<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Invalid Key in alert_actions.conf after upgrade to Splunk 9.0.0 in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/Invalid-Key-in-alert-actions-conf-after-upgrade-to-Splunk-9-0-0/m-p/602292#M12893</link>
    <description>&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;I get the message across all the Windows clients when I restart the client:&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Error when starting" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/20155i99E8794641049C17/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="Error when starting" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;Error when starting&lt;/span&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Output of splunk btool check --debug (pt1)" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/20156i59E36FF7DD4DA2F4/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="Output of splunk btool check --debug (pt1)" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;Output of splunk btool check --debug (pt1)&lt;/span&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Output of splunk btool check --debug (pt2)" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/20157iAC92AFA276B4D605/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="Output of splunk btool check --debug (pt2)" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;Output of splunk btool check --debug (pt2)&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 17 Jun 2022 21:26:52 GMT</pubDate>
    <dc:creator>dasadmin</dc:creator>
    <dc:date>2022-06-17T21:26:52Z</dc:date>
    <item>
      <title>Invalid Key in alert_actions.conf after upgrade to Splunk 9.0.0?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Invalid-Key-in-alert-actions-conf-after-upgrade-to-Splunk-9-0-0/m-p/602259#M12886</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;
&lt;P&gt;Upgraded Splunk Enterprise to 9.0.0 today - went OK.&lt;/P&gt;
&lt;P&gt;Upgraded Splunk Universal Forwarders on Windows Server 2019 to 9.0.0 - upgrade says all went OK.&lt;/P&gt;
&lt;P&gt;I opened cmd and executed &lt;STRONG&gt;splunk restart&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;The SplunkForwarder restarts OK, but I get the following error:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;Invalid key in stanza [webhook] in D:\Program Files\SplunkUniversalForwarder\etc\system\default\alert_actions.conf, line 229: enable_allowlist (value: false)&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In the file &lt;STRONG&gt;alert_actions.conf&lt;/STRONG&gt; on line 229:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;[webhook]
enable_allowlist = false&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Anyone know why I'm seeing this after the upgrade?&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 21 Nov 2022 12:05:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Invalid-Key-in-alert-actions-conf-after-upgrade-to-Splunk-9-0-0/m-p/602259#M12886</guid>
      <dc:creator>dasadmin</dc:creator>
      <dc:date>2022-11-21T12:05:30Z</dc:date>
    </item>
    <item>
      <title>Re: Invalid Key in alert_actions.conf after upgrade to Splunk 9.0.0</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Invalid-Key-in-alert-actions-conf-after-upgrade-to-Splunk-9-0-0/m-p/602282#M12891</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;at lest I cannot found that parameter from conf file description. Are you sure that you haven’t gotten that warning earlier?&lt;/P&gt;&lt;P&gt;r. Ismo&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 17 Jun 2022 19:14:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Invalid-Key-in-alert-actions-conf-after-upgrade-to-Splunk-9-0-0/m-p/602282#M12891</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2022-06-17T19:14:22Z</dc:date>
    </item>
    <item>
      <title>Re: Invalid Key in alert_actions.conf after upgrade to Splunk 9.0.0</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Invalid-Key-in-alert-actions-conf-after-upgrade-to-Splunk-9-0-0/m-p/602292#M12893</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;I get the message across all the Windows clients when I restart the client:&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Error when starting" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/20155i99E8794641049C17/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="Error when starting" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;Error when starting&lt;/span&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Output of splunk btool check --debug (pt1)" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/20156i59E36FF7DD4DA2F4/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="Output of splunk btool check --debug (pt1)" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;Output of splunk btool check --debug (pt1)&lt;/span&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Output of splunk btool check --debug (pt2)" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/20157iAC92AFA276B4D605/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="Output of splunk btool check --debug (pt2)" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;Output of splunk btool check --debug (pt2)&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 17 Jun 2022 21:26:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Invalid-Key-in-alert-actions-conf-after-upgrade-to-Splunk-9-0-0/m-p/602292#M12893</guid>
