All Apps and Add-ons

Splunk App for Windows Infrastructure: After upgrading to Splunk 6.3.3, why am I getting "Your indexes and inputs configurations are not internally consistent"?

swasserroth
Path Finder

Hi,

After upgrading to Splunk 6.3.3, the following problem is displayed when starting Splunk:

Checking conf files for problems...
            Invalid key in stanza [ui] in /opt/splunk/etc/apps/splunk_app_windows_infrastructure/default/app.conf, line 15: attribution_link  (value:  app.attributions).
            Your indexes and inputs configurations are not internally consistent. For more information, run 'splunk btool check --debug'

Does anybody know how to solve the problem?
Thanks!

1 Solution

swasserroth
Path Finder

See last comment of jwelch_splunk: Issue has been confirmed, warning should be ignored
This closes the issue -- Thank you!

View solution in original post

0 Karma

swasserroth
Path Finder

See last comment of jwelch_splunk: Issue has been confirmed, warning should be ignored
This closes the issue -- Thank you!

0 Karma

jwelch_splunk
Splunk Employee
Splunk Employee

When splunk starts.... It compares the app.conf file against app.conf.spec files. It would seem that you have a key under the [UI] stanza in the app.conf that is not listed as a valid key under the [UI] stanza in the app.conf.spec file.

So from /opt/splunk/etc/

find . -name app.conf.spec |xargs grep app.attributions OR however you would do this in windows.....

If you don't see that Key in any app.conf.spec file then you will get this error upon startup.

I am looking into this to see what I can find out. I will post back when I understand which bit was missed, but from the initial look it seems we are missing a part of the app.conf.spec file. I will file a bug and let you know the outcome.

0 Karma

jwelch_splunk
Splunk Employee
Splunk Employee

This issue has been confirmed, the warnings are expected and we will document this as a known issue. The app.conf.spec is scheduled to be addressed in a future release.

You can safely ignore the warning at present.

0 Karma

mattspierce
Explorer

I am also getting this error. In my case both the app for nix and app for windows are generating it.

Invalid key in stanza [ui] in /opt/splunk/etc/apps/splunk_app_for_nix/default/app.conf, line 18: attribution_link (value: app.attributions).
Invalid key in stanza [ui] in /opt/splunk/etc/apps/splunk_app_windows_infrastructure/default/app.conf, line 15: attribution_link (value: app.attributions).

0 Karma

srunyon
New Member

Same issue.

0 Karma

AlbintEIG
Engager

Same issue here.

0 Karma

dlpco
Path Finder

Did you get an answer offline about this. I have the same issue.

0 Karma

swasserroth
Path Finder

no answer yet 😞
problem still exists.

0 Karma
Get Updates on the Splunk Community!

Detecting Remote Code Executions With the Splunk Threat Research Team

WATCH NOWRemote code execution (RCE) vulnerabilities pose a significant risk to organizations. If exploited, ...

Enter the Splunk Community Dashboard Challenge for Your Chance to Win!

The Splunk Community Dashboard Challenge is underway! This is your chance to showcase your skills in creating ...

.conf24 | Session Scheduler is Live!!

.conf24 is happening June 11 - 14 in Las Vegas, and we are thrilled to announce that the conference catalog ...