Splunk Search

Bug during applyPendingMetadata, header processor does not own the indexed extractions confs

sandipan11
Path Finder

I am getting "Bug during applyPendingMetadata, header processor does not own the indexed extractions confs" so every file I am trying to ingest is ignoring. I am using Universal Forwarder to ingest data.

03-29-2016 22:22:27.818 -0700 ERROR TailingProcessor - Ignoring path="/opt/apps/splunk_data/uf2/data/bandy.txt" due to: Bug during applyPendingMetadata, header processor does not own the indexed extractions confs.

Can any one have solution for this?

abhinav_maxonic
Path Finder

I am also getting this error for my csv files. Splunk is not indexing some of csv files. All for them are 117KB in size. I am creating the CSV on linux using command -

ssh admin@machine1 "some command" > /opt/script_output_data/folder1/folder2/file_name_`date +\%m\%d\%Y_\%H_\%M_\%S`.csv

Error : 01-15-2017 21:40:22.148 -0800 ERROR TailReader - Ignoring path="/opt/script_output_data/folder1/folder2/file_name_01152017_21_40_18.csv" due to: Bug during applyPendingMetadata, header processor does not own the indexed extractions confs.

I have my props.conf on indexer as well as my forwarder.

0 Karma

hmatthews_splun
Splunk Employee
Splunk Employee

I realise this question is a few months old but hopefully the following will help!

Check your props.conf on the universal forwarder - it could be caused by INDEXED_EXCTRACTIONS=<x>. I had the same recently and narrowed it down to INDEXED_EXCTRACTIONS=<x>.

You'll need the configuration on the indexers, but not on the universal forwarder.

0 Karma

Paolo_Prigione
Builder

INDEXED_EXTRACTIONS are an exception in that the parsing/field extraction is performed on the UF instead of the HWF/IDX.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

How much can you really learn in 3 minutes?

Observability can certainly be hard to understand – there's a lot of jargon and buzzwords and it seems to ...

Event Series: The Agentic SOC: Trust Before Autonomy

AI is fundamentally changing security operations, but true progress requires more than just automation—it ...

Free Professional Services for .conf26 Attendees

This year at .conf26, we are doing something a little different. We are bringing the best minds from ...