<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Why am I getting the following error after updating from 6.6.0 to 6.6.3: Invalid key in stanza [auditTrail] in /opt/splunk/etc/system/local/audit.conf in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Why-am-I-getting-the-following-error-after-updating-from-6-6-0/m-p/343505#M165994</link>
    <description>&lt;P&gt;"Block signing" was removed in 6.3 when it was replaced by "data integrity".&lt;/P&gt;

&lt;P&gt;Even though you may have had config in your audit.conf for keys, I don't think this has been doing anything at all since 6.3.&lt;BR /&gt;
It looks like they tidied up the superfluous config between the versions you mention, so on the face of it, the solution is simply to remove those configurations because they have not been used for a few years. &lt;/P&gt;

&lt;P&gt;Might be worth checking if you enabled DI following Splunk 6.3&lt;/P&gt;</description>
    <pubDate>Wed, 17 Jan 2018 21:27:06 GMT</pubDate>
    <dc:creator>nickhills</dc:creator>
    <dc:date>2018-01-17T21:27:06Z</dc:date>
    <item>
      <title>Why am I getting the following error after updating from 6.6.0 to 6.6.3: Invalid key in stanza [auditTrail] in /opt/splunk/etc/system/local/audit.conf</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-am-I-getting-the-following-error-after-updating-from-6-6-0/m-p/343499#M165988</link>
      <description>&lt;P&gt;I'm getting this error:  Invalid key in stanza [auditTrail] in /opt/splunk/etc/system/local/audit.conf&lt;/P&gt;

&lt;P&gt;Looking at the audit.conf.spec, that key is no longer mentioned.  In earlier versions it was.  I couldn't find anything in the release notes  about this.&lt;/P&gt;</description>
      <pubDate>Wed, 20 Sep 2017 15:01:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-am-I-getting-the-following-error-after-updating-from-6-6-0/m-p/343499#M165988</guid>
      <dc:creator>gregbo</dc:creator>
      <dc:date>2017-09-20T15:01:10Z</dc:date>
    </item>
    <item>
      <title>Re: Why am I getting the following error after updating from 6.6.0 to 6.6.3: Invalid key in stanza [auditTrail] in /opt/splunk/etc/system/local/audit.conf</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-am-I-getting-the-following-error-after-updating-from-6-6-0/m-p/343500#M165989</link>
      <description>&lt;P&gt;Would you mind sharing the key name?&lt;/P&gt;</description>
      <pubDate>Wed, 20 Sep 2017 17:32:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-am-I-getting-the-following-error-after-updating-from-6-6-0/m-p/343500#M165989</guid>
      <dc:creator>s2_splunk</dc:creator>
      <dc:date>2017-09-20T17:32:22Z</dc:date>
    </item>
    <item>
      <title>Re: Why am I getting the following error after updating from 6.6.0 to 6.6.3: Invalid key in stanza [auditTrail] in /opt/splunk/etc/system/local/audit.conf</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-am-I-getting-the-following-error-after-updating-from-6-6-0/m-p/343501#M165990</link>
      <description>&lt;P&gt;Seems between 6.6.2 and 6.6.3 there were some features changed in the spec file. Im guessing this is around the privatekey and publickey keys in the config file?&lt;/P&gt;</description>
      <pubDate>Wed, 20 Sep 2017 18:04:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-am-I-getting-the-following-error-after-updating-from-6-6-0/m-p/343501#M165990</guid>
      <dc:creator>esix_splunk</dc:creator>
      <dc:date>2017-09-20T18:04:10Z</dc:date>
    </item>
    <item>
      <title>Re: Why am I getting the following error after updating from 6.6.0 to 6.6.3: Invalid key in stanza [auditTrail] in /opt/splunk/etc/system/local/audit.conf</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-am-I-getting-the-following-error-after-updating-from-6-6-0/m-p/343502#M165991</link>
      <description>&lt;P&gt;the privatekey and publickey keys&lt;/P&gt;</description>
      <pubDate>Thu, 21 Sep 2017 09:59:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-am-I-getting-the-following-error-after-updating-from-6-6-0/m-p/343502#M165991</guid>
      <dc:creator>gregbo</dc:creator>
      <dc:date>2017-09-21T09:59:57Z</dc:date>
    </item>
    <item>
      <title>Re: Why am I getting the following error after updating from 6.6.0 to 6.6.3: Invalid key in stanza [auditTrail] in /opt/splunk/etc/system/local/audit.conf</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-am-I-getting-the-following-error-after-updating-from-6-6-0/m-p/343503#M165992</link>
      <description>&lt;P&gt;yep, the privatekey and publickey keys&lt;/P&gt;</description>
      <pubDate>Thu, 21 Sep 2017 10:00:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-am-I-getting-the-following-error-after-updating-from-6-6-0/m-p/343503#M165992</guid>
      <dc:creator>gregbo</dc:creator>
      <dc:date>2017-09-21T10:00:11Z</dc:date>
    </item>
    <item>
      <title>Re: Why am I getting the following error after updating from 6.6.0 to 6.6.3: Invalid key in stanza [auditTrail] in /opt/splunk/etc/system/local/audit.conf</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-am-I-getting-the-following-error-after-updating-from-6-6-0/m-p/343504#M165993</link>
      <description>&lt;P&gt;After our upgrade to 6.6.5 from 6.4.3, I am seeing the same error. Do you know more how to fix this? Thanks.&lt;/P&gt;</description>
      <pubDate>Wed, 17 Jan 2018 20:42:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-am-I-getting-the-following-error-after-updating-from-6-6-0/m-p/343504#M165993</guid>
      <dc:creator>lqiao</dc:creator>
      <dc:date>2018-01-17T20:42:33Z</dc:date>
    </item>
    <item>
      <title>Re: Why am I getting the following error after updating from 6.6.0 to 6.6.3: Invalid key in stanza [auditTrail] in /opt/splunk/etc/system/local/audit.conf</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-am-I-getting-the-following-error-after-updating-from-6-6-0/m-p/343505#M165994</link>
      <description>&lt;P&gt;"Block signing" was removed in 6.3 when it was replaced by "data integrity".&lt;/P&gt;

&lt;P&gt;Even though you may have had config in your audit.conf for keys, I don't think this has been doing anything at all since 6.3.&lt;BR /&gt;
It looks like they tidied up the superfluous config between the versions you mention, so on the face of it, the solution is simply to remove those configurations because they have not been used for a few years. &lt;/P&gt;

&lt;P&gt;Might be worth checking if you enabled DI following Splunk 6.3&lt;/P&gt;</description>
      <pubDate>Wed, 17 Jan 2018 21:27:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-am-I-getting-the-following-error-after-updating-from-6-6-0/m-p/343505#M165994</guid>
      <dc:creator>nickhills</dc:creator>
      <dc:date>2018-01-17T21:27:06Z</dc:date>
    </item>
  </channel>
</rss>

