Archive

splunk error message when launch splunk web

Explorer

When I launch Splunk web interface,I get next message.How to fix it?

"received event for unconfigured/disabled index='_audit' with source='source::audittrail' host='host::myhostname' sourcetype='sourcetype::audittrail'.

Tags (1)
0 Karma

Splunk Employee
Splunk Employee

Click Manager-->Indexes, then "Enable" the _audit index. It should then be fixed when you restart Splunk.

0 Karma