Hello,
When i updated my Splunk server from 4.3.4 to version 5., i got an error as running:
| metadata type=host
error is "Error in 'metadata': No 'host' key found in results. Cannot merge metadata."
I restarted and tried again now it worked but as running the other:
| metadata type=sourcetypes
error is "Error in 'metadata': No 'sourcetypes' key found in results. Cannot merge metadata.".
Can you suggest me how to solve that problem ?
We saw this same error, until we upgraded our indexers. Once the indexers were upgraded and they finished the migration process the error was gone.
This should be the accepted answer. We had this problem this morning, upgraded one of our indexers to Splunk 5.0.2 and the metadata command is no longer returning errors.
I just upgraded from 4.3.3 to 5.0.1 and have the exact same issue.