<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to clear up eventgen.conf &amp;quot;Invalid key in stanza&amp;quot; errors after installing the Splunk Add-on for Microsoft Windows on Linux indexers? in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-clear-up-eventgen-conf-quot-Invalid-key-in-stanza-quot/m-p/273943#M31891</link>
    <description>&lt;P&gt;Are you doing this for the "props"?  The TA only goes on the windows forwarders to my knowledge and isn't required on the indexers.&lt;/P&gt;</description>
    <pubDate>Tue, 19 Jul 2016 13:13:18 GMT</pubDate>
    <dc:creator>jkat54</dc:creator>
    <dc:date>2016-07-19T13:13:18Z</dc:date>
    <item>
      <title>How to clear up eventgen.conf "Invalid key in stanza" errors after installing the Splunk Add-on for Microsoft Windows on Linux indexers?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-clear-up-eventgen-conf-quot-Invalid-key-in-stanza-quot/m-p/273940#M31888</link>
      <description>&lt;P&gt;Version 6.4 of Splunk Enterprise on my linux indexers, after I install the latest Splunk_TA_windows on it I get the following messages. How do I clean this up?:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;               Invalid key in stanza [windowsevent] in /opt/splunk_ind/etc/apps/search/local/props.conf, line 70: regex  (value:  ^(?:[^,\n]*,){3}\s+\w+="(?P&amp;lt;FQDN&amp;gt;[^"]+)(?:[^"\n]*"){2}(?P&amp;lt;OScode&amp;gt;[^"]+)[^=\n]*="(?P&amp;lt;Logfile&amp;gt;[^"]+)[^,\n]*,\s+\w+=(?P&amp;lt;EventCode&amp;gt;[^,]+)[^=\n]*=(?P&amp;lt;EventType&amp;gt;[^,]+)[^=\n]*="(?P&amp;lt;SourceName&amp;gt;[^"]+)(?:[^"\n]*"){2}(?P&amp;lt;Message&amp;gt;[^"]+)).
                Invalid key in stanza [sample.DhcpSrvLog] in /opt/splunk_ind/etc/apps/Splunk_TA_windows/default/eventgen.conf, line 5: index  (value:  windows).
                Invalid key in stanza [sample.DhcpSrvLog] in /opt/splunk_ind/etc/apps/Splunk_TA_windows/default/eventgen.conf, line 6: source (value: c:\windows\system32\dhcp\dhcpsrvlog.log).
                Invalid key in stanza [sample.DhcpSrvLog] in /opt/splunk_ind/etc/apps/Splunk_TA_windows/default/eventgen.conf, line 7: sourcetype  (value:  DhcpSrvLog).
                Invalid key in stanza [.*\.WindowsUpdateLog] in /opt/splunk_ind/etc/apps/Splunk_TA_windows/default/eventgen.conf, line 21: index  (value:  windows).
                Invalid key in stanza [.*\.WindowsUpdateLog] in /opt/splunk_ind/etc/apps/Splunk_TA_windows/default/eventgen.conf, line 22: source  (value:  WindowsUpdateLog).
                Invalid key in stanza [.*\.WindowsUpdateLog] in /opt/splunk_ind/etc/apps/Splunk_TA_windows/default/eventgen.conf, line 23: sourcetype  (value:  WindowsUpdateLog).
                Invalid key in stanza [WindowsUpdateClient.19.windows] in /opt/splunk_ind/etc/apps/Splunk_TA_windows/default/eventgen.conf, line 37: index  (value:  windows).
                Invalid key in stanza [WindowsUpdateClient.19.windows] in /opt/splunk_ind/etc/apps/Splunk_TA_windows/default/eventgen.conf, line 38: source  (value:  WindowsUpdateLog).
                Invalid key in stanza [WindowsUpdateClient.19.windows] in /opt/splunk_ind/etc/apps/Splunk_TA_windows/default/eventgen.conf, line 39: sourcetype  (value:  WindowsUpdateLog).
                Invalid key in stanza [sample.win_listening_ports] in /opt/splunk_ind/etc/apps/Splunk_TA_windows/default/eventgen.conf, line 51: index  (value:  windows).
                Invalid key in stanza [sample.win_listening_ports] in /opt/splunk_ind/etc/apps/Splunk_TA_windows/default/eventgen.conf, line 52: source  (value:  Script:ListeningPorts).
