All Apps and Add-ons

Field Extractor and non-default indicies

eegilbert
Explorer

Hello,

I'm using the 2.1 version of the Field Extractor app and it doesn't appear to like non-default indexes:

Unable to initialize workflow
information: Ignoring unknown index
'indexname')

Stacktrace: Traceback (most recent
call last): File "", line 397,
in initInfoFromWorkflow File
"", line 494, in
setCurrentIndex ModelException:
Ignoring unknown index 'indexname'

Please note indexname is my generic index name for this example.

1 Solution

carasso
Splunk Employee
Splunk Employee

I fixed the problem. Update the app to 2.3.

I just updated the Field Extractor app to work in distributed environments, so it works with indexes not on the search head.

 http://apps.splunk.com/app/494/

Let me know if you see any problems.

View solution in original post

0 Karma

carasso
Splunk Employee
Splunk Employee

I fixed the problem. Update the app to 2.3.

I just updated the Field Extractor app to work in distributed environments, so it works with indexes not on the search head.

 http://apps.splunk.com/app/494/

Let me know if you see any problems.

0 Karma

scsr_1
New Member

My network data has its own index and I am receiving the same error.

Unable to initialize workflow information: Ignoring unknown index 'index_name')

I checked with our Splunk Admin and he said the permissions are correct.

0 Karma

carasso
Splunk Employee
Splunk Employee

Is it possible the user running the field extractor does not have permission to use that index?

0 Karma

eegilbert
Explorer

Hello, I did wonder about this, however I'm using splunk with admin level permissions. I've even tried setting the app for read/write for all as a test and still get the same result.

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...