Deployment Architecture

I have an index created and the same index I named in inputs.conf but once I restart the forwarder it says the index is not configured ?

akumarsripathi
New Member

Search peer xxx(servername) has the following message: Received event for unconfigured/disabled/deleted index=\xC2\xA0my_data with source="source::/opt/mylogs/apache/logs/xxx.logs" host="host::servername" sourcetype="sourcetype::xxx.logs". So far received events from 1 missing index(es).

Above is the message banner which I see once I restart the forwarder. I created index name as my_data and I see other source is already loading to mentioned index.
These are apache tomcat logs.

Tags (1)
0 Karma

manjunathmeti
SplunkTrust
SplunkTrust

You index attribute contains special character in inputs.conf. Remove \xC2\xA0 in index=\xC2\xA0my_data in inputs.conf and restart forwarder.

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...