<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Received event for unconfigured/disabled/delted...... in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Received-event-for-unconfigured-disabled-delted/m-p/341003#M161293</link>
    <description>&lt;P&gt;I am a splunk novice.&lt;/P&gt;

&lt;P&gt;&lt;A href="Https://answers.splunk.com/answers/522405/why-is-there-no-data-in-my-summary-index.html"&gt;Https://answers.splunk.com/answers/522405/why-is-there-no-data-in-my-summary-index.html&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;URL of the file or not resolved.&lt;/P&gt;

&lt;P&gt;Description: I created a Splunk cluster and created a lot of alert strategies on my search server. Some alerts open the summary index, and the summary index name is "alerts", I confirm that the alerts are the existing . And I'm sure a lot of alert have been triggered. But I'm running "index = alerts" on the search server. Return empty And I got this information on the search server's WEBUI: "Received event for unconfigured / disabled / delted ...." as shown below:&lt;/P&gt;

&lt;P&gt;Question: Why is my summary index no data written? Is there a problem with my configuration?&lt;/P&gt;

&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/2812iB7DA7625BEAE4758/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 21 Apr 2017 07:40:33 GMT</pubDate>
    <dc:creator>xsstest</dc:creator>
    <dc:date>2017-04-21T07:40:33Z</dc:date>
    <item>
      <title>Received event for unconfigured/disabled/delted......</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Received-event-for-unconfigured-disabled-delted/m-p/341003#M161293</link>
      <description>&lt;P&gt;I am a splunk novice.&lt;/P&gt;

&lt;P&gt;&lt;A href="Https://answers.splunk.com/answers/522405/why-is-there-no-data-in-my-summary-index.html"&gt;Https://answers.splunk.com/answers/522405/why-is-there-no-data-in-my-summary-index.html&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;URL of the file or not resolved.&lt;/P&gt;

&lt;P&gt;Description: I created a Splunk cluster and created a lot of alert strategies on my search server. Some alerts open the summary index, and the summary index name is "alerts", I confirm that the alerts are the existing . And I'm sure a lot of alert have been triggered. But I'm running "index = alerts" on the search server. Return empty And I got this information on the search server's WEBUI: "Received event for unconfigured / disabled / delted ...." as shown below:&lt;/P&gt;

&lt;P&gt;Question: Why is my summary index no data written? Is there a problem with my configuration?&lt;/P&gt;

&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/2812iB7DA7625BEAE4758/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Apr 2017 07:40:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Received-event-for-unconfigured-disabled-delted/m-p/341003#M161293</guid>
      <dc:creator>xsstest</dc:creator>
      <dc:date>2017-04-21T07:40:33Z</dc:date>
    </item>
    <item>
      <title>Re: Received event for unconfigured/disabled/delted......</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Received-event-for-unconfigured-disabled-delted/m-p/341004#M161294</link>
      <description>&lt;P&gt;Have you enabled data forwarding on the search head to send the indexed data to the indexers? You can enable event forwarding on the serch head going to settings &amp;gt; forwarding and receiving &amp;gt; configure forwarding &amp;gt; add your two indexers. This way the data that you asked to index on the search head will be forwarder to the indexers and will get indexed.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Apr 2017 13:49:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Received-event-for-unconfigured-disabled-delted/m-p/341004#M161294</guid>
      <dc:creator>gfreitas</dc:creator>
      <dc:date>2017-04-21T13:49:16Z</dc:date>
    </item>
    <item>
      <title>Re: Received event for unconfigured/disabled/delted......</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Received-event-for-unconfigured-disabled-delted/m-p/341005#M161295</link>
      <description>&lt;P&gt;This is a cluster&lt;/P&gt;</description>
      <pubDate>Mon, 24 Apr 2017 05:40:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Received-event-for-unconfigured-disabled-delted/m-p/341005#M161295</guid>
      <dc:creator>xsstest</dc:creator>
      <dc:date>2017-04-24T05:40:48Z</dc:date>
    </item>
    <item>
      <title>Re: Received event for unconfigured/disabled/delted......</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Received-event-for-unconfigured-disabled-delted/m-p/341006#M161296</link>
      <description>&lt;P&gt;Can you run the below query and verify if the index is created on your indexers?&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;| eventcount summarize=false index=alerts
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Verify if all your indexers are listed here.&lt;BR /&gt;
Try restarting the indexers also once.&lt;/P&gt;</description>
      <pubDate>Mon, 24 Apr 2017 06:30:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Received-event-for-unconfigured-disabled-delted/m-p/341006#M161296</guid>
      <dc:creator>dineshraj9</dc:creator>
      <dc:date>2017-04-24T06:30:16Z</dc:date>
    </item>
    <item>
      <title>Re: Received event for unconfigured/disabled/delted......</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Received-event-for-unconfigured-disabled-delted/m-p/341007#M161297</link>
      <description>&lt;P&gt;result is  0 .  What should I do next?&lt;/P&gt;</description>
      <pubDate>Mon, 24 Apr 2017 06:48:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Received-event-for-unconfigured-disabled-delted/m-p/341007#M161297</guid>
      <dc:creator>xsstest</dc:creator>
      <dc:date>2017-04-24T06:48:32Z</dc:date>
    </item>
  </channel>
</rss>

