Hi, I just installed Splunk_TA_windows on my windows 2016 server. The server is running the splunk uf version 7.3.x and this is a new install. I am getting this error msg during startup of the Splunk UF and when I run the btool command 'C:\Program Files\splunkuniversalforwarder\bin\splunk.exe' btool check debug Checking: C:\Program Files\splunkuniversalforwarder\etc\apps\Splunk_TA_windows\default\transforms.conf Invalid key in stanza [user_account_control_property] in C:\Program Files\splunkuniversalforwarder\etc\apps\Splunk_TA_windows\default\transforms.conf, line 10: external_cmd (value: user_account_control_property.py user AccountControl userAccountPropertyFlag). Invalid key in stanza [user_account_control_property] in C:\Program Files\splunkuniversalforwarder\etc\apps\Splunk_TA_windows\default\transforms.conf, line 11: external_type (value: python). Invalid key in stanza [user_account_control_property] in C:\Program Files\splunkuniversalforwarder\etc\apps\Splunk_TA_windows\default\transforms.conf, line 12: fields_list (value: userAccountControl,userAccountProperty Flag). Invalid key in stanza [dhcp_discard_headers] in C:\Program Files\splunkuniversalforwarder\etc\apps\Splunk_TA_windows\default\transforms.conf, line 19: REGEX (value: ^(?:[^\d]+|\d+[^\d,])). Invalid key in stanza [dhcp_discard_headers] in C:\Program Files\splunkuniversalforwarder\etc\apps\Splunk_TA_windows\default\transforms.conf, line 20: DEST_KEY (value: queue). Invalid key in stanza [dhcp_discard_headers] in C:\Program Files\splunkuniversalforwarder\etc\apps\Splunk_TA_windows\default\transforms.conf, line 21: FORMAT (value: nullQueue). Invalid key in stanza [auto_kv_for_microsoft_dhcp] in C:\Program Files\splunkuniversalforwarder\etc\apps\Splunk_TA_windows\default\transforms.conf, line 24: DELIMS (value: ","). Invalid key in stanza [auto_kv_for_microsoft_dhcp] in C:\Program Files\splunkuniversalforwarder\etc\apps\Splunk_TA_windows\default\transforms.conf, line 25: FIELDS (value: msdhcp_id,date,time,description,ip,nt_host,mac ). Invalid key in stanza [msdhcp_signature_lookup] in C:\Program Files\splunkuniversalforwarder\etc\apps\Splunk_TA_windows\default\transforms.conf, line 28: filename (value: msdhcp_signatures.csv). <......SNIP ...> Invalid key in stanza [dns_recordclass_lookup] in C:\Program Files\splunkuniversalforwarder\etc\apps\Splunk_TA_windows\default\transforms.conf, line 1267: filename (value: dns_recordclass_lookup.csv). Invalid key in stanza [geo_us_states] in C:\Program Files\splunkuniversalforwarder\etc\apps\search\default\transforms.conf, line 2: external_type (value: geo). Invalid key in stanza [geo_us_states] in C:\Program Files\splunkuniversalforwarder\etc\apps\search\default\transforms.conf, line 3: filename (value: geo_us_states.kmz). Invalid key in stanza [geo_countries] in C:\Program Files\splunkuniversalforwarder\etc\apps\search\default\transforms.conf, line 6: external_type (value: geo). Invalid key in stanza [geo_countries] in C:\Program Files\splunkuniversalforwarder\etc\apps\search\default\transforms.conf, line 7: filename (value: geo_countries.kmz). Invalid key in stanza [geo_attr_us_states] in C:\Program Files\splunkuniversalforwarder\etc\apps\search\default\transforms.conf, line 10: filename (value: geo_attr_us_states.csv). Invalid key in stanza [geo_attr_countries] in C:\Program Files\splunkuniversalforwarder\etc\apps\search\default\transforms.conf, line 13: filename (value: geo_attr_countries.csv). Invalid key in stanza [geo_hex] in C:\Program Files\splunkuniversalforwarder\etc\apps\search\default\transforms.conf, line 16: external_type (value: geo_hex). Looks like there's a syntax error on every line in de default transforms.conf file. Upgraded from Splunk UF 7.3.3 to Splunk UF 7.3.9 - same problem. This is a default Splunk UF install. No other application is deployed to this UF.
... View more