Hi,
I upgraded Splunk from 6.3.0 to 6.4.1. On restarting Splunk, I am getting below messages.
Checking filesystem compatibility... Done
*Checking conf files for problems...
Invalid value in stanza [header_nullq] in /opt/splunk/etc/apps/CCMS-TA-onprem-reporting/default/transforms.conf, line 4: (key: DEST_KEY, value: nullqueue)
*
Your indexes and inputs configurations are not internally consistent. For more information, run 'splunk btool check --debug'
cannot find non-empty stack=download-trial for pool=auto_generated_pool_download-trial, skipping
Done
// Content of my transforms.conf file
[header_nullq]
DEST_KEY = queue
REGEX = ^TimeStamp
FORMAT = nullqueue
Is it due to the upgrade? How to resolve this issue?
Can somebody please help here?
Thanks,
Jitendra
... View more