                Invalid key in stanza [sample.win_listening_ports] in /opt/splunk_ind/etc/apps/Splunk_TA_windows/default/eventgen.conf, line 53: sourcetype  (value:  Script:ListeningPorts).
                Invalid key in stanza [sample.win_installed_apps] in /opt/splunk_ind/etc/apps/Splunk_TA_windows/default/eventgen.conf, line 82: index  (value:  windows).
                Invalid key in stanza [sample.win_installed_apps] in /opt/splunk_ind/etc/apps/Splunk_TA_windows/default/eventgen.conf, line 83: source  (value:  Script:InstalledApps).
                Invalid key in stanza [sample.win_installed_apps] in /opt/splunk_ind/etc/apps/Splunk_TA_windows/default/eventgen.conf, line 84: sourcetype  (value:  Script:InstalledApps).
                Invalid key in stanza [.*\.monitorware] in /opt/splunk_ind/etc/apps/Splunk_TA_windows/default/eventgen.conf, line 99: index  (value:  main).
                Invalid key in stanza [.*\.monitorware] in /opt/splunk_ind/etc/apps/Splunk_TA_windows/default/eventgen.conf, line 100: source  (value:  MonitorWare:Security).
                Invalid key in stanza [.*\.monitorware] in /opt/splunk_ind/etc/apps/Splunk_TA_windows/default/eventgen.conf, line 101: sourcetype  (value:  MonitorWare:Security).
                Invalid key in stanza [.*\.ntsyslog] in /opt/splunk_ind/etc/apps/Splunk_TA_windows/default/eventgen.conf, line 145: index  (value:  main).
                Invalid key in stanza [.*\.ntsyslog] in /opt/splunk_ind/etc/apps/Splunk_TA_windows/default/eventgen.conf, line 146: source  (value:  NTSyslog:Security).
                Invalid key in stanza [.*\.ntsyslog] in /opt/splunk_ind/etc/apps/Splunk_TA_windows/default/eventgen.conf, line 147: sourcetype  (value:  NTSyslog:Security).
                Invalid key in stanza [.*\.perfmon] in /opt/splunk_ind/etc/apps/Splunk_TA_windows/default/eventgen.conf, line 161: index  (value:  perfmon).
                Invalid key in stanza [CPUTime.perfmon] in /opt/splunk_ind/etc/apps/Splunk_TA_windows/default/eventgen.conf, line 174: index  (value:  perfmon).
                Invalid key in stanza [CPUTime.perfmon] in /opt/splunk_ind/etc/apps/Splunk_TA_windows/default/eventgen.conf, line 175: source  (value:  Perfmon:CPU).
                Invalid key in stanza [CPUTime.perfmon] in /opt/splunk_ind/etc/apps/Splunk_TA_windows/default/eventgen.conf, line 176: sourcetype  (value:  Perfmon:CPU).
                Invalid key in stanza [FreeDiskSpace.perfmon] in /opt/splunk_ind/etc/apps/Splunk_TA_windows/default/eventgen.conf, line 189: index  (value:  perfmon).
                Invalid key in stanza [FreeDiskSpace.perfmon] in /opt/splunk_ind/etc/apps/Splunk_TA_windows/default/eventgen.conf, line 190: source  (value:  Perfmon:FreeDiskSpace).
                Invalid key in stanza [FreeDiskSpace.perfmon] in /opt/splunk_ind/etc/apps/Splunk_TA_windows/default/eventgen.conf, line 191: sourcetype  (value:  Perfmon:FreeDiskSpace).
                Invalid key in stanza [Memory.perfmon] in /opt/splunk_ind/etc/apps/Splunk_TA_windows/default/eventgen.conf, line 204: source  (value:  Perfmon:Memory).
                Invalid key in stanza [Memory.perfmon] in /opt/splunk_ind/etc/apps/Splunk_TA_windows/default/eventgen.conf, line 205: sourcetype  (value:  Perfmon:Memory).
                Invalid key in stanza [LocalNetwork.perfmon] in /opt/splunk_ind/etc/apps/Splunk_TA_windows/default/eventgen.conf, line 210: source  (value:  Perfmon:LocalNetwork).
                Invalid key in stanza [LocalNetwork.perfmon] in /opt/splunk_ind/etc/apps/Splunk_TA_windows/default/eventgen.conf, line 211: sourcetype  (value:  Perfmon:LocalNetwork).
