Monitoring Splunk

Why does Universal Forwarders complain about missing stanza [distributedSearch] in distsearch.conf?

vgrote
Path Finder

Running the Customer Success Toolkit's error report I noticed a warning on lots of Universal Forwarders that doesn't make sense to me:

19.01.23 10:49:53,614

01-19-2023 10:49:53.614 +0100 WARN UserManagerPro - Can't find [distributedSearch] stanza in distsearch.conf, using default authtoken HTTP timeouts

  • host = Unix Box
  • source = /opt/forwarder/data/var/log/splunk/splunkd.log
  • sourcetype = splunkd

19.01.23 10:33:28,659

01-19-2023 10:33:28.659 +0100 WARN UserManagerPro - Can't find [distributedSearch] stanza in distsearch.conf, using default authtoken HTTP timeouts

  • host = Windows Box
  • source = C:\Program Files\Splunk\UniversalForwarder\var\log\splunk\splunkd.log
  • sourcetype = splunkd

 

Our Universal Forwarders have no distsearch.conf.

Any idea why this is reported?

And how to turn it off? We already have enough noise in our data.

Thanks in advance

Volkmar

Labels (2)
Tags (1)
0 Karma

Mahadev_Nanda
Loves-to-Learn

Hi @vgrote ,

Have you checked this https://community.splunk.com/t5/Getting-Data-In/Unable-to-find-distsearch-conf-file-on-my-system-and.... I’m not 100 sure, but looks like it may help. 

Thank You

0 Karma

PaulPanther
Motivator

@vgrote It is a useless Warning for UniversalForwarder. As a workaround to get rid of these log messages you could roll out a distsearch.conf file that contains only the stanza

[distributedSearch]

 

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Unlock What’s Next: The Splunk Cloud Platform at .conf25

In just a few days, Boston will be buzzing as the Splunk team and thousands of community members come together ...