Deployment Architecture

I have an index created and the same index I named in inputs.conf but once I restart the forwarder it says the index is not configured ?

akumarsripathi
New Member

Search peer xxx(servername) has the following message: Received event for unconfigured/disabled/deleted index=\xC2\xA0my_data with source="source::/opt/mylogs/apache/logs/xxx.logs" host="host::servername" sourcetype="sourcetype::xxx.logs". So far received events from 1 missing index(es).

Above is the message banner which I see once I restart the forwarder. I created index name as my_data and I see other source is already loading to mentioned index.
These are apache tomcat logs.

Tags (1)
0 Karma

manjunathmeti
SplunkTrust
SplunkTrust

You index attribute contains special character in inputs.conf. Remove \xC2\xA0 in index=\xC2\xA0my_data in inputs.conf and restart forwarder.

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

Splunk is officially part of Cisco

Revolutionizing how our customers build resilience across their entire digital footprint.   Splunk ...

Splunk APM & RUM | Planned Maintenance March 26 - March 28, 2024

There will be planned maintenance for Splunk APM and RUM between March 26, 2024 and March 28, 2024 as ...