I am getting below error message when I am trying to create new index 'introspection'.
In handler 'indexes': invalid name: 'introspection'. name parameter must be non-empty and cannot start with '_' or '-'
We have recently upgraded our heavy weight forwarder and indexer is still running an older version.After HWF upgarded we received few warning messages in GUI like "received event for unconfigured/disabled/deletd index index="_introspection".Now splunk not allowing to create index _introspection.How can I resolve this?Please advise
See if you can create it via a local indexes.conf edit and not via the gui.
This is what it looks like in newer versions.
homePath = $SPLUNKDB/introspection/db
coldPath = $SPLUNKDB/introspection/colddb
thawedPath = $SPLUNKDB/_introspection/thaweddb
maxDataSize = 1024
frozenTimePeriodInSecs = 1209600
I am sure I did exactly this on some older indexers when customers updated their forwarders before we upgraded our own machines.
See if this helps.
Keep in mind you can't manually create new indexes that start with
_ because that is reserved for Splunk internal ones. Internal indexes don't count towards the license so it's easy to guess why this is not permitted 🙂