Hello,
I am performing Splunk UF installation of version 8.0.5 and getting following error logged in error logs:
==> splunkd.log <==
08-23-2022 10:00:29.018 -0400 WARN TcpOutputProc - Pipeline data does not have indexKey. [_conf] = |||\n
08-23-2022 10:00:29.018 -0400 WARN TcpOutputProc - The event is missing source information. Event : no raw data
I am not sure what is this error means. I can see that sources defined in config files are sending logs to Splunk.
Could someone suggest how I can fix these errors to make sure no data lose there?