<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Why am I getting Invalid key in stanza errors when running ./splunk btool check --debug ? in Monitoring Splunk</title>
    <link>https://community.splunk.com/t5/Monitoring-Splunk/Why-am-I-getting-Invalid-key-in-stanza-errors-when-running/m-p/380972#M3259</link>
    <description>&lt;P&gt;If an attribute does not exist in the .spec file, then it should not be present in the matching .conf file.  Edit the .conf file to remove the offending attribute then re-run btool to verify there are no other warnings.&lt;/P&gt;</description>
    <pubDate>Mon, 24 Sep 2018 11:24:42 GMT</pubDate>
    <dc:creator>richgalloway</dc:creator>
    <dc:date>2018-09-24T11:24:42Z</dc:date>
    <item>
      <title>Why am I getting Invalid key in stanza errors when running ./splunk btool check --debug ?</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Why-am-I-getting-Invalid-key-in-stanza-errors-when-running/m-p/380968#M3255</link>
      <description>&lt;PRE&gt;&lt;CODE&gt;Checking: /opt/splunk/etc/apps/splunk_httpinput/default/inputs.conf
                Invalid key in stanza [http] in /opt/splunk/etc/apps/splunk_httpinput/default/inputs.conf, line 3: p
ort (value: 8088)
                Invalid key in stanza [http] in /opt/splunk/etc/apps/splunk_httpinput/default/inputs.conf, line 4: e
nableSSL (value: 1)
                Invalid key in stanza [http] in /opt/splunk/etc/apps/splunk_httpinput/default/inputs.conf, line 6: d
edicatedIoThreads (value: 2)
                Invalid key in stanza [http] in /opt/splunk/etc/apps/splunk_httpinput/default/inputs.conf, line 7: m
axThreads  (value:  0)
                Invalid key in stanza [http] in /opt/splunk/etc/apps/splunk_httpinput/default/inputs.conf, line 8: maxSockets  (value:  0)
                Invalid key in stanza [http] in /opt/splunk/etc/apps/splunk_httpinput/default/inputs.conf, line 9: useDeploymentServer (value: 0)
                Invalid key in stanza [http] in /opt/splunk/etc/apps/splunk_httpinput/default/inputs.conf, line 11: sslVersions (value: *,-ssl2)
        Did you mean 'source'?
        Did you mean 'sourcetype'?
                Invalid key in stanza [http] in /opt/splunk/etc/apps/splunk_httpinput/default/inputs.conf, line 12: allowSslCompression (value: true)
                Invalid key in stanza [http] in /opt/splunk/etc/apps/splunk_httpinput/default/inputs.conf, line 13: allowSslRenegotiation (value: true)
Checking: /fs/untd-1/splunk/etc/apps/splunk_instrumentation/default/app.conf
                Invalid key in stanza [ui] in /opt/splunk/etc/apps/splunk_instrumentation/default/app.conf, line 12: show_in_nav  (value:  0)
Checking: /fs/untd-1/splunk/etc/apps/splunk_instrumentation/default/collections.conf
                Invalid key in stanza [instrumentation] in /opt/splunk/etc/apps/splunk_instrumentation/default/collections.conf, line 10: type  (value:  internal_cache)
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;What I have identified is after the Splunk server moved from CentOS 5 to CentOS 6, below are new folders that got created.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;drwxr-xr-x  3   31855    31855 4096 Feb 28  2018 splunk_httpinput
drwxr-xr-x  5   31855    31855 4096 Feb 28  2018 splunk_archiver
drwxr-xr-x  4   31855    31855 4096 Feb 28  2018 appsbrowser
drwxr-xr-x  7   31855    31855 4096 Feb 28  2018 alert_webhook
drwxr-xr-x  7   31855    31855 4096 Feb 28  2018 alert_logevent
drwxr-xr-x  7   31855    31855 4096 Feb 28  2018 splunk_instrumentation
drwxr-xr-x 11   31855    31855 4096 Feb 28  2018 splunk_monitoring_console
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;I'm getting alerts from all the files in the above dirs. How can I fix them? I'm using Splunk 6.2.2 version&lt;/P&gt;