                Invalid key in stanza [.*\.snare] in /opt/splunk_ind/etc/apps/Splunk_TA_windows/default/eventgen.conf, line 217: index  (value:  wineventlog).
                Invalid key in stanza [.*\.snare] in /opt/splunk_ind/etc/apps/Splunk_TA_windows/default/eventgen.conf, line 218: source  (value:  WinEventLog:Security).
                Invalid key in stanza [.*\.snare] in /opt/splunk_ind/etc/apps/Splunk_TA_windows/default/eventgen.conf, line 219: sourcetype  (value:  WinEventLog:Security).
                Invalid key in stanza [.*\.windows] in /opt/splunk_ind/etc/apps/Splunk_TA_windows/default/eventgen.conf, line 263: index  (value:  wineventlog).
                Invalid key in stanza [SCM.7036.windows] in /opt/splunk_ind/etc/apps/Splunk_TA_windows/default/eventgen.conf, line 292: index  (value:  wineventlog).
                Invalid key in stanza [SCM.7036.windows] in /opt/splunk_ind/etc/apps/Splunk_TA_windows/default/eventgen.conf, line 293: source  (value:  WinEventLog:System).
                Invalid key in stanza [SCM.7036.windows] in /opt/splunk_ind/etc/apps/Splunk_TA_windows/default/eventgen.conf, line 294: sourcetype  (value:  WinEventLog:System).
                Invalid key in stanza [LSASRV.40961.windows] in /opt/splunk_ind/etc/apps/Splunk_TA_windows/default/eventgen.conf, line 297: index  (value:  wineventlog).
                Invalid key in stanza [LSASRV.40961.windows] in /opt/splunk_ind/etc/apps/Splunk_TA_windows/default/eventgen.conf, line 298: source  (value:  WinEventLog:System).
                Invalid key in stanza [LSASRV.40961.windows] in /opt/splunk_ind/etc/apps/Splunk_TA_windows/default/eventgen.conf, line 299: sourcetype  (value:  WinEventLog:System).
                Invalid key in stanza [AppPopup.26.windows] in /opt/splunk_ind/etc/apps/Splunk_TA_windows/default/eventgen.conf, line 302: index  (value:  wineventlog).
                Invalid key in stanza [AppPopup.26.windows] in /opt/splunk_ind/etc/apps/Splunk_TA_windows/default/eventgen.conf, line 303: source  (value:  WinEventLog:System).
                Invalid key in stanza [AppPopup.26.windows] in /opt/splunk_ind/etc/apps/Splunk_TA_windows/default/eventgen.conf, line 304: sourcetype  (value:  WinEventLog:System).
                Invalid key in stanza [W32Time\.[0-9]*\.windows] in /opt/splunk_ind/etc/apps/Splunk_TA_windows/default/eventgen.conf, line 307: index  (value:  wineventlog).
                Invalid key in stanza [W32Time\.[0-9]*\.windows] in /opt/splunk_ind/etc/apps/Splunk_TA_windows/default/eventgen.conf, line 308: source  (value:  WinEventLog:System).
                Invalid key in stanza [W32Time\.[0-9]*\.windows] in /opt/splunk_ind/etc/apps/Splunk_TA_windows/default/eventgen.conf, line 309: sourcetype  (value:  WinEventLog:System).
                Invalid key in stanza [Security\.[0-9]*\.windows] in /opt/splunk_ind/etc/apps/Splunk_TA_windows/default/eventgen.conf, line 312: index  (value:  wineventlog).
                Invalid key in stanza [Security\.[0-9]*\.windows] in /opt/splunk_ind/etc/apps/Splunk_TA_windows/default/eventgen.conf, line 313: source  (value:  WinEventLog:Security).
                Invalid key in stanza [Security\.[0-9]*\.windows] in /opt/splunk_ind/etc/apps/Splunk_TA_windows/default/eventgen.conf, line 314: sourcetype  (value:  WinEventLog:Security).
                Invalid key in stanza [Security\.(528|529|537|539|540|552)\.windows] in /opt/splunk_ind/etc/apps/Splunk_TA_windows/default/eventgen.conf, line 327: index  (value:  wineventlog).
