Splunk Search

WARN : Eventtype 'xxxxxxxx' does not exist or is disabled. Errors coming from indexers

pbrinkman
Path Finder

hi all,

I have had a number of scheduled searches that failed, all returning the same errors.

WARN : Eventtype 'xxxxxxxx' does not exist or is disabled.
WARN : [INDEXER 1] Eventtype 'xxxxxxxx' does not exist or is disabled.
WARN : [INDEXER 2] Eventtype 'xxxxxxxx' does not exist or is disabled.
WARN : [INDEXER 3] Eventtype 'xxxxxxxx' does not exist or is disabled.
WARN : [INDEXER 4] Eventtype 'xxxxxxxx' does not exist or is disabled.

Could someone explain why the indexers were returning the errors when all eventtypes are located on the search heads ?

cheers
Paul

Tags (1)
0 Karma

FrankVl
Ultra Champion

Search heads push a bundle of knowledge objects to the indexers, to enable the indexers to perform searches.

These errors are typically caused by a tag (in tags.conf) that refers to an eventtype that is not defined / disabled / in another app and not shared / not readable by current user.

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...