I just upgraded one of my splunk forwarders to version 4.1.4 and now I'm seeing the following error message in my internal logs:
WARN IniFile - C:\Program Files\Splunk\etc\apps\search\default\inputs.conf, line: 2: Cannot parse into key-value pair: This file intentionally left empty. Please do not delete it
This problem is caused by a bogus configuration file entry. To prevent this error message, open up your $SPLUNK_HOME/etc/apps/search/default/inputs.conf
config file, which could contain the following:
# Copyright (C) 2005-2010 Splunk Inc. All Rights Reserved. Version 4.1.4
This file intentionally left empty. Please do not delete it.
Simply remove or comment out (add a "#") to the second line and the error message will go away.
Example of a fixed file:
# Copyright (C) 2005-2010 Splunk Inc. All Rights Reserved. Version 4.1.4
# This file intentionally left empty. Please do not delete it.