                Invalid key in stanza [Security\.(528|529|537|539|540|552)\.windows] in /opt/splunk_ind/etc/apps/Splunk_TA_windows/default/eventgen.conf, line 328: source  (value:  WinEventLog:Security).
                Invalid key in stanza [Security\.(528|529|537|539|540|552)\.windows] in /opt/splunk_ind/etc/apps/Splunk_TA_windows/default/eventgen.conf, line 329: sourcetype  (value:  WinEventLog:Security).
                Invalid key in stanza [Security.529.anomaly.windows] in /opt/splunk_ind/etc/apps/Splunk_TA_windows/default/eventgen.conf, line 354: index  (value:  wineventlog).
                Invalid key in stanza [Security.529.anomaly.windows] in /opt/splunk_ind/etc/apps/Splunk_TA_windows/default/eventgen.conf, line 355: source  (value:  WinEventLog:Security).
                Invalid key in stanza [Security.529.anomaly.windows] in /opt/splunk_ind/etc/apps/Splunk_TA_windows/default/eventgen.conf, line 356: sourcetype  (value:  WinEventLog:Security).
                Invalid key in stanza [Security.552.anomaly.windows] in /opt/splunk_ind/etc/apps/Splunk_TA_windows/default/eventgen.conf, line 394: index  (value:  wineventlog).
                Invalid key in stanza [Security.552.anomaly.windows] in /opt/splunk_ind/etc/apps/Splunk_TA_windows/default/eventgen.conf, line 395: source  (value:  WinEventLog:Security).
                Invalid key in stanza [Security.552.anomaly.windows] in /opt/splunk_ind/etc/apps/Splunk_TA_windows/default/eventgen.conf, line 396: sourcetype  (value:  WinEventLog:Security).
                Invalid key in stanza [Security.680.windows] in /opt/splunk_ind/etc/apps/Splunk_TA_windows/default/eventgen.conf, line 436: index  (value:  wineventlog).
                Invalid key in stanza [Security.680.windows] in /opt/splunk_ind/etc/apps/Splunk_TA_windows/default/eventgen.conf, line 437: source  (value:  WinEventLog:Security).
                Invalid key in stanza [Security.680.windows] in /opt/splunk_ind/etc/apps/Splunk_TA_windows/default/eventgen.conf, line 438: sourcetype  (value:  WinEventLog:Security).
                Invalid key in stanza [Security.1102.windows] in /opt/splunk_ind/etc/apps/Splunk_TA_windows/default/eventgen.conf, line 448: index  (value:  wineventlog).
                Invalid key in stanza [Security.1102.windows] in /opt/splunk_ind/etc/apps/Splunk_TA_windows/default/eventgen.conf, line 449: source  (value:  WinEventLog:Security).
                Invalid key in stanza [Security.1102.windows] in /opt/splunk_ind/etc/apps/Splunk_TA_windows/default/eventgen.conf, line 450: sourcetype  (value:  WinEventLog:Security).
                Invalid key in stanza [Security.4726.windows] in /opt/splunk_ind/etc/apps/Splunk_TA_windows/default/eventgen.conf, line 456: index  (value:  wineventlog).
                Invalid key in stanza [Security.4726.windows] in /opt/splunk_ind/etc/apps/Splunk_TA_windows/default/eventgen.conf, line 457: source  (value:  WinEventLog:Security).
                Invalid key in stanza [Security.4726.windows] in /opt/splunk_ind/etc/apps/Splunk_TA_windows/default/eventgen.conf, line 458: sourcetype  (value:  WinEventLog:Security).
                Invalid key in stanza [Security.4743.windows] in /opt/splunk_ind/etc/apps/Splunk_TA_windows/default/eventgen.conf, line 464: index  (value:  wineventlog).
                Invalid key in stanza [Security.4743.windows] in /opt/splunk_ind/etc/apps/Splunk_TA_windows/default/eventgen.conf, line 465: source  (value:  WinEventLog:Security).
                Invalid key in stanza [Security.4743.windows] in /opt/splunk_ind/etc/apps/Splunk_TA_windows/default/eventgen.conf, line 466: sourcetype  (value:  WinEventLog:Security).
                Invalid key in stanza [Security.4672.windows] in /opt/splunk_ind/etc/apps/Splunk_TA_windows/default/eventgen.conf, line 472: index  (value:  wineventlog).
