<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: TransformsExtractionHandler - Unable to find stanza. Getting thousands of warnings in _internal splunkd in Splunk Enterprise Security</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/TransformsExtractionHandler-Unable-to-find-stanza-Getting/m-p/120709#M289</link>
    <description>&lt;P&gt;Is this resolved ?&lt;/P&gt;</description>
    <pubDate>Mon, 21 Sep 2015 02:27:41 GMT</pubDate>
    <dc:creator>i2sheri</dc:creator>
    <dc:date>2015-09-21T02:27:41Z</dc:date>
    <item>
      <title>TransformsExtractionHandler - Unable to find stanza. Getting thousands of warnings in _internal splunkd</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/TransformsExtractionHandler-Unable-to-find-stanza-Getting/m-p/120702#M282</link>
      <description>&lt;P&gt;Hey Splunkers, &lt;/P&gt;

&lt;P&gt;I'm getting an error in _internal that I can't seem to figure out. Every enabled app that has a csv lookup is throwing this error in splunkd.log.  These happen quite frequently -- adding up to 100,000 a day! &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;Environmont Details: Splunk 6.1. Enterprise Security 3.1  &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;06-26-2014 04:24:00.807 +0000 WARN  TransformsExtractionHandler - Unable to find stanza=identities_expanded.csv in lookups.conf, cannot enumerate fields list
06-26-2014 04:24:00.807 +0000 WARN  TransformsExtractionHandler - Unable to find stanza=pci_domains.csv in lookups.conf, cannot enumerate fields list
06-26-2014 04:24:00.807 +0000 WARN  TransformsExtractionHandler - Unable to find stanza=pci_domains_from_assets.csv in lookups.conf, cannot enumerate fields list
06-26-2014 04:24:00.807 +0000 WARN  TransformsExtractionHandler - Unable to find stanza=assets.csv in lookups.conf, cannot enumerate fields list
06-26-2014 04:24:00.807 +0000 WARN  TransformsExtractionHandler - Unable to find stanza=identities.csv in lookups.conf, cannot enumerate fields list
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Why would Splunk complain about every csv lookup in my environment??? I don't get any syantax errors when I start splunk. Any help would be greatly appreciated. Thanks! &lt;/P&gt;</description>
      <pubDate>Thu, 26 Jun 2014 05:35:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/TransformsExtractionHandler-Unable-to-find-stanza-Getting/m-p/120702#M282</guid>
      <dc:creator>joshuamcqueen</dc:creator>
      <dc:date>2014-06-26T05:35:14Z</dc:date>
    </item>
    <item>
      <title>Re: TransformsExtractionHandler - Unable to find stanza. Getting thousands of warnings in _internal splunkd</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/TransformsExtractionHandler-Unable-to-find-stanza-Getting/m-p/120703#M283</link>
      <description>&lt;P&gt;Its a bug in Splunk. A ticket has been opened for this (ticket number SPL-82145).&lt;/P&gt;</description>
      <pubDate>Thu, 26 Jun 2014 06:15:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/TransformsExtractionHandler-Unable-to-find-stanza-Getting/m-p/120703#M283</guid>
      <dc:creator>LukeMurphey</dc:creator>
      <dc:date>2014-06-26T06:15:04Z</dc:date>
    </item>
    <item>
      <title>Re: TransformsExtractionHandler - Unable to find stanza. Getting thousands of warnings in _internal splunkd</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/TransformsExtractionHandler-Unable-to-find-stanza-Getting/m-p/120704#M284</link>
      <description>&lt;P&gt;Thanks or the info. Is this warning harmless? Can it be affecting performance? Is there anyway to suppress?&lt;/P&gt;</description>
      <pubDate>Thu, 26 Jun 2014 14:25:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/TransformsExtractionHandler-Unable-to-find-stanza-Getting/m-p/120704#M284</guid>
      <dc:creator>joshuamcqueen</dc:creator>
      <dc:date>2014-06-26T14:25:58Z</dc:date>
    </item>
    <item>
      <title>Re: TransformsExtractionHandler - Unable to find stanza. Getting thousands of warnings in _internal splunkd</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/TransformsExtractionHandler-Unable-to-find-stanza-Getting/m-p/120705#M285</link>
      <description>&lt;P&gt;The warning is harmless (except for consuming disk space and I/O when being written). You can suppress it by setting this in log.cfg:&lt;/P&gt;

