Hello. I am on my Enterprise Security Search head and this is the output from the subject command (Minus the Checking lines):
No spec file for: /opt/splunk/etc/users/212040597/DA-ESS-IdentityManagement/local/asset_investigator_1_prefs.conf
No spec file for: /opt/splunk/etc/users/212040597/splunk_app_db_connect/local/dbx-ui-conn-prefs.conf
No spec file for: /opt/splunk/etc/users/212040597/splunk_app_db_connect/local/dbx-ui-prefs.conf
No spec file for: /opt/splunk/etc/users/abrittingham/DA-ESS-IdentityManagement/local/asset_investigator_1_prefs.conf
No spec file for: /opt/splunk/etc/users/abrittingham/splunk_app_for_nix/local/nix_view_prefs.conf
No spec file for: /opt/splunk/etc/users/admin/DA-ESS-IdentityManagement/local/asset_investigator_1_prefs.conf
No spec file for: /opt/splunk/etc/users/admin/splunk_app_db_connect/local/dbx-ui-conn-prefs.conf
No spec file for: /opt/splunk/etc/users/admin/splunk_app_db_connect/local/dbx-ui-prefs.conf
No spec file for: /opt/splunk/etc/users/admin/splunk_app_for_nix/local/nix_view_prefs.conf
No spec file for: /opt/splunk/etc/users/rkrishnanandam/DA-ESS-IdentityManagement/local/asset_investigator_1_prefs.conf
No spec file for: /opt/splunk/etc/apps/search/local/poolhealth.conf
No spec file for: /opt/splunk/etc/apps/DA-ESS-AccessProtection/default/eventgen.conf
No spec file for: /opt/splunk/etc/apps/DA-ESS-NetworkProtection/default/eventgen.conf
No spec file for: /opt/splunk/etc/apps/DA-ESS-ThreatIntelligence/default/eventgen.conf
No spec file for: /opt/splunk/etc/apps/SA-AuditAndDataProtection/default/eventgen.conf
No spec file for: /opt/splunk/etc/apps/SA-IdentityManagement/default/eventgen.conf
No spec file for: /opt/splunk/etc/apps/SA-NetworkProtection/default/eventgen.conf
No spec file for: /opt/splunk/etc/apps/SA-ThreatIntelligence/default/eventgen.conf
No spec file for: /opt/splunk/etc/apps/SA-nix/default/alert_overlay.conf
No spec file for: /opt/splunk/etc/apps/SplunkEnterpriseSecuritySuite/default/api.conf
No spec file for: /opt/splunk/etc/apps/Splunk_TA_bro/default/eventgen.conf
No spec file for: /opt/splunk/etc/apps/Splunk_TA_flowfix/default/eventgen.conf
No spec file for: /opt/splunk/etc/apps/Splunk_TA_mcafee/default/eventgen.conf
No spec file for: /opt/splunk/etc/apps/Splunk_TA_nessus/default/eventgen.conf
No spec file for: /opt/splunk/etc/apps/Splunk_TA_nix/default/eventgen.conf
No spec file for: /opt/splunk/etc/apps/Splunk_TA_oracle/default/database.conf
No spec file for: /opt/splunk/etc/apps/Splunk_TA_oracle/default/eventgen.conf
No spec file for: /opt/splunk/etc/apps/Splunk_TA_sophos/default/eventgen.conf
No spec file for: /opt/splunk/etc/apps/Splunk_TA_sourcefire/default/eventgen.conf
No spec file for: /opt/splunk/etc/apps/Splunk_TA_tomcat/default/eventgen.conf
No spec file for: /opt/splunk/etc/apps/Splunk_TA_tomcat/default/jmx_templates.conf
No spec file for: /opt/splunk/etc/apps/Splunk_TA_tomcat/default/tomcat_server.conf
No spec file for: /opt/splunk/etc/apps/Splunk_TA_windows/default/admon.conf
No spec file for: /opt/splunk/etc/apps/Splunk_TA_windows/default/eventgen.conf
No spec file for: /opt/splunk/etc/apps/Splunk_TA_windows/default/perfmon.conf
No spec file for: /opt/splunk/etc/apps/Splunk_TA_windows/default/regmon-filters.conf
No spec file for: /opt/splunk/etc/apps/TA-Azure/default/azure_insights.conf
Invalid key in stanza [AzureAudit] in /opt/splunk/etc/apps/TA-Azure/default/inputs.conf, line 12: api_version (value: 2014-04-01)
No spec file for: /opt/splunk/etc/apps/TA-airdefense/default/eventgen.conf
No spec file for: /opt/splunk/etc/apps/TA-alcatel/default/eventgen.conf
No spec file for: /opt/splunk/etc/apps/TA-bluecoat/default/eventgen.conf
No spec file for: /opt/splunk/etc/apps/TA-fireeye/default/eventgen.conf
No spec file for: /opt/splunk/etc/apps/TA-fortinet/default/eventgen.conf
No spec file for: /opt/splunk/etc/apps/TA-juniper/default/eventgen.conf
No spec file for: /opt/splunk/etc/apps/TA-nmap/default/eventgen.conf
No spec file for: /opt/splunk/etc/apps/TA-ossec/default/eventgen.conf
No spec file for: /opt/splunk/etc/apps/TA-sav/default/eventgen.conf
No spec file for: /opt/splunk/etc/apps/TA-sep/default/eventgen.conf
No spec file for: /opt/splunk/etc/apps/TA-tippingpoint/default/eventgen.conf
No spec file for: /opt/splunk/etc/apps/TA-trendmicro/default/eventgen.conf
No spec file for: /opt/splunk/etc/apps/TA-websense/default/eventgen.conf
No spec file for: /opt/splunk/etc/apps/splunk_app_db_connect/default/dbx_logging.conf
No spec file for: /opt/splunk/etc/apps/splunk_app_db_connect/default/resourcepool.conf
No spec file for: /opt/splunk/etc/apps/splunk_app_db_connect/default/settings.conf
Invalid key in stanza [ui] in /opt/splunk/etc/apps/splunk_app_for_nix/default/app.conf, line 17: attribution_link (value: app.attributions)
No spec file for: /opt/splunk/etc/apps/splunk_app_for_nix/default/unix_setup.conf
No spec file for: /opt/splunk/etc/apps/splunk_management_console/default/logging.conf
No spec file for: /opt/splunk/etc/system/default/conf.conf
No spec file for: /opt/splunk/etc/system/default/prefs.conf
No spec file for: /opt/splunk/etc/system/local/migration.conf
Should I be concerned by any of it? Thanks!
You can ignore the warning for custom conf files likes dbx_logging, eventgen etc, as Splunk doesn't have their specification to validate the the configurations. FOr known conf files, like app.conf and inputs.conf, you should fix the warning (invalid key etc) to ensure your conf files are doing what you expect them to.
List of Splunk provided conf files is listed in the left side of this page
http://docs.splunk.com/Documentation/Splunk/6.4.1/Admin/Savedsearchesconf