                Invalid key in stanza [Security.4672.windows] in /opt/splunk_ind/etc/apps/Splunk_TA_windows/default/eventgen.conf, line 473: source  (value:  WinEventLog:Security).
                Invalid key in stanza [Security.4672.windows] in /opt/splunk_ind/etc/apps/Splunk_TA_windows/default/eventgen.conf, line 474: sourcetype  (value:  WinEventLog:Security).
                Invalid key in stanza [.*\.winregistry] in /opt/splunk_ind/etc/apps/Splunk_TA_windows/default/eventgen.conf, line 482: index  (value:  windows).
                Invalid key in stanza [.*\.winregistry] in /opt/splunk_ind/etc/apps/Splunk_TA_windows/default/eventgen.conf, line 483: source  (value:  WinRegistry).
                Invalid key in stanza [.*\.winregistry] in /opt/splunk_ind/etc/apps/Splunk_TA_windows/default/eventgen.conf, line 484: sourcetype  (value:  WinRegistry).
                Invalid key in stanza [.*\.wmi] in /opt/splunk_ind/etc/apps/Splunk_TA_windows/default/eventgen.conf, line 499: index  (value:  windows).
                Invalid key in stanza [ComputerSystem.wmi] in /opt/splunk_ind/etc/apps/Splunk_TA_windows/default/eventgen.conf, line 514: index  (value:  perfmon).
                Invalid key in stanza [ComputerSystem.wmi] in /opt/splunk_ind/etc/apps/Splunk_TA_windows/default/eventgen.conf, line 515: source  (value:  Perfmon:Memory).
                Invalid key in stanza [ComputerSystem.wmi] in /opt/splunk_ind/etc/apps/Splunk_TA_windows/default/eventgen.conf, line 516: sourcetype  (value:  Perfmon:Memory).
                Invalid key in stanza [CPUTime.wmi] in /opt/splunk_ind/etc/apps/Splunk_TA_windows/default/eventgen.conf, line 522: index  (value:  perfmon).
                Invalid key in stanza [CPUTime.wmi] in /opt/splunk_ind/etc/apps/Splunk_TA_windows/default/eventgen.conf, line 523: source  (value:  Perfmon:CPUTime).
                Invalid key in stanza [CPUTime.wmi] in /opt/splunk_ind/etc/apps/Splunk_TA_windows/default/eventgen.conf, line 524: sourcetype  (value:  Perfmon:CPUTime).
                Invalid key in stanza [FreeDiskSpace.wmi] in /opt/splunk_ind/etc/apps/Splunk_TA_windows/default/eventgen.conf, line 535: index  (value:  perfmon).
                Invalid key in stanza [FreeDiskSpace.wmi] in /opt/splunk_ind/etc/apps/Splunk_TA_windows/default/eventgen.conf, line 536: source  (value:  Perfmon:FreeDiskSpace).
                Invalid key in stanza [FreeDiskSpace.wmi] in /opt/splunk_ind/etc/apps/Splunk_TA_windows/default/eventgen.conf, line 537: sourcetype  (value:  Perfmon:FreeDiskSpace).
                Invalid key in stanza [InstalledUpdates.wmi] in /opt/splunk_ind/etc/apps/Splunk_TA_windows/default/eventgen.conf, line 548: index  (value:  windows).
                Invalid key in stanza [InstalledUpdates.wmi] in /opt/splunk_ind/etc/apps/Splunk_TA_windows/default/eventgen.conf, line 549: source  (value:  WindowsUpdateLog).
                Invalid key in stanza [InstalledUpdates.wmi] in /opt/splunk_ind/etc/apps/Splunk_TA_windows/default/eventgen.conf, line 550: sourcetype  (value:  WindowsUpdateLog).
                Invalid key in stanza [LocalNetwork.wmi] in /opt/splunk_ind/etc/apps/Splunk_TA_windows/default/eventgen.conf, line 556: index  (value:  perfmon).
                Invalid key in stanza [LocalNetwork.wmi] in /opt/splunk_ind/etc/apps/Splunk_TA_windows/default/eventgen.conf, line 557: source  (value:  Perfmon:LocalNetwork).
                Invalid key in stanza [LocalNetwork.wmi] in /opt/splunk_ind/etc/apps/Splunk_TA_windows/default/eventgen.conf, line 558: sourcetype  (value:  Perfmon:LocalNetwork).
