After upgrading to Splunk 6.3.3, the following problem is displayed when starting Splunk:
Checking conf files for problems... Invalid key in stanza [ui] in /opt/splunk/etc/apps/splunk_app_windows_infrastructure/default/app.conf, line 15: attribution_link (value: app.attributions). Your indexes and inputs configurations are not internally consistent. For more information, run 'splunk btool check --debug'
Does anybody know how to solve the problem?
When splunk starts.... It compares the app.conf file against app.conf.spec files. It would seem that you have a key under the [UI] stanza in the app.conf that is not listed as a valid key under the [UI] stanza in the app.conf.spec file.
So from /opt/splunk/etc/
find . -name app.conf.spec |xargs grep app.attributions OR however you would do this in windows.....
If you don't see that Key in any app.conf.spec file then you will get this error upon startup.
I am looking into this to see what I can find out. I will post back when I understand which bit was missed, but from the initial look it seems we are missing a part of the app.conf.spec file. I will file a bug and let you know the outcome.
This issue has been confirmed, the warnings are expected and we will document this as a known issue. The app.conf.spec is scheduled to be addressed in a future release.
You can safely ignore the warning at present.
I am also getting this error. In my case both the app for nix and app for windows are generating it.
Invalid key in stanza [ui] in /opt/splunk/etc/apps/splunkappfornix/default/app.conf, line 18: attributionlink (value: app.attributions).
Invalid key in stanza [ui] in /opt/splunk/etc/apps/splunkappwindowsinfrastructure/default/app.conf, line 15: attributionlink (value: app.attributions).