We just completed upgrading to 4.2.1.
But now, in our console, we keep getting error messages such as the following:
received event for unconfigured/disabled index='sample' with source='source::/opt/splunk/etc/apps/sample_app/logs/maillog' host='host::ip-10-250-39-210' sourcetype='sourcetype::sendmail' (1 missing total)
Any ideas?
jcbrendsel,
The "sample_app"
app ships with Splunk and is told to index the following by default:
## inputs.conf
[monitor://$SPLUNK_HOME/etc/apps/sample_app/logs]
index=sample
sourcetype=sendmail
The error is likely caused by the disablement of the sample index that also ships with this app. I would recommend disabling the "sample_app"
altogether, or re-enabling this index.