Getting Data In

ERROR TailingProcessor - Ignoring path due to: This key could not be found : _MetaData:Index

FRoth
Contributor

I checked out the new Universal Forwarder and ran into some problems that I dont understand.
First I configured the forwarder by creating a "output.conf" and "input.conf" in /opt/splunkforwarder/etc/system/local.

The content of output.conf:

[tcpout:indexerNeo]

server=mapache.server.org:55515

The content of input.conf:

[monitor:///var/log/apache2/modsec_audit.log]

sourcetype=modsec

I got some errors in the splunkd.log that I dont understand:

05-03-2011 15:35:14.993 +0000 WARN TcpOutputProc - Pipeline data does not have indexKey. [_path] = /var/log/apache2/modsec_audit.log

[_startOffset] = 38875

[_fnameCrc] = 9536363811639999154

[_seekCrc] = 8646198035968417993

[_fishKey] = 15451249598830936081

[_modTime] = 1304436775

[_raw] =

[MetaData:Source] = source::/var/log/apache2/modsec_audit.log

[MetaData:Host] = host::s152188.onlinehome-server.info

[MetaData:Sourcetype] = sourcetype::modsec

[_done] = _done

[_hpn] = _hpn

[_conf] = source::/var/log/apache2/modsec_audit.log|host::s152188.onlinehome-server.info|modsec|

05-03-2011 15:35:16.714 +0000 ERROR TailingProcessor - Ignoring path due to: This key could not be   found : _MetaData:Index

Is there anybody who can help me?

0 Karma
1 Solution

FRoth
Contributor

Ok, I did it. I had to set an index to write the input to.

I added and index and then the line in "input.conf" file:

[monitor:///var/log/apache2/modsec_audit.log]

sourcetype=modsec

index=modsec

View solution in original post

FRoth
Contributor

Ok, I did it. I had to set an index to write the input to.

I added and index and then the line in "input.conf" file:

[monitor:///var/log/apache2/modsec_audit.log]

sourcetype=modsec

index=modsec

Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...