I'm seeing the error below under messages in my Splunk enterprise console:
Missing or malformed messages.conf stanza for TCPOUT:FORWARDING_BLOCKED_Indexer IP ADDress_default-autolb-group DC-Host N...
...ntentions tries to use them to circumvent role-basedfieldfiltering. As a result, theSplunkplatform restricts these commands when used by people withroles that are configured withfieldfiltering.
...essionManager - auth tokens will be generated with shpooling shared secret
09-25-2018 06:17:18.378 INFO UserManager - Setting user context: splunk-system-user
09-25-2018 06:17:18.378 INFO UserManager - Done setting...