Splunk Enterprise

Kept receiving error message at indexer

Nicholas_Key
Splunk Employee
Splunk Employee

Hi all,

I'm trying to forward my summarized events from an indexer (machine1) to multiple indexers (machine2 and machine 3) and I'm seeing this error message at machine2 and machine3:

received event for unconfigured/disabled index='summary_forwarders' with source='source::All forwarders - regenerator summary index' host='host::machine1' sourcetype='sourcetype::stash'

I'm really sure that I'm not using summary_forwarders in any way.

Any idea why this happens?

Tags (1)
0 Karma

Stephen_Sorkin
Splunk Employee
Splunk Employee

You have a summary index search configured on machine1 that puts data into the index summary_forwarders that doesn't exist on machine2 or machine3. This is probably from the beta SplunkDeploymentMonitor app. Is it installed only on machine1?

Get Updates on the Splunk Community!

Technical Workshop Series: Splunk Data Management and SPL2 | Register here!

Hey, Splunk Community! Ready to take your data management skills to the next level? Join us for a 3-part ...

Spotting Financial Fraud in the Haystack: A Guide to Behavioral Analytics with Splunk

In today's digital financial ecosystem, security teams face an unprecedented challenge. The sheer volume of ...

Solve Problems Faster with New, Smarter AI and Integrations in Splunk Observability

Solve Problems Faster with New, Smarter AI and Integrations in Splunk Observability As businesses scale ...