- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
splunk error message when launch splunk web
bwenge
Explorer
02-28-2011
07:45 AM
When I launch Splunk web interface,I get next message.How to fix it?
"received event for unconfigured/disabled index='_audit' with source='source::audittrail' host='host::myhostname' sourcetype='sourcetype::audittrail'.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Ron_Naken

Splunk Employee
02-28-2011
08:05 AM
Click Manager-->Indexes, then "Enable" the _audit index. It should then be fixed when you restart Splunk.
