I'm trying to forward my summarized events from an indexer (machine1) to multiple indexers (machine2 and machine 3) and I'm seeing this error message at machine2 and machine3:
received event for unconfigured/disabled index='summary_forwarders' with source='source::All forwarders - regenerator summary index' host='host::machine1' sourcetype='sourcetype::stash'
I'm really sure that I'm not using summary_forwarders in any way.
Any idea why this happens?
You have a summary index search configured on machine1 that puts data into the index summary_forwarders that doesn't exist on machine2 or machine3. This is probably from the beta SplunkDeploymentMonitor app. Is it installed only on machine1?