                Invalid key in stanza [LocalPhysicalDisk.wmi] in /opt/splunk_ind/etc/apps/Splunk_TA_windows/default/eventgen.conf, line 564: index  (value:  perfmon).
                Invalid key in stanza [LocalPhysicalDisk.wmi] in /opt/splunk_ind/etc/apps/Splunk_TA_windows/default/eventgen.conf, line 565: source  (value:  Perfmon:LocalPhysicalDisk).
                Invalid key in stanza [LocalPhysicalDisk.wmi] in /opt/splunk_ind/etc/apps/Splunk_TA_windows/default/eventgen.conf, line 566: sourcetype  (value:  Perfmon:LocalPhysicalDisk).
                Invalid key in stanza [LocalProcesses.wmi] in /opt/splunk_ind/etc/apps/Splunk_TA_windows/default/eventgen.conf, line 572: index  (value:  perfmon).
                Invalid key in stanza [LocalProcesses.wmi] in /opt/splunk_ind/etc/apps/Splunk_TA_windows/default/eventgen.conf, line 573: source  (value:  Perfmon:LocalProcesses).
                Invalid key in stanza [LocalProcesses.wmi] in /opt/splunk_ind/etc/apps/Splunk_TA_windows/default/eventgen.conf, line 574: sourcetype  (value:  Perfmon:LocalProcesses).
                Invalid key in stanza [Memory.wmi] in /opt/splunk_ind/etc/apps/Splunk_TA_windows/default/eventgen.conf, line 580: index  (value:  perfmon).
                Invalid key in stanza [Memory.wmi] in /opt/splunk_ind/etc/apps/Splunk_TA_windows/default/eventgen.conf, line 581: source  (value:  Perfmon:Memory).
                Invalid key in stanza [Memory.wmi] in /opt/splunk_ind/etc/apps/Splunk_TA_windows/default/eventgen.conf, line 582: sourcetype  (value:  Perfmon:Memory).
                Invalid key in stanza [ScheduledJobs.wmi] in /opt/splunk_ind/etc/apps/Splunk_TA_windows/default/eventgen.conf, line 588: index  (value:  windows).
                Invalid key in stanza [ScheduledJobs.wmi] in /opt/splunk_ind/etc/apps/Splunk_TA_windows/default/eventgen.conf, line 589: source  (value:  WMI:ScheduledJobs).
                Invalid key in stanza [ScheduledJobs.wmi] in /opt/splunk_ind/etc/apps/Splunk_TA_windows/default/eventgen.conf, line 590: sourcetype  (value:  WMI:ScheduledJobs).
                Invalid key in stanza [Service.wmi] in /opt/splunk_ind/etc/apps/Splunk_TA_windows/default/eventgen.conf, line 596: index  (value:  windows).
                Invalid key in stanza [Service.wmi] in /opt/splunk_ind/etc/apps/Splunk_TA_windows/default/eventgen.conf, line 597: source  (value:  WMI:Service).
                Invalid key in stanza [Service.wmi] in /opt/splunk_ind/etc/apps/Splunk_TA_windows/default/eventgen.conf, line 598: sourcetype  (value:  WMI:Service).
                Invalid key in stanza [Uptime.wmi] in /opt/splunk_ind/etc/apps/Splunk_TA_windows/default/eventgen.conf, line 604: index  (value:  windows).
                Invalid key in stanza [Uptime.wmi] in /opt/splunk_ind/etc/apps/Splunk_TA_windows/default/eventgen.conf, line 605: source  (value:  WMI:Uptime).
                Invalid key in stanza [Uptime.wmi] in /opt/splunk_ind/etc/apps/Splunk_TA_windows/default/eventgen.conf, line 606: sourcetype  (value:  WMI:Uptime).
                Invalid key in stanza [UserAccounts.wmi] in /opt/splunk_ind/etc/apps/Splunk_TA_windows/default/eventgen.conf, line 612: index  (value:  windows).
                Invalid key in stanza [UserAccounts.wmi] in /opt/splunk_ind/etc/apps/Splunk_TA_windows/default/eventgen.conf, line 613: source  (value:  WMI:UserAccounts).
                Invalid key in stanza [UserAccounts.wmi] in /opt/splunk_ind/etc/apps/Splunk_TA_windows/default/eventgen.conf, line 614: sourcetype  (value:  WMI:UserAccounts).
