Splunk Search

How to remove "received event for unconfigured/disabled/deleted index" messages

mkelderm
Path Finder

Due to some mistake, I am getting this messages:

received event for unconfigured/disabled/deleted index='2013-03-10 19:53:34_stats' with source='DatabaseQueryMonitor' host='host::Counts@PROD' sourcetype='sourcetype::appman:ExecutionTimems=' (1 missing total

How can I tell Splunk> to ge rid of this message. Clicking on the X in the web-interface does not help.

0 Karma
1 Solution

mkelderm
Path Finder

The issue is related to Windows. The log files is still being updated while Splunk wants to read it. The log file is created by a PHP script started every 30 minutes.

In my inputs.conf I added:

ignoreOlderThan = 240m
alwaysOpenFile = 1

View solution in original post

mce128
Explorer

Okay, I know this is a few months old, but I am rather curious as to whether or not the OP had determined a way to suppress the warning message about the missing index?

FRoth
Contributor

Me too. Any updates?

0 Karma

mkelderm
Path Finder

The issue is related to Windows. The log files is still being updated while Splunk wants to read it. The log file is created by a PHP script started every 30 minutes.

In my inputs.conf I added:

ignoreOlderThan = 240m
alwaysOpenFile = 1

mkelderm
Path Finder

the issue is not the input. but the application that supplied the data to the forwarder. I want to ignore this message. It is fixed now, but i still get the messages. Is Splunk Forwarder keeping these messages on his local queue?

0 Karma

BobM
Builder

The problem is one of your data sources, probably on a forwarder, is trying to send data to an index you don't have set up. The messages are telling you that they are being dropped so you are losing data. To fix this, you need to either edit the inputs.conf on the forwarder to point to a valid index, or create the index it is trying to send to on your indexer/s.

It is possible, though less likely, you have a faulty transforms.conf on your indexer that is trying to redirect it to an invalid index.

If you can't find the problem yourself, send an email to support@splunk.com and they will be able to find the error.

Bob

mkelderm
Path Finder

the issue is not the input. but the application that supplied the data to the forwarder. I want to ignore this message. It is fixed now, but i still get the messages. Is Splunk Forwarder keeping these messages on his local queue?

0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...