      <dc:creator>dasadmin</dc:creator>
      <dc:date>2022-06-17T21:26:52Z</dc:date>
    </item>
    <item>
      <title>Re: Invalid Key in alert_actions.conf after upgrade to Splunk 9.0.0</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Invalid-Key-in-alert-actions-conf-after-upgrade-to-Splunk-9-0-0/m-p/602293#M12894</link>
      <description>As you get it from etc/system/default directory and you haven't changed it, you should report this to Splunk via support portal.</description>
      <pubDate>Fri, 17 Jun 2022 21:45:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Invalid-Key-in-alert-actions-conf-after-upgrade-to-Splunk-9-0-0/m-p/602293#M12894</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2022-06-17T21:45:38Z</dc:date>
    </item>
    <item>
      <title>Re: Invalid Key in alert_actions.conf after upgrade to Splunk 9.0.0</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Invalid-Key-in-alert-actions-conf-after-upgrade-to-Splunk-9-0-0/m-p/602872#M12955</link>
      <description>&lt;P&gt;Getting the same issue in my environment after upgrading my universal forwarders to 9.0.0&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jun 2022 19:38:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Invalid-Key-in-alert-actions-conf-after-upgrade-to-Splunk-9-0-0/m-p/602872#M12955</guid>
      <dc:creator>achavarria</dc:creator>
      <dc:date>2022-06-22T19:38:54Z</dc:date>
    </item>
    <item>
      <title>Re: Invalid Key in alert_actions.conf after upgrade to Splunk 9.0.0</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Invalid-Key-in-alert-actions-conf-after-upgrade-to-Splunk-9-0-0/m-p/602922#M12961</link>
      <description>&lt;P&gt;If this has worked earlier, you should report that to splunk support.&lt;/P&gt;</description>
      <pubDate>Thu, 23 Jun 2022 06:39:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Invalid-Key-in-alert-actions-conf-after-upgrade-to-Splunk-9-0-0/m-p/602922#M12961</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2022-06-23T06:39:29Z</dc:date>
    </item>
    <item>
      <title>Re: Invalid Key in alert_actions.conf after upgrade to Splunk 9.0.0</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Invalid-Key-in-alert-actions-conf-after-upgrade-to-Splunk-9-0-0/m-p/606406#M13391</link>
      <description>&lt;P&gt;Were you able to find any solution to this issue ?&lt;/P&gt;</description>
      <pubDate>Wed, 20 Jul 2022 23:53:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Invalid-Key-in-alert-actions-conf-after-upgrade-to-Splunk-9-0-0/m-p/606406#M13391</guid>
      <dc:creator>sumedhjoglekar</dc:creator>
      <dc:date>2022-07-20T23:53:39Z</dc:date>
    </item>
    <item>
      <title>Re: Invalid Key in alert_actions.conf after upgrade to Splunk 9.0.0</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Invalid-Key-in-alert-actions-conf-after-upgrade-to-Splunk-9-0-0/m-p/606524#M13402</link>
      <description>&lt;P&gt;hello&lt;/P&gt;&lt;P&gt;I opened a case with splunk and they said don't worry about the error unless it is causing an issue.&lt;/P&gt;&lt;P&gt;It has been forwarded to splunk engineering to look at further.&lt;/P&gt;&lt;P&gt;Thx&lt;/P&gt;</description>
      <pubDate>Thu, 21 Jul 2022 14:17:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Invalid-Key-in-alert-actions-conf-after-upgrade-to-Splunk-9-0-0/m-p/606524#M13402</guid>
      <dc:creator>dasadmin</dc:creator>
      <dc:date>2022-07-21T14:17:19Z</dc:date>
    </item>
    <item>
      <title>Re: Invalid Key in alert_actions.conf after upgrade to Splunk 9.0.0</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Invalid-Key-in-alert-actions-conf-after-upgrade-to-Splunk-9-0-0/m-p/621534#M14571</link>
      <description>&lt;P&gt;I'm so disappointed by Splunk release process that they even don't run "&lt;EM&gt;splunk btool check&lt;/EM&gt;" in their testing pipelines to catch this kind of errors&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":face_with_rolling_eyes:"&gt;🙄&lt;/span&gt;.&lt;/P&gt;</description>
      <pubDate>Mon, 21 Nov 2022 08:35:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Invalid-Key-in-alert-actions-conf-after-upgrade-to-Splunk-9-0-0/m-p/621534#M14571</guid>
      <dc:creator>tro</dc:creator>
      <dc:date>2022-11-21T08:35:35Z</dc:date>
    </item>
    <item>
      <title>Re: Invalid Key in alert_actions.conf after upgrade to Splunk 9.0.0</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Invalid-Key-in-alert-actions-conf-after-upgrade-to-Splunk-9-0-0/m-p/625613#M14938</link>
      <description>&lt;P&gt;Happy new year everyone!&lt;/P&gt;&lt;P&gt;I want to ask, if there is an update about this issue? We updated our Splunk Server and universal forwarder to the latest version 9.0.2 yet and ran into the same issue on some machines.&lt;/P&gt;&lt;P&gt;Splunk and the forwarder seems to operate as intended, but we get this errors in the log on some hosts:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;Dec 12 15:14:26 somehostname-123 splunk[2268]: Invalid key in stanza [webhook] in /opt/splunkforwarder/etc/system/default/alert_actions.conf, line 229: enable_allowlist (value: false).
