I have the following error message appearing every ~3 seconds. My searches have not yielded anyone who has this issue. Anyone come across it?
ERROR EAIOutParameters - invalid entry title in toAtom(): INDEXER_MISSING_INDEX-\x00\x00j\x00fre
My thoughts are that I have a bad data source coming in, which is somehow telling Splunk that it needs to be deposited into an index called \x00\x00j\x00fre
- although trying to find it isn't too easy!
I was having this same issue. Removed splunk_add_on_nix from the SH's (SA-Nix from indexers as well), and this error disappeared.
I was having this same issue. Removed splunk_add_on_nix from the SH's (SA-Nix from indexers as well), and this error disappeared.
I also had the add on enabled, I can't prove this was the cause as I no longer have access to the environment so as good an answer as we're going to get from @tlelle!
Happening to me at the moment as well. Strange error.
hi, did you find a solution for this problem. It is happening to me now
Never found the solution, I believe it was something strange coming from a Universal Forwarder (A windows one) which fixed itself - I think it was for mis-configured index for Windows eventlog data as that happened to coincide (seems there was a bug in a older version of the UC for Windows which meant some eventlog data was forwarded despite no options being selected during installation).
Fixed itself so never investigated further.