Getting Data In

Why am I getting indexer error "EAIOutParameters - invalid entry title in toAtom(): INDEXER_MISSING_INDEX-\x00\x00j\x00fre"?

Communicator

I have the following error message appearing every ~3 seconds. My searches have not yielded anyone who has this issue. Anyone come across it?

ERROR EAIOutParameters - invalid entry title in toAtom(): INDEXER_MISSING_INDEX-\x00\x00j\x00fre

My thoughts are that I have a bad data source coming in, which is somehow telling Splunk that it needs to be deposited into an index called \x00\x00j\x00fre - although trying to find it isn't too easy!

1 Solution

Splunk Employee
Splunk Employee

I was having this same issue. Removed splunkaddon_nix from the SH's (SA-Nix from indexers as well), and this error disappeared.

View solution in original post

Splunk Employee
Splunk Employee

I was having this same issue. Removed splunkaddon_nix from the SH's (SA-Nix from indexers as well), and this error disappeared.

View solution in original post

Communicator

I also had the add on enabled, I can't prove this was the cause as I no longer have access to the environment so as good an answer as we're going to get from @tlelle!

0 Karma

Splunk Employee
Splunk Employee

Happening to me at the moment as well. Strange error.

0 Karma

Builder

hi, did you find a solution for this problem. It is happening to me now

0 Karma

Communicator

Never found the solution, I believe it was something strange coming from a Universal Forwarder (A windows one) which fixed itself - I think it was for mis-configured index for Windows eventlog data as that happened to coincide (seems there was a bug in a older version of the UC for Windows which meant some eventlog data was forwarded despite no options being selected during installation).

Fixed itself so never investigated further.

0 Karma