All Apps and Add-ons

Field Extractor and non-default indicies

eegilbert
Explorer

Hello,

I'm using the 2.1 version of the Field Extractor app and it doesn't appear to like non-default indexes:

Unable to initialize workflow
information: Ignoring unknown index
'indexname')

Stacktrace: Traceback (most recent
call last): File "", line 397,
in initInfoFromWorkflow File
"", line 494, in
setCurrentIndex ModelException:
Ignoring unknown index 'indexname'

Please note indexname is my generic index name for this example.

1 Solution

carasso
Splunk Employee
Splunk Employee

I fixed the problem. Update the app to 2.3.

I just updated the Field Extractor app to work in distributed environments, so it works with indexes not on the search head.

 http://apps.splunk.com/app/494/

Let me know if you see any problems.

View solution in original post

0 Karma

carasso
Splunk Employee
Splunk Employee

I fixed the problem. Update the app to 2.3.

I just updated the Field Extractor app to work in distributed environments, so it works with indexes not on the search head.

 http://apps.splunk.com/app/494/

Let me know if you see any problems.

0 Karma

scsr_1
New Member

My network data has its own index and I am receiving the same error.

Unable to initialize workflow information: Ignoring unknown index 'index_name')

I checked with our Splunk Admin and he said the permissions are correct.

0 Karma

carasso
Splunk Employee
Splunk Employee

Is it possible the user running the field extractor does not have permission to use that index?

0 Karma

eegilbert
Explorer

Hello, I did wonder about this, however I'm using splunk with admin level permissions. I've even tried setting the app for read/write for all as a test and still get the same result.

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...