Splunk Search

WARN : Eventtype 'xxxxxxxx' does not exist or is disabled. Errors coming from indexers

pbrinkman
Path Finder

hi all,

I have had a number of scheduled searches that failed, all returning the same errors.

WARN : Eventtype 'xxxxxxxx' does not exist or is disabled.
WARN : [INDEXER 1] Eventtype 'xxxxxxxx' does not exist or is disabled.
WARN : [INDEXER 2] Eventtype 'xxxxxxxx' does not exist or is disabled.
WARN : [INDEXER 3] Eventtype 'xxxxxxxx' does not exist or is disabled.
WARN : [INDEXER 4] Eventtype 'xxxxxxxx' does not exist or is disabled.

Could someone explain why the indexers were returning the errors when all eventtypes are located on the search heads ?

cheers
Paul

Tags (1)
0 Karma

FrankVl
Ultra Champion

Search heads push a bundle of knowledge objects to the indexers, to enable the indexers to perform searches.

These errors are typically caused by a tag (in tags.conf) that refers to an eventtype that is not defined / disabled / in another app and not shared / not readable by current user.

0 Karma
Get Updates on the Splunk Community!

Splunk Search APIを使えば調査過程が残せます

   このゲストブログは、JCOM株式会社の情報セキュリティ本部・専任部長である渡辺慎太郎氏によって執筆されました。 Note: This article is published in both Japanese ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...