<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Received event for unconfigured/disabled/deleted index=... in Installation</title>
    <link>https://community.splunk.com/t5/Installation/Received-event-for-unconfigured-disabled-deleted-index/m-p/556066#M8540</link>
    <description>&lt;P&gt;Hello, currently experience this error on the search head with a newly created index (created on the indexer). Does it take time for the indexer to show up on the search head?&lt;/P&gt;</description>
    <pubDate>Thu, 17 Jun 2021 00:18:35 GMT</pubDate>
    <dc:creator>jbmitchell</dc:creator>
    <dc:date>2021-06-17T00:18:35Z</dc:date>
    <item>
      <title>Received event for unconfigured/disabled/deleted index=...</title>
      <link>https://community.splunk.com/t5/Installation/Received-event-for-unconfigured-disabled-deleted-index/m-p/442462#M8537</link>
      <description>&lt;P&gt;Hi team!&lt;/P&gt;

&lt;P&gt;I have this error:&lt;/P&gt;

&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/7001iC8D3BBDB5F737522/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;But the Indexter is here. What appends?&lt;/P&gt;

&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/7002i2CA458241172E038/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 08 May 2019 10:15:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Received-event-for-unconfigured-disabled-deleted-index/m-p/442462#M8537</guid>
      <dc:creator>christianubeda</dc:creator>
      <dc:date>2019-05-08T10:15:48Z</dc:date>
    </item>
    <item>
      <title>Re: Received event for unconfigured/disabled/deleted index=...</title>
      <link>https://community.splunk.com/t5/Installation/Received-event-for-unconfigured-disabled-deleted-index/m-p/442463#M8538</link>
      <description>&lt;P&gt;please check&lt;BR /&gt;
1. if you get the errors from a single indexer (in a multi cluster system). if that's case, just check on that single indexer&lt;BR /&gt;
2. Did permissions change on Unix filesystem?&lt;BR /&gt;
3. How is the data collected? via UF directly to indexer?&lt;BR /&gt;
4. Check your indexes.conf on the individual indexer to see everything is good. Do a restart of indexer too&lt;/P&gt;</description>
      <pubDate>Wed, 08 May 2019 10:35:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Received-event-for-unconfigured-disabled-deleted-index/m-p/442463#M8538</guid>
      <dc:creator>koshyk</dc:creator>
      <dc:date>2019-05-08T10:35:24Z</dc:date>
    </item>
    <item>
      <title>Re: Received event for unconfigured/disabled/deleted index=...</title>
      <link>https://community.splunk.com/t5/Installation/Received-event-for-unconfigured-disabled-deleted-index/m-p/442464#M8539</link>
      <description>&lt;P&gt;Hi @christianubeda,&lt;/P&gt;

&lt;P&gt;This errors means that the server receiving the logs does not have that index. It could be a historical message if you've just created the index but if that's not the case then you might have created the index on your search head whereas data is coming in to your indexers (where the index was supposed to be).&lt;/P&gt;

&lt;P&gt;To fix this, go on your CM and make sure you deploy the new index configuration to the indexers as shown here in the docs: &lt;A href="https://docs.splunk.com/Documentation/Splunk/7.2.6/Indexer/Configurethepeerindexes"&gt;https://docs.splunk.com/Documentation/Splunk/7.2.6/Indexer/Configurethepeerindexes&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Let me know if that helps,&lt;/P&gt;

&lt;P&gt;Cheers,&lt;BR /&gt;
David&lt;/P&gt;</description>
      <pubDate>Wed, 08 May 2019 11:02:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Received-event-for-unconfigured-disabled-deleted-index/m-p/442464#M8539</guid>
      <dc:creator>DavidHourani</dc:creator>
      <dc:date>2019-05-08T11:02:07Z</dc:date>
    </item>
    <item>
      <title>Re: Received event for unconfigured/disabled/deleted index=...</title>
      <link>https://community.splunk.com/t5/Installation/Received-event-for-unconfigured-disabled-deleted-index/m-p/556066#M8540</link>
      <description>&lt;P&gt;Hello, currently experience this error on the search head with a newly created index (created on the indexer). Does it take time for the indexer to show up on the search head?&lt;/P&gt;</description>
      <pubDate>Thu, 17 Jun 2021 00:18:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Received-event-for-unconfigured-disabled-deleted-index/m-p/556066#M8540</guid>
      <dc:creator>jbmitchell</dc:creator>
      <dc:date>2021-06-17T00:18:35Z</dc:date>
    </item>
  </channel>
</rss>

