<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Why am I getting errors in system default file configuration when upgrading a Universal Forwarder from 8.2.5 to 9.0.0.1? in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/Why-am-I-getting-errors-in-system-default-file-configuration/m-p/609851#M13663</link>
    <description>&lt;P&gt;Dear All,&lt;/P&gt;&lt;P&gt;I have a pretty bare Splunk Universal Forwarder that was installed at 8.2.5 and had no errors on restart, but when I upgraded it to 9.0.0.1, I started to get the following errors?&lt;/P&gt;&lt;P&gt;NOTE: These are all in the system/default files (so not my settings):&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;Invalid key in stanza [webhook] in /opt/splunkforwarder/etc/system/default/alert_actions.conf, line 229: enable_allowlist (value: false).&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;Invalid key in stanza [provider:splunk] in /opt/splunkforwarder/etc/system/default/federated.conf, line 20: mode (value: standard).&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;Invalid key in stanza [general] in /opt/splunkforwarder/etc/system/default/federated.conf, line 23: needs_consent (value: true).&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 17 Aug 2022 17:45:00 GMT</pubDate>
    <dc:creator>BlueSocket</dc:creator>
    <dc:date>2022-08-17T17:45:00Z</dc:date>
    <item>
      <title>Why am I getting errors in system default file configuration when upgrading a Universal Forwarder from 8.2.5 to 9.0.0.1?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Why-am-I-getting-errors-in-system-default-file-configuration/m-p/609851#M13663</link>
      <description>&lt;P&gt;Dear All,&lt;/P&gt;&lt;P&gt;I have a pretty bare Splunk Universal Forwarder that was installed at 8.2.5 and had no errors on restart, but when I upgraded it to 9.0.0.1, I started to get the following errors?&lt;/P&gt;&lt;P&gt;NOTE: These are all in the system/default files (so not my settings):&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;Invalid key in stanza [webhook] in /opt/splunkforwarder/etc/system/default/alert_actions.conf, line 229: enable_allowlist (value: false).&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;Invalid key in stanza [provider:splunk] in /opt/splunkforwarder/etc/system/default/federated.conf, line 20: mode (value: standard).&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;Invalid key in stanza [general] in /opt/splunkforwarder/etc/system/default/federated.conf, line 23: needs_consent (value: true).&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 17 Aug 2022 17:45:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Why-am-I-getting-errors-in-system-default-file-configuration/m-p/609851#M13663</guid>
      <dc:creator>BlueSocket</dc:creator>
      <dc:date>2022-08-17T17:45:00Z</dc:date>
    </item>
    <item>
      <title>Re: Why am I getting errors in system default file configuration when upgrading a Universal Forwarder from 8.2.5 to 9.0.</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Why-am-I-getting-errors-in-system-default-file-configuration/m-p/609872#M13668</link>
      <description>&lt;P&gt;"Pretty sure"?&amp;nbsp; I can't find those settings in the 8.2.5 or 9.0.0 docs so I wonder what they're doing there.&amp;nbsp; None of them apply to Universal Forwarders so you might as well remove them.&lt;/P&gt;</description>
      <pubDate>Wed, 17 Aug 2022 20:59:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Why-am-I-getting-errors-in-system-default-file-configuration/m-p/609872#M13668</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2022-08-17T20:59:57Z</dc:date>
    </item>
    <item>
      <title>Re: Why am I getting errors in system default file configuration when upgrading a Universal Forwarder from 8.2.5 to 9.0.</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Why-am-I-getting-errors-in-system-default-file-configuration/m-p/610305#M13695</link>
      <description>&lt;P&gt;I am not sure how those settings got there, but the way that I got those errors was:&lt;/P&gt;&lt;P&gt;1) Install Splunk Universal Forwarder at version 8.2.5.&lt;/P&gt;&lt;P&gt;2) Upgrade Splunk Universal Forwarder to 9.0.0.1.&lt;/P&gt;&lt;P&gt;I just redid it and on start up of the Forwarder, I get these messages:&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;Invalid key in stanza [webhook] in /opt/splunkforwarder/etc/system/default/alert_actions.conf, line 229: enable_allowlist (value: false).&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;Invalid key in stanza [provider:splunk] in /opt/splunkforwarder/etc/system/default/federated.conf, line 20: mode (value: standard).&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;Invalid key in stanza [general] in /opt/splunkforwarder/etc/system/default/federated.conf, line 23: needs_consent (value: true).&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;I will take out the weird configurations, but this is kind-of to help others, if they get the same results.&lt;/P&gt;</description>
      <pubDate>Mon, 22 Aug 2022 09:32:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Why-am-I-getting-errors-in-system-default-file-configuration/m-p/610305#M13695</guid>
      <dc:creator>BlueSocket</dc:creator>
      <dc:date>2022-08-22T09:32:08Z</dc:date>
    </item>
  </channel>
</rss>

