All Apps and Add-ons

Why am I getting "Invalid key in stanza" errors for the Splunk Add-on for Microsoft Windows default configuration?

casey18cc
Explorer

I am getting an error when I restart splunk:

Invalid key in stanza [WinEventLog:Application] in /opt/splunk/etc/apps/Splunk_TA_windows/default/inputs.conf, line 16: start_from  (value:  oldest)
Invalid key in stanza [WinEventLog:Application] in /opt/splunk/etc/apps/Splunk_TA_windows/default/inputs.conf, line 17: current_only  (value:  0)
Invalid key in stanza [WinEventLog:Application] in /opt/splunk/etc/apps/Splunk_TA_windows/default/inputs.conf, line 18: checkpointInterval  (value:  5)
Invalid key in stanza [WinEventLog:Security] in /opt/splunk/etc/apps/Splunk_TA_windows/default/inputs.conf, line 22: start_from  (value:  oldest)
Invalid key in stanza [WinEventLog:Security] in /opt/splunk/etc/apps/Splunk_TA_windows/default/inputs.conf, line 23: current_only  (value:  0)
Invalid key in stanza [WinEventLog:Security] in /opt/splunk/etc/apps/Splunk_TA_windows/default/inputs.conf, line 24: evt_resolve_ad_obj  (value:  1)
Invalid key in stanza [WinEventLog:Security] in /opt/splunk/etc/apps/Splunk_TA_windows/default/inputs.conf, line 25: checkpointInterval  (value:  5)
Invalid key in stanza [WinEventLog:System] in /opt/splunk/etc/apps/Splunk_TA_windows/default/inputs.conf, line 29: start_from  (value:  oldest)
Invalid key in stanza [WinEventLog:System] in /opt/splunk/etc/apps/Splunk_TA_windows/default/inputs.conf, line 30: current_only  (value:  0)
Invalid key in stanza [WinEventLog:System] in /opt/splunk/etc/apps/Splunk_TA_windows/default/inputs.conf, line 31: checkpointInterval  (value:  5)

I am not sure why I would be getting this error from the default folder. Is this expected, or is there a way to clean this up?

Thanks,

Casey

0 Karma

jcoates_splunk
Splunk Employee
Splunk Employee

This is caused by the License Monitor app -- uninstall it, and the problem will go away.

muebel
SplunkTrust
SplunkTrust

What version of splunk? What version of the add-on?

casey18cc
Explorer

we are running Splunk 6.2.2.

I am trying to find the Splunk_TA_windows version, and while I can't find the version number, it is dated 8/27/2012, so an upgrade does appear to be in order.

While I have the Splunk Health overview installed on our deployment server, I do not have the License Monitor app installed.

0 Karma

josh_FentonAF
Engager

Having the same issue and no license monitor app installed in the environment. Has anyone solved this?

What is interesting is these are flagging as invalid keys, but they do in fact work.

Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...