Splunk Search

INDEXED_EXTRACTIONS error in splunkd.log

Path Finder

Can you please advise, what do I do if my Splunk complains often (every couple minutes) in splunkd.log in production environment about

07-06-2018 11:21:04.253 +0300 ERROR IndexedExtractionsConfig - Tried to set INDEXED_EXTRACTIONS but it already had a value! (was: 0, wanted: 😎

I have tried enabling debug logging level for IndexedExtractionsConfig, but got no details.
How can I locate and fix the problem?

0 Karma

Path Finder

Are our ufix events considered by server to be erroneously indicated as CSV type? Is it a problem caused by unquoted space chars or something?

Sample ufix event:
"/opt/splunk/var/lib/splunk/xru/db/db15312179041531166719_2035/rawdata","journal.gz",10.07.18 13:18 ,453815577,0,6E09087F,3,-

Sample ufix_status event:
List creation: 0, prj creation: 0, report creation: 0

splunk/etc/apps/x/local/props.conf:

[ufix]
DATETIMECONFIG = CURRENT
FIELD
NAMES = directory, filename, date, bytelength, linelength, crc, crctype, idcrc
INDEXEDEXTRACTIONS = csv
KV
MODE = none
NOBINARYCHECK = true
SHOULDLINEMERGE = false
category = Structured
description = CSV-report by ФИКС-Unix
disabled = false
pulldown
type = true

[ufixstatus]
category = Structured
pulldown
type = 1
EXTRACT-liststatus = List creation: (?\d*), prj
EXTRACT-prj
status = prj creation: (?\d),
EXTRACT-report_status = report creation: (?\d
)
DATETIMECONFIG = CURRENT
FIELD
NAMES = directory, filename, modifydate, bytelength, linelength, crc, crctype, idcrc
INDEXED
EXTRACTIONS = csv
KVMODE = none
NO
BINARYCHECK = true
SHOULD
LINEMERGE = false
description = Comma-separated value format. Set header and other settings in "Delimited Settings"
disabled = false

0 Karma

Path Finder

Checked that INDEXED_EXTRACTIONS setting is not being redefined several times in any configs.

There are no INDEXEDEXTRACTIONS settings in our server config except for ufix, ufixstatus and default config files (unchanged).

ufix and ufix_status events are generated every morning, the should not be causing the minutely error messages.

0 Karma

Path Finder

I am fixing a production Splunk with lots of inputs and users, so I cannot just 'start over' a fresh server and find out when the error would reappear again.
Please advise.
How can I track down the input causing the error?
How can I know what is the impact of the error?
What is the best practice to fix it in a proper way?
What is the meaning of this error at all?

0 Karma

Ultra Champion

I see the exact same error at -

alt text

But I can't reach this page from Latest Questions on Splunk Answers

0 Karma