Dec 12 15:14:26 somehostname-123 splunk[2268]: Your indexes and inputs configurations are not internally consistent. For more information, run 'splunk btool check --debug' &lt;/LI-CODE&gt;</description>
      <pubDate>Mon, 02 Jan 2023 12:38:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Invalid-Key-in-alert-actions-conf-after-upgrade-to-Splunk-9-0-0/m-p/625613#M14938</guid>
      <dc:creator>mhanisch_kvd</dc:creator>
      <dc:date>2023-01-02T12:38:23Z</dc:date>
    </item>
    <item>
      <title>Re: Invalid Key in alert_actions.conf after upgrade to Splunk 9.0.0</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Invalid-Key-in-alert-actions-conf-after-upgrade-to-Splunk-9-0-0/m-p/625619#M14941</link>
      <description>&lt;P&gt;I got this answer via official Splunk support:&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;DIV&gt;&lt;BLOCKQUOTE&gt;&lt;DIV&gt;Ticket raised to our developers: SPL-229404.&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;In general fix in new app version was already implemented. But app is still not ready to be released due to some other things which have to be tested.&lt;/DIV&gt;&lt;DIV&gt;Unfortunately I don't have any specific ETA for now but I believe it should not take too long.&lt;/DIV&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;So I would suggest watch&amp;nbsp;&lt;STRONG&gt;SPL-229404&lt;/STRONG&gt; in upcoming &lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/ReleaseNotes/Fixedissues" target="_self"&gt;changelogs&lt;/A&gt;.&lt;/DIV&gt;</description>
      <pubDate>Mon, 02 Jan 2023 13:50:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Invalid-Key-in-alert-actions-conf-after-upgrade-to-Splunk-9-0-0/m-p/625619#M14941</guid>
      <dc:creator>tro</dc:creator>
      <dc:date>2023-01-02T13:50:47Z</dc:date>
    </item>
    <item>
      <title>Re: Invalid Key in alert_actions.conf after upgrade to Splunk 9.0.0?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Invalid-Key-in-alert-actions-conf-after-upgrade-to-Splunk-9-0-0/m-p/634190#M15690</link>
      <description>&lt;P&gt;I have the same problem. Did you get a fix?&lt;/P&gt;</description>
      <pubDate>Mon, 13 Mar 2023 06:27:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Invalid-Key-in-alert-actions-conf-after-upgrade-to-Splunk-9-0-0/m-p/634190#M15690</guid>
      <dc:creator>ivarbaba</dc:creator>
      <dc:date>2023-03-13T06:27:25Z</dc:date>
    </item>
    <item>
      <title>Re: Invalid Key in alert_actions.conf after upgrade to Splunk 9.0.0?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Invalid-Key-in-alert-actions-conf-after-upgrade-to-Splunk-9-0-0/m-p/634206#M15691</link>
      <description>&lt;P&gt;You you are having same issue, then it is fixed in version Splunk 9.0.4. Please do update &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 13 Mar 2023 07:21:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Invalid-Key-in-alert-actions-conf-after-upgrade-to-Splunk-9-0-0/m-p/634206#M15691</guid>
      <dc:creator>tro</dc:creator>
      <dc:date>2023-03-13T07:21:52Z</dc:date>
    </item>
    <item>
      <title>Re: Invalid Key in alert_actions.conf after upgrade to Splunk 9.0.0</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Invalid-Key-in-alert-actions-conf-after-upgrade-to-Splunk-9-0-0/m-p/641340#M16181</link>
