Splunk Enterprise

splunk error message when launch splunk web

bwenge
Explorer

When I launch Splunk web interface,I get next message.How to fix it?

"received event for unconfigured/disabled index='_audit' with source='source::audittrail' host='host::myhostname' sourcetype='sourcetype::audittrail'.

Tags (1)
0 Karma

Ron_Naken
Splunk Employee
Splunk Employee

Click Manager-->Indexes, then "Enable" the _audit index. It should then be fixed when you restart Splunk.

0 Karma
Get Updates on the Splunk Community!

Unlock New Opportunities with Splunk Education: Explore Our Latest Courses!

At Splunk Education, we’re dedicated to providing top-tier learning experiences that cater to every skill ...

Technical Workshop Series: Splunk Data Management and SPL2 | Register here!

Hey, Splunk Community! Ready to take your data management skills to the next level? Join us for a 3-part ...

Spotting Financial Fraud in the Haystack: A Guide to Behavioral Analytics with Splunk

In today's digital financial ecosystem, security teams face an unprecedented challenge. The sheer volume of ...