I have the following error message appearing every ~3 seconds. My searches have not yielded anyone who has this issue. Anyone come across it?
ERROR EAIOutParameters - invalid entry title in toAtom(): INDEXER_MISSING_INDEX-\x00\x00j\x00fre
My thoughts are that I have a bad data source coming in, which is somehow telling Splunk that it needs to be deposited into an index called
\x00\x00j\x00fre - although trying to find it isn't too easy!
I also had the add on enabled, I can't prove this was the cause as I no longer have access to the environment so as good an answer as we're going to get from @tlelle!
Never found the solution, I believe it was something strange coming from a Universal Forwarder (A windows one) which fixed itself - I think it was for mis-configured index for Windows eventlog data as that happened to coincide (seems there was a bug in a older version of the UC for Windows which meant some eventlog data was forwarded despite no options being selected during installation).
Fixed itself so never investigated further.