<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk 9.x Invalid Stanza in `federated.conf` in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/Does-anyone-know-a-fix-for-Splunk-9-x-Invalid-Stanza-in/m-p/602699#M12926</link>
    <description>&lt;P&gt;Can you check e.g. with od that this file is not corrupted and contains some additional control character?&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;od -t c -t x1 &lt;/LI-CODE&gt;&lt;P&gt;I cannot &amp;nbsp;test those parameters, but please check those from man page.&lt;/P&gt;</description>
    <pubDate>Tue, 21 Jun 2022 18:06:18 GMT</pubDate>
    <dc:creator>isoutamo</dc:creator>
    <dc:date>2022-06-21T18:06:18Z</dc:date>
    <item>
      <title>Does anyone know a fix for Splunk 9.x Invalid Stanza in `federated.conf`?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Does-anyone-know-a-fix-for-Splunk-9-x-Invalid-Stanza-in/m-p/602488#M12909</link>
      <description>&lt;P&gt;Newly released Splunk 9 introduced an error or invalid stanza on `federated.conf`. Anybody knows how to fix this?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;Invalid key in stanza [provider:splunk] in /opt/splunk/etc/system/default/federated.conf, line 20: mode (value: standard).
Invalid key in stanza [general] in /opt/splunk/etc/system/default/federated.conf, line 23: needs_consent (value: true).&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 20 Jul 2022 21:17:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Does-anyone-know-a-fix-for-Splunk-9-x-Invalid-Stanza-in/m-p/602488#M12909</guid>
      <dc:creator>morethanyell</dc:creator>
      <dc:date>2022-07-20T21:17:10Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk 9.x Invalid Stanza in `federated.conf`</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Does-anyone-know-a-fix-for-Splunk-9-x-Invalid-Stanza-in/m-p/602551#M12912</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;quite interesting as I have both of those in place and didn't got any errors!&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[soutamo@fer] ~&amp;gt;
(0) $ splunk btool check
[soutamo@fer] ~&amp;gt;
(0) $ splunk btool federated list --debug
/opt/splunk/9.0.0/splunk/etc/system/default/federated.conf [default]
/opt/splunk/9.0.0/splunk/etc/system/default/federated.conf [general]
/opt/splunk/9.0.0/splunk/etc/system/default/federated.conf needs_consent = true
/opt/splunk/9.0.0/splunk/etc/system/default/federated.conf [provider:splunk]
/opt/splunk/9.0.0/splunk/etc/system/default/federated.conf appContext = search
/opt/splunk/9.0.0/splunk/etc/system/default/federated.conf mode = standard
/opt/splunk/9.0.0/splunk/etc/system/default/federated.conf type = splunk
/opt/splunk/9.0.0/splunk/etc/system/default/federated.conf useFSHKnowledgeObjects = false
[soutamo@fer] ~&amp;gt;
(0) $&lt;/LI-CODE&gt;&lt;P&gt;What you will gotten when you are running those two commands?&lt;/P&gt;&lt;P&gt;r. Ismo&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 21 Jun 2022 07:27:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Does-anyone-know-a-fix-for-Splunk-9-x-Invalid-Stanza-in/m-p/602551#M12912</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2022-06-21T07:27:58Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk 9.x Invalid Stanza in `federated.conf`</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Does-anyone-know-a-fix-for-Splunk-9-x-Invalid-Stanza-in/m-p/602676#M12918</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="btool.png" style="width: 803px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/20213i64B70E93F9CAD24C/image-size/large?v=v2&amp;amp;px=999" role="button" title="btool.png" alt="btool.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;This is what I get.&lt;/P&gt;</description>
      <pubDate>Tue, 21 Jun 2022 16:09:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Does-anyone-know-a-fix-for-Splunk-9-x-Invalid-Stanza-in/m-p/602676#M12918</guid>
      <dc:creator>morethanyell</dc:creator>
      <dc:date>2022-06-21T16:09:16Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk 9.x Invalid Stanza in `federated.conf`</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Does-anyone-know-a-fix-for-Splunk-9-x-Invalid-Stanza-in/m-p/602689#M12920</link>
      <description>&lt;P&gt;I am getting that exact same set of errors as the original author on a basic 8.2.4 deployment server.&lt;/P&gt;</description>
      <pubDate>Tue, 21 Jun 2022 17:47:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Does-anyone-know-a-fix-for-Splunk-9-x-Invalid-Stanza-in/m-p/602689#M12920</guid>
      <dc:creator>zrxcrasher</dc:creator>
