Deployment Architecture

I have an index created and the same index I named in inputs.conf but once I restart the forwarder it says the index is not configured ?

akumarsripathi
New Member

Search peer xxx(servername) has the following message: Received event for unconfigured/disabled/deleted index=\xC2\xA0my_data with source="source::/opt/mylogs/apache/logs/xxx.logs" host="host::servername" sourcetype="sourcetype::xxx.logs". So far received events from 1 missing index(es).

Above is the message banner which I see once I restart the forwarder. I created index name as my_data and I see other source is already loading to mentioned index.
These are apache tomcat logs.

Tags (1)
0 Karma

manjunathmeti
Champion

You index attribute contains special character in inputs.conf. Remove \xC2\xA0 in index=\xC2\xA0my_data in inputs.conf and restart forwarder.

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...