Deployment Architecture

I have an index created and the same index I named in inputs.conf but once I restart the forwarder it says the index is not configured ?

akumarsripathi
Observer

Search peer xxx(servername) has the following message: Received event for unconfigured/disabled/deleted index=\xC2\xA0my_data with source="source::/opt/mylogs/apache/logs/xxx.logs" host="host::servername" sourcetype="sourcetype::xxx.logs". So far received events from 1 missing index(es).

Above is the message banner which I see once I restart the forwarder. I created index name as my_data and I see other source is already loading to mentioned index.
These are apache tomcat logs.

Tags (1)
0 Karma

manjunathmeti
Champion

You index attribute contains special character in inputs.conf. Remove \xC2\xA0 in index=\xC2\xA0my_data in inputs.conf and restart forwarder.

0 Karma
Get Updates on the Splunk Community!

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

🔐 Trust at Every Hop: How mTLS in Splunk Enterprise 10.0 Makes Security Simpler

From Idea to Implementation: Why Splunk Built mTLS into Splunk Enterprise 10.0  mTLS wasn’t just a checkbox ...