Splunk Enterprise

splunk error message when launch splunk web

bwenge
Explorer

When I launch Splunk web interface,I get next message.How to fix it?

"received event for unconfigured/disabled index='_audit' with source='source::audittrail' host='host::myhostname' sourcetype='sourcetype::audittrail'.

Tags (1)
0 Karma

Ron_Naken
Splunk Employee
Splunk Employee

Click Manager-->Indexes, then "Enable" the _audit index. It should then be fixed when you restart Splunk.

0 Karma
Get Updates on the Splunk Community!

Let’s Talk Terraform

If you’re beyond the first-weeks-of-a-startup stage, chances are your application’s architecture is pretty ...

Cloud Platform | Customer Change Announcement: Email Notification is Available For ...

The Notification Team is migrating our email service provider. As the rollout progresses, Splunk has enabled ...

Save the Date: GovSummit Returns Wednesday, December 11th!

Hey there, Splunk Community! Exciting news: Splunk’s GovSummit 2024 is returning to Washington, D.C. on ...