Any ideas what this warning is telling me?
message from "python /opt/splunk/etc/apps/Splunk_TA_vmware/bin/ta_vmware_collection_scheduler.py" WARNING:splunk.rest.format:There was an error parsing the feed document. Error: Input is not proper UTF-8, indicate encoding
these messages are coming from my indexer not my search head.
PS installed the APP and copied all the VMWare TA's to the indexers. I guess that is right but why would the Collection Scheduler be running on the indexer and should I turn it off?
I read throu the documentation and found this link
This link told me that the TA above is supposed to be on the indexer but other components should not be loaded on the indexer.
I will remove the components that should not be on the indexers and see if that solves the problem
The scheduler aspects of the splunk vmware app should be installed on search head which is dedicated to farming out those jobs. There is no reason that these components should be installed on the indexers unless your indexer is also serving as a scheduler (this would not be advised)?
For more detail about these processes see here
Can you help or someone else. I read thru the linked document and I don't think I am having problem with the scheduler only were the scheduler is running from.
In the VMware installation documents it is not so clear to me what parts are put on the search head and what pars are put on the indexers. since all parts are on both indexer and search head it may be that the scheduler is trying to run from the indexer and causing the error message above. I am not sure if I can just delete the scheduler part OR disable the scheduler part.
Is there cleaqr direction anywhere that I have not found that shows what parts of VMWare should be installed on the Searchhead, DCN, Indexer, license manager and Deployment Server.
Splunk has become very expandable but we are no-longer on one Splunk Enterprise System and things should be split up so different jobs are done on different systems.