Hi All, Currently we have moved from older splunk version to latest version, but when we reboot the splunk services, we found it is throwing some invalid key stanza details, but not sure what exactly we need to do to fix this issue.
Checking conf files for problems...
Invalid key in stanza [serverClass:Allsearchheads] in /opt/splunk/etc/apps/search/local/serverclass.conf, line 34: targetRepositoryLocation (value: "/splunksearchpool/etc/apps").
Invalid key in stanza [tcpout:allindexers] in /opt/splunk/etc/apps/Allfwd_outputs/default/outputs.conf, line 7: autoLB (value: true).
Invalid key in stanza [sysactivated] in /opt/splunk/etc/apps/security/default/eventtypes.conf, line 2: index (value: nfw sourcetype=syslog "Input/CMD1" OR edsnotifier activated OR fwrules/active).
Invalid key in stanza [email] in /opt/splunk/etc/system/local/alertactions.conf, line 5: reportServerEnabled (value: 0).
Invalid key in stanza [email] in /opt/splunk/etc/system/local/alertactions.conf, line 6: reportServerURL (value: ).
Kindly guide me how to fix the issue.
The Invalid Key error means that key in the stanza is not recognised by splunk as belonging in that conf file. Its possible your old config files contain removed keys - check the relevant documentation in previous versions to see what they have been replaced with. (Usually when the keys are deprecated Splunk will indicate in the docs what they have been replaced with)
Also check that there are no typos in the keys!
Hi jplumsdaine, thanks for your effort on this, Yes I had removed the stanza that was showing the Invalid Key error. After deleting the stanza from the configuration files and bounced the splunk service and found no errors were popping out.
As far as the autoLB error is concerned, "autoLB=true" setting is invalid from splunk 6.6. As autoLB is only configured as true (you can't make it false), no need to mention the setting explicitly from Splunk 6.6 and autolb is by default enabled.