                Invalid key in stanza [Version.wmi] in /opt/splunk_ind/etc/apps/Splunk_TA_windows/default/eventgen.conf, line 620: index  (value:  windows).
                Invalid key in stanza [Version.wmi] in /opt/splunk_ind/etc/apps/Splunk_TA_windows/default/eventgen.conf, line 621: source  (value:  WMI:Version).
                Invalid key in stanza [Version.wmi] in /opt/splunk_ind/etc/apps/Splunk_TA_windows/default/eventgen.conf, line 622: sourcetype  (value:  WMI:Version).
                Invalid key in stanza [WinHostMon-OperatingSystem] in /opt/splunk_ind/etc/apps/Splunk_TA_windows/default/eventgen.conf, line 627: index  (value:  windows).
                Invalid key in stanza [WinHostMon-OperatingSystem] in /opt/splunk_ind/etc/apps/Splunk_TA_windows/default/eventgen.conf, line 628: sourcetype  (value:  WinHostMon).
                Invalid key in stanza [WinHostMon-OperatingSystem] in /opt/splunk_ind/etc/apps/Splunk_TA_windows/default/eventgen.conf, line 629: source  (value:  OperatingSystem).
                Invalid key in stanza [WinHostMon-Processor] in /opt/splunk_ind/etc/apps/Splunk_TA_windows/default/eventgen.conf, line 633: index  (value:  windows).
                Invalid key in stanza [WinHostMon-Processor] in /opt/splunk_ind/etc/apps/Splunk_TA_windows/default/eventgen.conf, line 634: sourcetype  (value:  Processor).
                Invalid key in stanza [WinHostMon-Processor] in /opt/splunk_ind/etc/apps/Splunk_TA_windows/default/eventgen.conf, line 635: source  (value:  Computer).
                Invalid key in stanza [XmlSecurity\.[0-9]*\.windows\.xml] in /opt/splunk_ind/etc/apps/Splunk_TA_windows/default/eventgen.conf, line 639: index  (value:  wineventlog).
                Invalid key in stanza [XmlSecurity\.[0-9]*\.windows\.xml] in /opt/splunk_ind/etc/apps/Splunk_TA_windows/default/eventgen.conf, line 640: source  (value:  WinEventLog:Security).
                Invalid key in stanza [XmlSecurity\.[0-9]*\.windows\.xml] in /opt/splunk_ind/etc/apps/Splunk_TA_windows/default/eventgen.conf, line 641: sourcetype  (value:  XmlWinEventLog:Security).
                Invalid key in stanza [XmlSystem.update_.*\.xml] in /opt/splunk_ind/etc/apps/Splunk_TA_windows/default/eventgen.conf, line 645: index  (value:  wineventlog).
                Invalid key in stanza [XmlSystem.update_.*\.xml] in /opt/splunk_ind/etc/apps/Splunk_TA_windows/default/eventgen.conf, line 646: source  (value:  WinEventLog:System).
                Your indexes and inputs configurations are not internally consistent. For more information, run 'splunk btool check --debug'
                Invalid key in stanza [XmlSystem.update_.*\.xml] in /opt/splunk_ind/etc/apps/Splunk_TA_windows/default/eventgen.conf, line 647: sourcetype  (value:  XmlWinEventLog:System).
