
When I installed the splunk universal forwarder on my linux server and restarted the splunk service, there run an error like below:'Invalid key in stanza [monitor:///tmp/nohup_1.out] in /opt/splunkforwarder/etc/system/local/inputs.conf, line 5: disable (value: 0)'. Was it a normal message? I need your help!
Thanks,
Henry
Hi ford1863,
change disable
to disabled
in inputs.conf monitor stanza.
hope this helps ...
cheers, MuS
It is what it says - you have an invalid key in your inputs.conf. It's supposed to be "disabled", not "disable". On the other hand, the default for that value is 0 anyway, so it won't make a difference - the stanza should be applied anyway.
Hi ford1863,
change disable
to disabled
in inputs.conf monitor stanza.
hope this helps ...
cheers, MuS