After I removed those lines, when validating the cluster bundle for our index cluster, I received these errors:
`[Not Critical] Invalid key in stanza [threatlist://minemeld_ipv4threatlist] in D:\Splunk\etc\master-apps\Splunk_TA_paloalto\default\inputs.conf, line 23: description (value: MineMeld IPv4 threatlist indicators for Splunk ES).
[Not Critical] Invalid key in stanza [threatlist://minemeld_ipv4threatlist] in D:\Splunk\etc\master-apps\Splunk_TA_paloalto\default\inputs.conf, line 26: type (value: threatlist).
[Not Critical] Invalid key in stanza [threatlist://minemeld_ipv4threatlist] in D:\Splunk\etc\master-apps\Splunk_TA_paloalto\default\inputs.conf, line 27: url (value: lookup://minemeld_ipv4threatlist).
[Not Critical] Invalid key in stanza [threatlist://minemeld_domainthreatlist] in D:\Splunk\etc\master-apps\Splunk_TA_paloalto\default\inputs.conf, line 30: description (value: MineMeld Domain threatlist indicators for Splunk ES).
[Not Critical] Invalid key in stanza [threatlist://minemeld_domainthreatlist] in D:\Splunk\etc\master-apps\Splunk_TA_paloalto\default\inputs.conf, line 33: type (value: threatlist).
[Not Critical] Invalid key in stanza [threatlist://minemeld_domainthreatlist] in D:\Splunk\etc\master-apps\Splunk_TA_paloalto\default\inputs.conf, line 34: url (value: lookup://minemeld_domainthreatlist).
[Not Critical] Invalid key in stanza [threatlist://minemeld_urlthreatlist] in D:\Splunk\etc\master-apps\Splunk_TA_paloalto\default\inputs.conf, line 37: description (value: MineMeld URL threatlist indicators for Splunk ES).
[Not Critical] Invalid key in stanza [threatlist://minemeld_urlthreatlist] in D:\Splunk\etc\master-apps\Splunk_TA_paloalto\default\inputs.conf, line 40: type (value: threatlist).
[Not Critical] Invalid key in stanza [threatlist://minemeld_urlthreatlist] in D:\Splunk\etc\master-apps\Splunk_TA_paloalto\default\inputs.conf, line 41: url (value: lookup://minemeld_urlthreatlist).
[Not Critical] Invalid key in stanza [threatlist://minemeld_filethreatlist] in D:\Splunk\etc\master-apps\Splunk_TA_paloalto\default\inputs.conf, line 44: description (value: MineMeld file threatlist indicators for Splunk ES).
[Not Critical] Invalid key in stanza [threatlist://minemeld_filethreatlist] in D:\Splunk\etc\master-apps\Splunk_TA_paloalto\default\inputs.conf, line 47: type (value: threatlist).
[Not Critical] Invalid key in stanza [threatlist://minemeld_filethreatlist] in D:\Splunk\etc\master-apps\Splunk_TA_paloalto\default\inputs.conf, line 48: url (value: lookup://minemeld_filethreatlist).`
After commenting out everything in the "MildMeld Inputs" section of the Splunk_TA_paloalto/default/inputs.conf file, the validation was successful.
(We're not using any of that functionality)
... View more