Splunk Enterprise

splunk error message when launch splunk web

bwenge
Explorer

When I launch Splunk web interface,I get next message.How to fix it?

"received event for unconfigured/disabled index='_audit' with source='source::audittrail' host='host::myhostname' sourcetype='sourcetype::audittrail'.

Tags (1)
0 Karma

Ron_Naken
Splunk Employee
Splunk Employee

Click Manager-->Indexes, then "Enable" the _audit index. It should then be fixed when you restart Splunk.

0 Karma
Get Updates on the Splunk Community!

Pro Tips for First-Time .conf Attendees: Advice from SplunkTrust

Heading to your first .Conf? You’re in for an unforgettable ride — learning, networking, swag collecting, ...

Raise Your Skills at the .conf25 Builder Bar: Your Splunk Developer Destination

Calling all Splunk developers, custom SPL builders, dashboarders, and Splunkbase app creators – the Builder ...

Hunt Smarter, Not Harder: Discover New SPL “Recipes” in Our Threat Hunting Webinar

Are you ready to take your threat hunting skills to the next level? As Splunk community members, you know the ...