Splunk Enterprise

Fresh installation of Splunk UF 8.0.5 having error- How to resolve?

dhimanv
Loves-to-Learn Lots

Hello,

 

I am performing Splunk UF installation of version 8.0.5 and getting following error logged in error logs:

==> splunkd.log <==
08-23-2022 10:00:29.018 -0400 WARN TcpOutputProc - Pipeline data does not have indexKey. [_conf] = |||\n
08-23-2022 10:00:29.018 -0400 WARN TcpOutputProc - The event is missing source information. Event : no raw data

I am not sure what is this error means. I can see that sources defined in config files are sending logs to Splunk.

Could someone suggest how I can fix these errors to make sure no data lose there?

Labels (2)
Tags (1)
0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...