      <dc:date>2022-06-21T17:47:10Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk 9.x Invalid Stanza in `federated.conf`</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Does-anyone-know-a-fix-for-Splunk-9-x-Invalid-Stanza-in/m-p/602699#M12926</link>
      <description>&lt;P&gt;Can you check e.g. with od that this file is not corrupted and contains some additional control character?&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;od -t c -t x1 &lt;/LI-CODE&gt;&lt;P&gt;I cannot &amp;nbsp;test those parameters, but please check those from man page.&lt;/P&gt;</description>
      <pubDate>Tue, 21 Jun 2022 18:06:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Does-anyone-know-a-fix-for-Splunk-9-x-Invalid-Stanza-in/m-p/602699#M12926</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2022-06-21T18:06:18Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk 9.x Invalid Stanza in `federated.conf`</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Does-anyone-know-a-fix-for-Splunk-9-x-Invalid-Stanza-in/m-p/603144#M12977</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I got the exact same error after upgrading 8.2.6.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;splunk btool check --debug&lt;/P&gt;&lt;P&gt;...&lt;/P&gt;&lt;P&gt;Checking: /opt/splunk/etc/system/default/federated.conf&lt;BR /&gt;Invalid key in stanza [provider:splunk] in /opt/splunk/etc/system/default/federated.conf, line 20: mode (value: standard).&lt;BR /&gt;Invalid key in stanza [general] in /opt/splunk/etc/system/default/federated.conf, line 23: needs_consent (value: true).&lt;/P&gt;&lt;P&gt;...&lt;/P&gt;&lt;P&gt;splunk btool federated list --debug&lt;BR /&gt;/opt/splunk/etc/system/default/federated.conf [default]&lt;BR /&gt;/opt/splunk/etc/system/default/federated.conf [general]&lt;BR /&gt;/opt/splunk/etc/system/default/federated.conf needs_consent = true&lt;BR /&gt;/opt/splunk/etc/system/default/federated.conf [provider:splunk]&lt;BR /&gt;/opt/splunk/etc/system/default/federated.conf appContext = search&lt;BR /&gt;/opt/splunk/etc/system/default/federated.conf mode = standard&lt;BR /&gt;/opt/splunk/etc/system/default/federated.conf type = splunk&lt;BR /&gt;/opt/splunk/etc/system/default/federated.conf useFSHKnowledgeObjects = false&lt;/P&gt;&lt;P&gt;any idea?&lt;/P&gt;</description>
      <pubDate>Fri, 24 Jun 2022 10:34:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Does-anyone-know-a-fix-for-Splunk-9-x-Invalid-Stanza-in/m-p/603144#M12977</guid>
      <dc:creator>norbertt911</dc:creator>
      <dc:date>2022-06-24T10:34:29Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk 9.x Invalid Stanza in `federated.conf`</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Does-anyone-know-a-fix-for-Splunk-9-x-Invalid-Stanza-in/m-p/603184#M12985</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Correct me if I'm wrong but "mode" and "needs_consent" value definitions are missing from .../system/README/federated.conf.example and federated.conf.spec.&lt;/P&gt;&lt;P&gt;I think that causing the issue.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 24 Jun 2022 15:57:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Does-anyone-know-a-fix-for-Splunk-9-x-Invalid-Stanza-in/m-p/603184#M12985</guid>
      <dc:creator>norbertt911</dc:creator>
      <dc:date>2022-06-24T15:57:38Z</dc:date>
    </item>
    <item>
      <title>Re: Does anyone know w a fix for Splunk 9.x Invalid Stanza in `federated.conf`?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Does-anyone-know-a-fix-for-Splunk-9-x-Invalid-Stanza-in/m-p/603411#M13027</link>
      <description>&lt;P&gt;We found out that the current Splunk 9 Enterprise OnPrem tarfile updates the /etc/system/default/federated.conf file with new options/keys but they arent including the associated spec file in /etc/system/README/federated.conf.spec or the example file in /etc/system/README/federated.conf.example.&lt;BR /&gt;&lt;BR /&gt;So it is using the previous version of both spec and example files if you are upgrading, or none if it is a clean install.&lt;BR /&gt;&lt;BR /&gt;Also there is no information about the 9.0.0 federated.conf.spec in the conf files reference section of the online admin manual (there are entries for older versions &lt;A href="https://docs.splunk.com/Documentation/Splunk/8.2.6/Admin/Federatedconf" target="_blank" rel="noopener"&gt;https://docs.splunk.com/Documentation/Splunk/8.2.6/Admin/Federatedconf&lt;/A&gt;), so we cant generate the fixed spec file.&lt;BR /&gt;&lt;BR /&gt;We could add these missing options/keys into the spec file (assuming the spec is broken), or we could use the 8.2.6 federated.conf file that works (assuming the current one is broken).&lt;BR /&gt;Any ideas about this issue? or official responses from Splunk about this?&lt;/P&gt;</description>
