Getting Data In

Why am I getting error message 'invalid key in stanza' after installing a universal forwarder?

New Member

Hi All,

When I installed the splunk universal forwarder on my linux server and restarted the splunk service, there run an error like below:'Invalid key in stanza [monitor:///tmp/nohup_1.out] in /opt/splunkforwarder/etc/system/local/inputs.conf, line 5: disable (value: 0)'. Was it a normal message? I need your help!

Thanks,
Henry

0 Karma
1 Solution

SplunkTrust
SplunkTrust

Hi ford1863,

change disable to disabled in inputs.conf monitor stanza.

hope this helps ...

cheers, MuS

View solution in original post

Legend

It is what it says - you have an invalid key in your inputs.conf. It's supposed to be "disabled", not "disable". On the other hand, the default for that value is 0 anyway, so it won't make a difference - the stanza should be applied anyway.

SplunkTrust
SplunkTrust

Hi ford1863,

change disable to disabled in inputs.conf monitor stanza.

hope this helps ...

cheers, MuS

View solution in original post