&lt;P&gt;Thanks&lt;BR /&gt;
Rajesh&lt;/P&gt;</description>
      <pubDate>Fri, 21 Sep 2018 11:16:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Why-am-I-getting-Invalid-key-in-stanza-errors-when-running/m-p/380968#M3255</guid>
      <dc:creator>rajesh_pidikiti</dc:creator>
      <dc:date>2018-09-21T11:16:47Z</dc:date>
    </item>
    <item>
      <title>Re: Why am I getting Invalid key in stanza errors when running ./splunk btool check --debug ?</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Why-am-I-getting-Invalid-key-in-stanza-errors-when-running/m-p/380969#M3256</link>
      <description>&lt;P&gt;Those messages mean btool found an attribute ("key") in a .conf file that is not present in the corresponding .conf.spec file.  The .conf.spec file identifies all of the valid keys allowed in the .conf.  Use a text editor to review the files listed in the btool output and verify everything on the left side of an "=" is also present in the matching .spec file.  Some of the keys you are using may be for newer versions of Splunk.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Sep 2018 12:45:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Why-am-I-getting-Invalid-key-in-stanza-errors-when-running/m-p/380969#M3256</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2018-09-21T12:45:19Z</dc:date>
    </item>
    <item>
      <title>Re: Why am I getting Invalid key in stanza errors when running ./splunk btool check --debug ?</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Why-am-I-getting-Invalid-key-in-stanza-errors-when-running/m-p/380970#M3257</link>
      <description>&lt;P&gt;hi @rajesh_pidikiti &lt;/P&gt;

&lt;P&gt;Did the answer below solve your problem? If so, please resolve this post by approving it! &lt;BR /&gt;
If your problem is still not solved, keep us updated so that someone else can help ya.&lt;BR /&gt;
Thanks for posting!&lt;/P&gt;</description>
      <pubDate>Fri, 21 Sep 2018 21:12:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Why-am-I-getting-Invalid-key-in-stanza-errors-when-running/m-p/380970#M3257</guid>
      <dc:creator>mstjohn_splunk</dc:creator>
      <dc:date>2018-09-21T21:12:26Z</dc:date>
    </item>
    <item>
      <title>Re: Why am I getting Invalid key in stanza errors when running ./splunk btool check --debug ?</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Why-am-I-getting-Invalid-key-in-stanza-errors-when-running/m-p/380971#M3258</link>
      <description>&lt;P&gt;Thanks. Yeah, I'm seeing the conf.spec doesn't have any data.  &lt;/P&gt;

&lt;BLOCKQUOTE&gt;
&lt;BLOCKQUOTE&gt;
&lt;BLOCKQUOTE&gt;
&lt;/BLOCKQUOTE&gt;
&lt;/BLOCKQUOTE&gt;
&lt;/BLOCKQUOTE&gt;

&lt;PRE&gt;&lt;CODE&gt;[logevent]

param.event = &amp;lt;string&amp;gt;
* Default value for event content sent to the receiver endpoint, which is eventually indexed

param.host = &amp;lt;string&amp;gt;
* Default field value of the host field of the newly indexed event

param.source = &amp;lt;string&amp;gt;
* Default field value of the source field of the newly indexed event

param.sourcetype = &amp;lt;string&amp;gt;
* Default field value of the sourcetype field of the newly indexed event

param.index = &amp;lt;string&amp;gt;
* Default field value for the destination index of the newly indexed event
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&lt;/P&gt;

&lt;P&gt;In my env, I don't require all these apps like alert_webhook, splunk_instrumentation, etc. How can disable or remove them?&lt;/P&gt;

&lt;P&gt;Thanks&lt;BR /&gt;
Rajesh&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 21:21:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Why-am-I-getting-Invalid-key-in-stanza-errors-when-running/m-p/380971#M3258</guid>
      <dc:creator>rajesh_pidikiti</dc:creator>
      <dc:date>2020-09-29T21:21:33Z</dc:date>
    </item>
    <item>
      <title>Re: Why am I getting Invalid key in stanza errors when running ./splunk btool check --debug ?</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Why-am-I-getting-Invalid-key-in-stanza-errors-when-running/m-p/380972#M3259</link>
      <description>&lt;P&gt;If an attribute does not exist in the .spec file, then it should not be present in the matching .conf file.  Edit the .conf file to remove the offending attribute then re-run btool to verify there are no other warnings.&lt;/P&gt;</description>
      <pubDate>Mon, 24 Sep 2018 11:24:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Why-am-I-getting-Invalid-key-in-stanza-errors-when-running/m-p/380972#M3259</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2018-09-24T11:24:42Z</dc:date>
    </item>
    <item>
      <title>Re: Why am I getting Invalid key in stanza errors when running ./splunk btool check --debug ?</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Why-am-I-getting-Invalid-key-in-stanza-errors-when-running/m-p/527582#M4617</link>
      <description>&lt;P&gt;Thanks &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/213957"&gt;@richgalloway&lt;/a&gt;&amp;nbsp;. Your answer should be selected as "solution" cuz it definitely answered it for me and solve it for me.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 02 Nov 2020 18:26:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Why-am-I-getting-Invalid-key-in-stanza-errors-when-running/m-p/527582#M4617</guid>
      <dc:creator>aa70627</dc:creator>
      <dc:date>2020-11-02T18:26:04Z</dc:date>
    </item>
  </channel>
</rss>

