Getting Data In

I am getting error from tailreader and file is not being auto indexed

katzr
Path Finder

I have a .csv that was dropped in an auto index folder and I am getting this error:

-0500 ERROR TailReader - Ignoring path="X" due to: Bug during applyPendingMetadata, header processor does not own the indexed extractions conf

I did not change my process (another file was dropped here this morning and it worked fine) and this file doesn't look any different- do you know why this is happening/how to fix?

Thank you!

0 Karma

mayurr98
Super Champion

hey
Have you configured anything that is use for extraction in props.conf?
you have to remove the extraction from your props.conf on your forwarder. Universal Forwarders cannot extract fields (they can only filter events). To extract fields with a forwarder you would need a heavy forwarder.
have a look at this answers
https://answers.splunk.com/answers/387158/bug-during-applypendingmetadata-header-processor-d.html
https://answers.splunk.com/answers/489579/error-bug-during-applypendingmetadata-header-proce.html

let me know if this helps!

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas

    Thursday, June 25, 2026  |  11AM PDT / 2PM EDT  Duration: 1 Hour (Includes live Q&A) Register to ...

Analytics Workspace deprecation

As of Splunk Cloud Platform 10.4.2604 and Splunk Enterprise 10.4, Analytics Workspace is now deprecated. ...

Splunk Developer Day Recap: Building, Publishing, and Growing on the Splunk Platform

Splunk Developer Day brought the Splunk developer community together for a practical look at what it means to ...