Splunk Enterprise

received event for unconfigured/disabled index=_audit

heterodyned
Path Finder

Currently, I have enabled splunk forwarder on a particular windows box with SSL encryption to the indexer. ( Although this may not be actually the source of the issue)

I am receiving events for unconfigured/disabled index='_audit' on the forwader for some reason. I did verify that all the indexes in the forwarder are enabled, and the same holds true for the receiver

Any idea what could be the source of the issue?

Tags (1)
0 Karma
1 Solution

jbsplunk
Splunk Employee
Splunk Employee

This is a defect in 4.1.x, the message happens when you restart a LWF. I have been able to replicate the issue. It has been reported to support and is being investigated by engineering. This has been added to the known issues document, see SPL-37337:

http://www.splunk.com/base/Documentation/4.1.7/ReleaseNotes/Knownissues

View solution in original post

jbsplunk
Splunk Employee
Splunk Employee

This is a defect in 4.1.x, the message happens when you restart a LWF. I have been able to replicate the issue. It has been reported to support and is being investigated by engineering. This has been added to the known issues document, see SPL-37337:

http://www.splunk.com/base/Documentation/4.1.7/ReleaseNotes/Knownissues

heterodyned
Path Finder

I could fix this issue, the windows forwarder was actually configured as LightForwarder and was still operating in LightForwarder Mode, ( this was done by someone previously) and at the sametime I was using the SplunkWebUI for this particular server, which was causing these events.

Solution: I disabled splunk-light forwarder and enabled forwarder mode, the issue got resolved

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...