All Apps and Add-ons

Why am I getting "Invalid key in stanza" errors for the Splunk Add-on for Microsoft Windows default configuration?

Explorer

I am getting an error when I restart splunk:

Invalid key in stanza [WinEventLog:Application] in /opt/splunk/etc/apps/Splunk_TA_windows/default/inputs.conf, line 16: start_from  (value:  oldest)
Invalid key in stanza [WinEventLog:Application] in /opt/splunk/etc/apps/Splunk_TA_windows/default/inputs.conf, line 17: current_only  (value:  0)
Invalid key in stanza [WinEventLog:Application] in /opt/splunk/etc/apps/Splunk_TA_windows/default/inputs.conf, line 18: checkpointInterval  (value:  5)
Invalid key in stanza [WinEventLog:Security] in /opt/splunk/etc/apps/Splunk_TA_windows/default/inputs.conf, line 22: start_from  (value:  oldest)
Invalid key in stanza [WinEventLog:Security] in /opt/splunk/etc/apps/Splunk_TA_windows/default/inputs.conf, line 23: current_only  (value:  0)
Invalid key in stanza [WinEventLog:Security] in /opt/splunk/etc/apps/Splunk_TA_windows/default/inputs.conf, line 24: evt_resolve_ad_obj  (value:  1)
Invalid key in stanza [WinEventLog:Security] in /opt/splunk/etc/apps/Splunk_TA_windows/default/inputs.conf, line 25: checkpointInterval  (value:  5)
Invalid key in stanza [WinEventLog:System] in /opt/splunk/etc/apps/Splunk_TA_windows/default/inputs.conf, line 29: start_from  (value:  oldest)
Invalid key in stanza [WinEventLog:System] in /opt/splunk/etc/apps/Splunk_TA_windows/default/inputs.conf, line 30: current_only  (value:  0)
Invalid key in stanza [WinEventLog:System] in /opt/splunk/etc/apps/Splunk_TA_windows/default/inputs.conf, line 31: checkpointInterval  (value:  5)

I am not sure why I would be getting this error from the default folder. Is this expected, or is there a way to clean this up?

Thanks,

Casey

0 Karma

Splunk Employee
Splunk Employee

This is caused by the License Monitor app -- uninstall it, and the problem will go away.

SplunkTrust
SplunkTrust

What version of splunk? What version of the add-on?

Explorer

we are running Splunk 6.2.2.

I am trying to find the SplunkTAwindows version, and while I can't find the version number, it is dated 8/27/2012, so an upgrade does appear to be in order.

While I have the Splunk Health overview installed on our deployment server, I do not have the License Monitor app installed.

0 Karma

Having the same issue and no license monitor app installed in the environment. Has anyone solved this?

What is interesting is these are flagging as invalid keys, but they do in fact work.