Splunk Enterprise

Kept receiving error message at indexer

Nicholas_Key
Splunk Employee
Splunk Employee

Hi all,

I'm trying to forward my summarized events from an indexer (machine1) to multiple indexers (machine2 and machine 3) and I'm seeing this error message at machine2 and machine3:

received event for unconfigured/disabled index='summary_forwarders' with source='source::All forwarders - regenerator summary index' host='host::machine1' sourcetype='sourcetype::stash'

I'm really sure that I'm not using summary_forwarders in any way.

Any idea why this happens?

Tags (1)
0 Karma

Stephen_Sorkin
Splunk Employee
Splunk Employee

You have a summary index search configured on machine1 that puts data into the index summary_forwarders that doesn't exist on machine2 or machine3. This is probably from the beta SplunkDeploymentMonitor app. Is it installed only on machine1?

Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...