&lt;P&gt;category.TransformsExtractionHandler=ERROR&lt;/P&gt;

&lt;P&gt;However, you'd lose other warning messages from that category via that solution; caveat emptor.&lt;/P&gt;</description>
      <pubDate>Thu, 26 Jun 2014 15:40:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/TransformsExtractionHandler-Unable-to-find-stanza-Getting/m-p/120705#M285</guid>
      <dc:creator>jervin_splunk</dc:creator>
      <dc:date>2014-06-26T15:40:10Z</dc:date>
    </item>
    <item>
      <title>Re: TransformsExtractionHandler - Unable to find stanza. Getting thousands of warnings in _internal splunkd</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/TransformsExtractionHandler-Unable-to-find-stanza-Getting/m-p/120706#M286</link>
      <description>&lt;P&gt;I have the same problem.&lt;BR /&gt;
I've just done this change in log.conf "category.TransformsExtractionHandler=ERROR", but issue is still alive.&lt;/P&gt;

&lt;P&gt;Any other workaround?&lt;/P&gt;</description>
      <pubDate>Tue, 01 Jul 2014 16:52:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/TransformsExtractionHandler-Unable-to-find-stanza-Getting/m-p/120706#M286</guid>
      <dc:creator>antonioformato</dc:creator>
      <dc:date>2014-07-01T16:52:32Z</dc:date>
    </item>
    <item>
      <title>Re: TransformsExtractionHandler - Unable to find stanza. Getting thousands of warnings in _internal splunkd</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/TransformsExtractionHandler-Unable-to-find-stanza-Getting/m-p/120707#M287</link>
      <description>&lt;P&gt;Did you restart Splunk to make the updated log.cfg take effect? I'm not seeing the messages following a restart, but am likely on a different product version.&lt;/P&gt;

&lt;P&gt;To make the settings take effect immediately, you can also do this:&lt;/P&gt;

&lt;P&gt;splunk set log-level TransformsExtractionHandler -level ERROR&lt;/P&gt;

&lt;P&gt;However I don't think that will persist beyond a restart.&lt;/P&gt;

&lt;P&gt;If you continue to have trouble, I'd suggest opening a support case; there could be other issues at play.&lt;/P&gt;</description>
      <pubDate>Wed, 02 Jul 2014 23:13:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/TransformsExtractionHandler-Unable-to-find-stanza-Getting/m-p/120707#M287</guid>
      <dc:creator>jervin_splunk</dc:creator>
      <dc:date>2014-07-02T23:13:59Z</dc:date>
    </item>
    <item>
      <title>Re: TransformsExtractionHandler - Unable to find stanza. Getting thousands of warnings in _internal splunkd</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/TransformsExtractionHandler-Unable-to-find-stanza-Getting/m-p/120708#M288</link>
      <description>&lt;P&gt;added as a known issue for splunk 6.1.*&lt;BR /&gt;
&lt;A href="http://docs.splunk.com/Documentation/Splunk/6.1.3/ReleaseNotes/KnownIssues#Search.2C_saved_search.2C_alerting.2C_scheduling.2C_and_job_management_issues"&gt;http://docs.splunk.com/Documentation/Splunk/6.1.3/ReleaseNotes/KnownIssues#Search.2C_saved_search.2C_alerting.2C_scheduling.2C_and_job_management_issues&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 05 Sep 2014 04:11:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/TransformsExtractionHandler-Unable-to-find-stanza-Getting/m-p/120708#M288</guid>
      <dc:creator>yannK</dc:creator>
      <dc:date>2014-09-05T04:11:28Z</dc:date>
    </item>
    <item>
      <title>Re: TransformsExtractionHandler - Unable to find stanza. Getting thousands of warnings in _internal splunkd</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/TransformsExtractionHandler-Unable-to-find-stanza-Getting/m-p/120709#M289</link>
      <description>&lt;P&gt;Is this resolved ?&lt;/P&gt;</description>
      <pubDate>Mon, 21 Sep 2015 02:27:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/TransformsExtractionHandler-Unable-to-find-stanza-Getting/m-p/120709#M289</guid>
      <dc:creator>i2sheri</dc:creator>
      <dc:date>2015-09-21T02:27:41Z</dc:date>
    </item>
  </channel>
</rss>

