Splunk Search

WARN : Eventtype 'xxxxxxxx' does not exist or is disabled. Errors coming from indexers

pbrinkman
Path Finder

hi all,

I have had a number of scheduled searches that failed, all returning the same errors.

WARN : Eventtype 'xxxxxxxx' does not exist or is disabled.
WARN : [INDEXER 1] Eventtype 'xxxxxxxx' does not exist or is disabled.
WARN : [INDEXER 2] Eventtype 'xxxxxxxx' does not exist or is disabled.
WARN : [INDEXER 3] Eventtype 'xxxxxxxx' does not exist or is disabled.
WARN : [INDEXER 4] Eventtype 'xxxxxxxx' does not exist or is disabled.

Could someone explain why the indexers were returning the errors when all eventtypes are located on the search heads ?

cheers
Paul

Tags (1)
0 Karma

FrankVl
Ultra Champion

Search heads push a bundle of knowledge objects to the indexers, to enable the indexers to perform searches.

These errors are typically caused by a tag (in tags.conf) that refers to an eventtype that is not defined / disabled / in another app and not shared / not readable by current user.

0 Karma
Get Updates on the Splunk Community!

Enter the Splunk Community Dashboard Challenge for Your Chance to Win!

The Splunk Community Dashboard Challenge is underway! This is your chance to showcase your skills in creating ...

.conf24 | Session Scheduler is Live!!

.conf24 is happening June 11 - 14 in Las Vegas, and we are thrilled to announce that the conference catalog ...

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...