<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: received event for unconfigured/disabled index=_audit in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/received-event-for-unconfigured-disabled-index-audit/m-p/56868#M8746</link>
    <description>&lt;P&gt;This is a defect in 4.1.x, the message happens when you restart a LWF. I have been able to replicate the issue. It has been reported to support and is being investigated by engineering.  This has been added to the known issues document, see SPL-37337:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;&lt;A href="http://www.splunk.com/base/Documentation/4.1.7/ReleaseNotes/Knownissues" target="test_blank"&gt;http://www.splunk.com/base/Documentation/4.1.7/ReleaseNotes/Knownissues&lt;/A&gt;
&lt;/CODE&gt;&lt;/PRE&gt;</description>
    <pubDate>Thu, 24 Mar 2011 23:30:11 GMT</pubDate>
    <dc:creator>jbsplunk</dc:creator>
    <dc:date>2011-03-24T23:30:11Z</dc:date>
    <item>
      <title>received event for unconfigured/disabled index=_audit</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/received-event-for-unconfigured-disabled-index-audit/m-p/56866#M8744</link>
      <description>&lt;P&gt;Currently, I have enabled splunk forwarder on a particular windows box with SSL encryption to the indexer. ( Although this may not be actually the source of the issue)&lt;/P&gt;

&lt;P&gt;I am receiving events for unconfigured/disabled index='_audit' on the forwader for some reason. I did verify that all the indexes in the forwarder are enabled, and the same holds true for the receiver&lt;/P&gt;

&lt;P&gt;Any idea what could be the source of the issue? &lt;/P&gt;</description>
      <pubDate>Thu, 10 Mar 2011 10:34:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/received-event-for-unconfigured-disabled-index-audit/m-p/56866#M8744</guid>
      <dc:creator>heterodyned</dc:creator>
      <dc:date>2011-03-10T10:34:16Z</dc:date>
    </item>
    <item>
      <title>Re: received event for unconfigured/disabled index=_audit</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/received-event-for-unconfigured-disabled-index-audit/m-p/56867#M8745</link>
      <description>&lt;P&gt;I could fix this issue, the windows forwarder was actually configured as LightForwarder and was still operating in LightForwarder Mode, ( this was done by someone previously) and at the sametime I was using the SplunkWebUI for this particular server, which was causing these events. &lt;/P&gt;

&lt;P&gt;Solution: I disabled splunk-light forwarder and enabled forwarder mode, the issue got resolved&lt;/P&gt;</description>
      <pubDate>Thu, 10 Mar 2011 13:30:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/received-event-for-unconfigured-disabled-index-audit/m-p/56867#M8745</guid>
      <dc:creator>heterodyned</dc:creator>
      <dc:date>2011-03-10T13:30:27Z</dc:date>
    </item>
    <item>
      <title>Re: received event for unconfigured/disabled index=_audit</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/received-event-for-unconfigured-disabled-index-audit/m-p/56868#M8746</link>
      <description>&lt;P&gt;This is a defect in 4.1.x, the message happens when you restart a LWF. I have been able to replicate the issue. It has been reported to support and is being investigated by engineering.  This has been added to the known issues document, see SPL-37337:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;&lt;A href="http://www.splunk.com/base/Documentation/4.1.7/ReleaseNotes/Knownissues" target="test_blank"&gt;http://www.splunk.com/base/Documentation/4.1.7/ReleaseNotes/Knownissues&lt;/A&gt;
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Thu, 24 Mar 2011 23:30:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/received-event-for-unconfigured-disabled-index-audit/m-p/56868#M8746</guid>
      <dc:creator>jbsplunk</dc:creator>
      <dc:date>2011-03-24T23:30:11Z</dc:date>
    </item>
  </channel>
</rss>

