Splunk Enterprise

Fresh installation of Splunk UF 8.0.5 having error- How to resolve?

Loves-to-Learn Lots



I am performing Splunk UF installation of version 8.0.5 and getting following error logged in error logs:

==> splunkd.log <==
08-23-2022 10:00:29.018 -0400 WARN TcpOutputProc - Pipeline data does not have indexKey. [_conf] = |||\n
08-23-2022 10:00:29.018 -0400 WARN TcpOutputProc - The event is missing source information. Event : no raw data

I am not sure what is this error means. I can see that sources defined in config files are sending logs to Splunk.

Could someone suggest how I can fix these errors to make sure no data lose there?

Labels (2)
Tags (1)
0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to July and August Tech Talks, Office Hours, and Webinars!

Dive into our sizzling summer lineup for July and August Community Office Hours and Tech Talks. Scroll down to ...

Edge Processor Scaling, Energy & Manufacturing Use Cases, and More New Articles on ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Get More Out of Your Security Practice With a SIEM

Get More Out of Your Security Practice With a SIEMWednesday, July 31, 2024  |  11AM PT / 2PM ETREGISTER ...