Getting Data In

Invalid key in stanza

Okezie1
Explorer

Invalid key in stanza [workday://user_activity] in /opt/splunk/etc/apps/TA-workday/local/inputs.conf, line 2: include_target (value: 0).

[workday://user_activity]
include_target = 0
index = workday
input_name = user_activity
interval = 300
include_target_details = 0

Need some help with this one trying to ingest logs from my Workday TA, logs stopped reporting.

Labels (1)
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

Check the docs in /opt/splunk/etc/apps/TA-workday/README/inputs.conf.spec to make sure you have the attribute name correct. 

---
If this reply helps you, Karma would be appreciated.

View solution in original post

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Check the docs in /opt/splunk/etc/apps/TA-workday/README/inputs.conf.spec to make sure you have the attribute name correct. 

---
If this reply helps you, Karma would be appreciated.
0 Karma

Okezie1
Explorer

Thanks I checked the doc, it turns out there were some duplicate Stanzas within the inputs.conf and my tasettings.conf. Thanks. 

0 Karma

richgalloway
SplunkTrust
SplunkTrust

If your problem is resolved, then please click the "Accept as Solution" button to help future readers.

---
If this reply helps you, Karma would be appreciated.
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...