I am getting an error when I restart splunk:
Invalid key in stanza [WinEventLog:Application] in /opt/splunk/etc/apps/Splunk_TA_windows/default/inputs.conf, line 16: start_from (value: oldest)
Invalid key in stanza [WinEventLog:Application] in /opt/splunk/etc/apps/Splunk_TA_windows/default/inputs.conf, line 17: current_only (value: 0)
Invalid key in stanza [WinEventLog:Application] in /opt/splunk/etc/apps/Splunk_TA_windows/default/inputs.conf, line 18: checkpointInterval (value: 5)
Invalid key in stanza [WinEventLog:Security] in /opt/splunk/etc/apps/Splunk_TA_windows/default/inputs.conf, line 22: start_from (value: oldest)
Invalid key in stanza [WinEventLog:Security] in /opt/splunk/etc/apps/Splunk_TA_windows/default/inputs.conf, line 23: current_only (value: 0)
Invalid key in stanza [WinEventLog:Security] in /opt/splunk/etc/apps/Splunk_TA_windows/default/inputs.conf, line 24: evt_resolve_ad_obj (value: 1)
Invalid key in stanza [WinEventLog:Security] in /opt/splunk/etc/apps/Splunk_TA_windows/default/inputs.conf, line 25: checkpointInterval (value: 5)
Invalid key in stanza [WinEventLog:System] in /opt/splunk/etc/apps/Splunk_TA_windows/default/inputs.conf, line 29: start_from (value: oldest)
Invalid key in stanza [WinEventLog:System] in /opt/splunk/etc/apps/Splunk_TA_windows/default/inputs.conf, line 30: current_only (value: 0)
Invalid key in stanza [WinEventLog:System] in /opt/splunk/etc/apps/Splunk_TA_windows/default/inputs.conf, line 31: checkpointInterval (value: 5)
I am not sure why I would be getting this error from the default folder. Is this expected, or is there a way to clean this up?
Thanks,
Casey
... View more