Getting Data In

Windows Universal Forwarder - "received event for unconfigured/disabled index" warning message

jstockamp
Communicator

I'm trying to configure the Splunk Unviersal forwader on a windows box to forward windows event log messages to my splunk 4.2 indexer. I wanted to keep windows events in a separate index from my other linux logs, so I created a new index on the indexer for "windows_events" and made sure it was enabled. I then added "index = windows_events" to each of my sections in the inputs.conf file in "C:\Program Files\SplunkUniversalForwarder\etc\apps\MSICreated\local" on my forwarder.

I'm getting events into my windows_events index, but I'm also seeing this warning at the top of my search screen

received event for unconfigured/disabled index='"windows_events"' with source='source::WinEventLog:Security' host='host::DC001' sourcetype='sourcetype::WinEventLog:Security' (1 missing total)

Any idea how to clear this warning message?

  • Jeff
Tags (1)
0 Karma

jstockamp
Communicator

I had created the index via SplunkWeb manager. This issues seems to have resolved itself after restarting splunk about 3 times and waiting a few hours.

0 Karma

MarioM
Motivator

how did you create your index?via the UI?via the indexes.conf?

do you have more than 1 indexer? if yes did you create the index on all of the indexer?

0 Karma
Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...