      <pubDate>Mon, 27 Jun 2022 15:46:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Does-anyone-know-a-fix-for-Splunk-9-x-Invalid-Stanza-in/m-p/603411#M13027</guid>
      <dc:creator>joshiro</dc:creator>
      <dc:date>2022-06-27T15:46:46Z</dc:date>
    </item>
    <item>
      <title>Re: Does anyone know w a fix for Splunk 9.x Invalid Stanza in `federated.conf`?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Does-anyone-know-a-fix-for-Splunk-9-x-Invalid-Stanza-in/m-p/603425#M13031</link>
      <description>&lt;P&gt;If you are needing those options then add those to spec file otherwise remove/comment those. Anyway you should create a support case to splunk, that they could fix it for future versions.&lt;/P&gt;</description>
      <pubDate>Mon, 27 Jun 2022 17:20:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Does-anyone-know-a-fix-for-Splunk-9-x-Invalid-Stanza-in/m-p/603425#M13031</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2022-06-27T17:20:37Z</dc:date>
    </item>
    <item>
      <title>Re: Does anyone know w a fix for Splunk 9.x Invalid Stanza in `federated.conf`?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Does-anyone-know-a-fix-for-Splunk-9-x-Invalid-Stanza-in/m-p/603430#M13033</link>
      <description>&lt;P&gt;This is not something I configured intentionally.&amp;nbsp; This is the direct result of upgrade from Splunk 8.2.4 to 9.0.0.&lt;/P&gt;</description>
      <pubDate>Mon, 27 Jun 2022 17:58:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Does-anyone-know-a-fix-for-Splunk-9-x-Invalid-Stanza-in/m-p/603430#M13033</guid>
      <dc:creator>zrxcrasher</dc:creator>
      <dc:date>2022-06-27T17:58:07Z</dc:date>
    </item>
    <item>
      <title>Re: Does anyone know w a fix for Splunk 9.x Invalid Stanza in `federated.conf`?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Does-anyone-know-a-fix-for-Splunk-9-x-Invalid-Stanza-in/m-p/606033#M13368</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I have the same error after upgrade from 8.2.7.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;./splunk btool check --debug&lt;/P&gt;&lt;P&gt;Checking: /opt/splunk/etc/system/default/federated.conf&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Invalid key in stanza [provider:splunk] in /opt/splunk/etc/system/default/federated.conf, line 20: mode (value: standard).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Invalid key in stanza [general] in /opt/splunk/etc/system/default/federated.conf, line 23: needs_consent (value: true).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I’ve made some research on fresh 9.0.0 install doesn’t have this file.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;/opt/splunk/bin# ./splunk btool check --debug | grep fede&lt;/P&gt;&lt;P&gt;No spec file for: /opt/splunk/etc/system/default/federated.conf&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So it looks like an after upgrade issue.&lt;/P&gt;</description>
      <pubDate>Mon, 18 Jul 2022 18:35:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Does-anyone-know-a-fix-for-Splunk-9-x-Invalid-Stanza-in/m-p/606033#M13368</guid>
      <dc:creator>mskrzynski</dc:creator>
      <dc:date>2022-07-18T18:35:00Z</dc:date>
    </item>
    <item>
      <title>Re: Does anyone know w a fix for Splunk 9.x Invalid Stanza in `federated.conf`?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Does-anyone-know-a-fix-for-Splunk-9-x-Invalid-Stanza-in/m-p/606037#M13370</link>
      <description>&lt;P&gt;Hi again,&lt;/P&gt;&lt;P&gt;Fresh 9.0.0 install&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;find $SPLUNK_HOME/ -name federated.conf*&lt;/P&gt;&lt;P&gt;&lt;FONT color="#339966"&gt;/opt/splunk/var/run/splunk/confsnapshot/baseline_default/system/default/federated.conf&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#339966"&gt;/opt/splunk/etc/system/default/federated.conf&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;8.2.7 -&amp;gt; 9.0.0 install&lt;/P&gt;&lt;P&gt;find $SPLUNK_HOME/ -name federated.conf*&lt;/P&gt;&lt;P&gt;&lt;FONT color="#FF0000"&gt;&lt;STRONG&gt;/opt/splunk/etc/system/README/federated.conf.spec&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#FF0000"&gt;&lt;STRONG&gt;/opt/splunk/etc/system/README/federated.conf.example&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#008000"&gt;/opt/splunk/etc/system/default/federated.conf&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#008000"&gt;/opt/splunk/var/run/splunk/confsnapshot/baseline_default/system/default/federated.conf&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;root@srvslprosplunk1:/opt# mv /opt/splunk/etc/system/README/federated.conf.spec /home/splunk/&lt;/P&gt;&lt;P&gt;root@srvslprosplunk1:/opt# mv /opt/splunk/etc/system/README/federated.conf.example /home/splunk/&lt;/P&gt;&lt;P&gt;root@srvslprosplunk1:/opt# splunk/bin/splunk btool check –debug | grep fede&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;No spec file for: /opt/splunk/etc/system/default/federated.conf&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;/etc/inid.d/splunk start&lt;/P&gt;&lt;P&gt;…&lt;/P&gt;&lt;P&gt;…&lt;/P&gt;&lt;P&gt;Splunk&amp;gt; Finding your faults, just like mom.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Checking prerequisites...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Checking http port [8000]: open&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Checking mgmt port [8089]: open&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Checking appserver port [127.0.0.1:8065]: open&lt;/P&gt;&lt;P&gt;All preliminary checks passed.&lt;/P&gt;&lt;P&gt;…&lt;/P&gt;&lt;P&gt;Starting splunk server daemon (splunkd)...&lt;/P&gt;&lt;P&gt;If you get stuck, we're here to help.&lt;/P&gt;&lt;P&gt;Look for answers here: &lt;A href="http://docs.splunk.com" target="_blank"&gt;http://docs.splunk.com&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The Splunk web interface is at &lt;A href="https://xxx:8000" target="_blank"&gt;https://xxx:8000&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#008000"&gt;Works fine.&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 18 Jul 2022 18:55:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Does-anyone-know-a-fix-for-Splunk-9-x-Invalid-Stanza-in/m-p/606037#M13370</guid>
      <dc:creator>mskrzynski</dc:creator>
      <dc:date>2022-07-18T18:55:14Z</dc:date>
    </item>
    <item>
      <title>Re: Does anyone know w a fix for Splunk 9.x Invalid Stanza in `federated.conf`?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Does-anyone-know-a-fix-for-Splunk-9-x-Invalid-Stanza-in/m-p/606193#M13380</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;No offense, but he first rule of Splunk, that&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#FF0000"&gt;&lt;STRONG&gt;/opt/splunk/etc/system/README/&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#008000"&gt;/opt/splunk/etc/system/default&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;folders and content should be not modified. This is should be done by the Splunk support in a new release.&amp;nbsp; I understand that the do-it-yourself way faster,&amp;nbsp; but in the future, you can have unexpected behavior.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 19 Jul 2022 14:30:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Does-anyone-know-a-fix-for-Splunk-9-x-Invalid-Stanza-in/m-p/606193#M13380</guid>
      <dc:creator>norbertt911</dc:creator>
      <dc:date>2022-07-19T14:30:19Z</dc:date>
    </item>
    <item>
      <title>Re: Does anyone know w a fix for Splunk 9.x Invalid Stanza in `federated.conf`?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Does-anyone-know-a-fix-for-Splunk-9-x-Invalid-Stanza-in/m-p/606314#M13384</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I understand and agree with You.&lt;/P&gt;&lt;P&gt;But fresh install doesn’t have federated in README…&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best regards M.&lt;/P&gt;</description>
      <pubDate>Wed, 20 Jul 2022 10:02:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Does-anyone-know-a-fix-for-Splunk-9-x-Invalid-Stanza-in/m-p/606314#M13384</guid>
      <dc:creator>mskrzynski</dc:creator>
      <dc:date>2022-07-20T10:02:59Z</dc:date>
    </item>
    <item>
      <title>Re: Does anyone know a fix for Splunk 9.x Invalid Stanza in `federated.conf`?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Does-anyone-know-a-fix-for-Splunk-9-x-Invalid-Stanza-in/m-p/609431#M13629</link>
      <description>&lt;P&gt;I had the same problem and I could get rid of that error by renaming "federated.conf.spec" file from $SPLUNK_HOME/etc/system/README path.&lt;/P&gt;&lt;P&gt;Please upvote if this helpful.&lt;/P&gt;&lt;P&gt;Thanks, Mitesh.&lt;/P&gt;</description>
      <pubDate>Mon, 15 Aug 2022 03:28:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Does-anyone-know-a-fix-for-Splunk-9-x-Invalid-Stanza-in/m-p/609431#M13629</guid>
      <dc:creator>miteshp250283</dc:creator>
      <dc:date>2022-08-15T03:28:17Z</dc:date>
    </item>
  </channel>
</rss>

