All Apps and Add-ons

Splunk App for Infrastructure

bogdan_nicolesc
Communicator

Hi guys,

I get this error message on Splunk App for Infrastructure:

Received event for unconfigured/disabled/deleted index=em_metrics with source="source::Perfmon:CPU" host="host::DSK0098" sourcetype="sourcetype::Perfmon:CPU". So far received events from 1 missing index(es).

Can anyone tell me why i get this and how can i correct it?

Thank you.

0 Karma
1 Solution

lakshman239
Influencer

The add-on/app installed and configured is sending logs/data to an index called "em_metrics", but that's not defined. Please create "index=em_metrics" if you haven't done so and the message will go away. [ if you are creating indexes via indexes.conf], you will need to restart the indexer.

View solution in original post

0 Karma

lakshman239
Influencer

The add-on/app installed and configured is sending logs/data to an index called "em_metrics", but that's not defined. Please create "index=em_metrics" if you haven't done so and the message will go away. [ if you are creating indexes via indexes.conf], you will need to restart the indexer.

0 Karma

bogdan_nicolesc
Communicator

Hi lakshman239,

This is the short answer.

The longer answer is the fact that i have overlooked the fact that i needed to install Splunk Add-on for Infrastructure.

Bogdan.

Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk on November 6 at 11AM PT, and empower your SOC to reach new heights! Duration: ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...