Getting Data In

Why am I getting an error when backing up my heavy forwarder?

kdelvillar
Engager

I want to back up my HF so that I can upgrade to the new 7.2 version but I get these invalid errors:

Checking conf files for problems...

            Invalid key in stanza [aws:cloudwatch:metric] in /opt/splunk/etc/apps/Splunk_TA_aws/default/props.conf, line 242: METRIC-SCHEMA-TRANSFORMS  (value:  metric-schema:aws_cloudwatch_metric_schema).

            Invalid key in stanza [eval_aws_metric_name_prefix] in /opt/splunk/etc/apps/Splunk_TA_aws/default/transforms.conf, line 75: INGEST_EVAL  (value:  metric_name = Namespace.".".MetricName).

            Invalid key in stanza [metric-schema:aws_cloudwatch_metric_schema] in /opt/splunk/etc/apps/Splunk_TA_aws/default/transforms.conf, line 78: METRIC-SCHEMA-MEASURES  (value:  SampleCount,Average,Sum,Minimum,Maximum).

            Invalid key in stanza [Splunk_TA_f5_bigip_main] in /opt/splunk/etc/apps/Splunk_TA_f5-bigip/default/log_info.conf, line 3: level (value: INFO).

What's the problem and how can I fix this? Thanks

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Those are warnings, not errors, and can be ignored safely.

If you really want to fix them, you can try updating or re-installing the apps that generate them: Splunk_TA_aws and Splunk_TA_f5-bigip.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...