      <description>&lt;P&gt;Fwiw, the problem is still there in UF 9.0.4.&lt;/P&gt;</description>
      <pubDate>Tue, 25 Apr 2023 19:57:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Invalid-Key-in-alert-actions-conf-after-upgrade-to-Splunk-9-0-0/m-p/641340#M16181</guid>
      <dc:creator>lbdatpsu</dc:creator>
      <dc:date>2023-04-25T19:57:05Z</dc:date>
    </item>
    <item>
      <title>Re: Invalid Key in alert_actions.conf after upgrade to Splunk 9.0.0</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Invalid-Key-in-alert-actions-conf-after-upgrade-to-Splunk-9-0-0/m-p/641451#M16186</link>
      <description>&lt;P&gt;Honestly. Nearly 1 year later and 2 version revisions and every fresh UF install done on every server throws this out-of-the-box warning. Not at all impressed&lt;/P&gt;</description>
      <pubDate>Wed, 26 Apr 2023 14:38:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Invalid-Key-in-alert-actions-conf-after-upgrade-to-Splunk-9-0-0/m-p/641451#M16186</guid>
      <dc:creator>chadmedeiros</dc:creator>
      <dc:date>2023-04-26T14:38:52Z</dc:date>
    </item>
    <item>
      <title>Re: Invalid Key in alert_actions.conf after upgrade to Splunk 9.0.0?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Invalid-Key-in-alert-actions-conf-after-upgrade-to-Splunk-9-0-0/m-p/641453#M16187</link>
      <description>&lt;P&gt;this is not fixed in 9.0.4&lt;/P&gt;</description>
      <pubDate>Wed, 26 Apr 2023 14:39:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Invalid-Key-in-alert-actions-conf-after-upgrade-to-Splunk-9-0-0/m-p/641453#M16187</guid>
      <dc:creator>chadmedeiros</dc:creator>
      <dc:date>2023-04-26T14:39:41Z</dc:date>
    </item>
    <item>
      <title>Re: Invalid Key in alert_actions.conf after upgrade to Splunk 9.0.0?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Invalid-Key-in-alert-actions-conf-after-upgrade-to-Splunk-9-0-0/m-p/650874#M16850</link>
      <description>&lt;P&gt;Getting this error when either: installing fresh 9.1.0.1 or upgrading 8.x to 9.1.&amp;nbsp; This is just sad.. I mean how could Splunk have NOT fixed this in over a year??&lt;/P&gt;&lt;P&gt;Obviously the syntax changed.. can't be that hard to figure out why.&lt;/P&gt;</description>
      <pubDate>Mon, 17 Jul 2023 16:45:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Invalid-Key-in-alert-actions-conf-after-upgrade-to-Splunk-9-0-0/m-p/650874#M16850</guid>
      <dc:creator>Skeer-Jamf</dc:creator>
      <dc:date>2023-07-17T16:45:59Z</dc:date>
    </item>
    <item>
      <title>Re: Invalid Key in alert_actions.conf after upgrade to Splunk 9.0.0?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Invalid-Key-in-alert-actions-conf-after-upgrade-to-Splunk-9-0-0/m-p/659327#M17491</link>
      <description>&lt;P&gt;Getting the same warning.&amp;nbsp; I'll submit a support ticket.&lt;/P&gt;</description>
      <pubDate>Mon, 02 Oct 2023 18:24:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Invalid-Key-in-alert-actions-conf-after-upgrade-to-Splunk-9-0-0/m-p/659327#M17491</guid>
      <dc:creator>computermathguy</dc:creator>
      <dc:date>2023-10-02T18:24:10Z</dc:date>
    </item>
  </channel>
</rss>

