All Apps and Add-ons

Why am I getting "Invalid key in stanza" errors for the Splunk Add-on for Microsoft Windows default configuration?

casey18cc
Explorer

I am getting an error when I restart splunk:

Invalid key in stanza [WinEventLog:Application] in /opt/splunk/etc/apps/Splunk_TA_windows/default/inputs.conf, line 16: start_from  (value:  oldest)
Invalid key in stanza [WinEventLog:Application] in /opt/splunk/etc/apps/Splunk_TA_windows/default/inputs.conf, line 17: current_only  (value:  0)
Invalid key in stanza [WinEventLog:Application] in /opt/splunk/etc/apps/Splunk_TA_windows/default/inputs.conf, line 18: checkpointInterval  (value:  5)
Invalid key in stanza [WinEventLog:Security] in /opt/splunk/etc/apps/Splunk_TA_windows/default/inputs.conf, line 22: start_from  (value:  oldest)
Invalid key in stanza [WinEventLog:Security] in /opt/splunk/etc/apps/Splunk_TA_windows/default/inputs.conf, line 23: current_only  (value:  0)
Invalid key in stanza [WinEventLog:Security] in /opt/splunk/etc/apps/Splunk_TA_windows/default/inputs.conf, line 24: evt_resolve_ad_obj  (value:  1)
Invalid key in stanza [WinEventLog:Security] in /opt/splunk/etc/apps/Splunk_TA_windows/default/inputs.conf, line 25: checkpointInterval  (value:  5)
Invalid key in stanza [WinEventLog:System] in /opt/splunk/etc/apps/Splunk_TA_windows/default/inputs.conf, line 29: start_from  (value:  oldest)
Invalid key in stanza [WinEventLog:System] in /opt/splunk/etc/apps/Splunk_TA_windows/default/inputs.conf, line 30: current_only  (value:  0)
Invalid key in stanza [WinEventLog:System] in /opt/splunk/etc/apps/Splunk_TA_windows/default/inputs.conf, line 31: checkpointInterval  (value:  5)

I am not sure why I would be getting this error from the default folder. Is this expected, or is there a way to clean this up?

Thanks,

Casey

0 Karma

jcoates_splunk
Splunk Employee
Splunk Employee

This is caused by the License Monitor app -- uninstall it, and the problem will go away.

muebel
SplunkTrust
SplunkTrust

What version of splunk? What version of the add-on?

casey18cc
Explorer

we are running Splunk 6.2.2.

I am trying to find the Splunk_TA_windows version, and while I can't find the version number, it is dated 8/27/2012, so an upgrade does appear to be in order.

While I have the Splunk Health overview installed on our deployment server, I do not have the License Monitor app installed.

0 Karma

josh_FentonAF
Engager

Having the same issue and no license monitor app installed in the environment. Has anyone solved this?

What is interesting is these are flagging as invalid keys, but they do in fact work.

Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...