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Tue, 29 Sep 2020 10:19:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-clear-up-eventgen-conf-quot-Invalid-key-in-stanza-quot/m-p/273940#M31888</guid>
      <dc:creator>banderson7</dc:creator>
      <dc:date>2020-09-29T10:19:43Z</dc:date>
    </item>
    <item>
      <title>Re: How to clear up eventgen.conf "Invalid key in stanza" errors after installing the Splunk Add-on for Microsoft Windows on Linux indexers?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-clear-up-eventgen-conf-quot-Invalid-key-in-stanza-quot/m-p/273941#M31889</link>
      <description>&lt;P&gt;Hi banderson7, renaming the eventgen.conf file to something like eventgen.conf.bak would clear up most of these messages. Usually eventgen isn't needed, and if you aren't using it then it's just noise.&lt;/P&gt;

&lt;P&gt;Please let me know if this answers your question! &lt;span class="lia-unicode-emoji" title=":grinning_face_with_smiling_eyes:"&gt;😄&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 19 Jul 2016 12:53:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-clear-up-eventgen-conf-quot-Invalid-key-in-stanza-quot/m-p/273941#M31889</guid>
      <dc:creator>muebel</dc:creator>
      <dc:date>2016-07-19T12:53:13Z</dc:date>
    </item>
    <item>
      <title>Re: How to clear up eventgen.conf "Invalid key in stanza" errors after installing the Splunk Add-on for Microsoft Windows on Linux indexers?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-clear-up-eventgen-conf-quot-Invalid-key-in-stanza-quot/m-p/273942#M31890</link>
      <description>&lt;P&gt;Why are you installing the Splunk ta for WINDOWS on a linux device?  That's why you're getting these errors.  It's not meant to be installed on linux Splunk instances.  Try the Splunk ta for linux instead.&lt;/P&gt;

&lt;P&gt;To "clean it up" remove the Splunk ta for windows from /opt/splunk_ind/etc/apps/ and restart Splunk.  rm -Rf /opt/splunk_ind/etc/apps/splunk_ta_windows and then restarting Splunk should do the trick.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 10:16:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-clear-up-eventgen-conf-quot-Invalid-key-in-stanza-quot/m-p/273942#M31890</guid>
      <dc:creator>jkat54</dc:creator>
      <dc:date>2020-09-29T10:16:39Z</dc:date>
    </item>
    <item>
      <title>Re: How to clear up eventgen.conf "Invalid key in stanza" errors after installing the Splunk Add-on for Microsoft Windows on Linux indexers?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-clear-up-eventgen-conf-quot-Invalid-key-in-stanza-quot/m-p/273943#M31891</link>
      <description>&lt;P&gt;Are you doing this for the "props"?  The TA only goes on the windows forwarders to my knowledge and isn't required on the indexers.&lt;/P&gt;</description>
      <pubDate>Tue, 19 Jul 2016 13:13:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-clear-up-eventgen-conf-quot-Invalid-key-in-stanza-quot/m-p/273943#M31891</guid>
      <dc:creator>jkat54</dc:creator>
      <dc:date>2016-07-19T13:13:18Z</dc:date>
    </item>
    <item>
      <title>Re: How to clear up eventgen.conf "Invalid key in stanza" errors after installing the Splunk Add-on for Microsoft Windows on Linux indexers?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-clear-up-eventgen-conf-quot-Invalid-key-in-stanza-quot/m-p/273944#M31892</link>
      <description>&lt;P&gt;Per: &lt;A href="http://docs.splunk.com/Documentation/WindowsAddOn/4.8.3/User/DeploytheSplunkAdd-onforWindowsinadistributedenvironment"&gt;http://docs.splunk.com/Documentation/WindowsAddOn/4.8.3/User/DeploytheSplunkAdd-onforWindowsinadistributedenvironment&lt;/A&gt;&lt;BR /&gt;
"&lt;BR /&gt;
Complete the procedure in "Install the Splunk Add-on for Windows" to place the Splunk Add-on for Windows onto the indexer.&lt;BR /&gt;
If the indexer is a Windows host and you want to collect Windows data from it, configure the add-on on that host."&lt;BR /&gt;
It would be helpful to get an idea if the TA was required on the indexers. Do I just need to add the props.conf file?&lt;/P&gt;</description>
      <pubDate>Tue, 19 Jul 2016 13:17:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-clear-up-eventgen-conf-quot-Invalid-key-in-stanza-quot/m-p/273944#M31892</guid>
      <dc:creator>banderson7</dc:creator>
      <dc:date>2016-07-19T13:17:57Z</dc:date>
    </item>
    <item>
      <title>Re: How to clear up eventgen.conf "Invalid key in stanza" errors after installing the Splunk Add-on for Microsoft Windows on Linux indexers?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-clear-up-eventgen-conf-quot-Invalid-key-in-stanza-quot/m-p/273945#M31893</link>
      <description>&lt;P&gt;I'm going with muebels comment then.  Delete eventgen.conf and then edit the props.conf to remove that one regex.&lt;/P&gt;</description>
      <pubDate>Tue, 19 Jul 2016 13:42:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-clear-up-eventgen-conf-quot-Invalid-key-in-stanza-quot/m-p/273945#M31893</guid>
      <dc:creator>jkat54</dc:creator>
      <dc:date>2016-07-19T13:42:49Z</dc:date>
    </item>
  </channel>
</rss>

