Quantcast
Channel: Questions in topic: "upgrade"
Viewing all articles
Browse latest Browse all 457

After upgrading Splunk from 6.3.0 to 6.4.1, why am I getting error "Invalid value in stanza [header_nullq]" on restart?

$
0
0
Hi, I upgraded Splunk from 6.3.0 to 6.4.1. On restarting Splunk, I am getting below messages. Checking filesystem compatibility... Done **Checking conf files for problems... Invalid value in stanza [header_nullq] in /opt/splunk/etc/apps/CCMS-TA-onprem-reporting/default/transforms.conf, line 4: (key: DEST_KEY, value: nullqueue) ** Your indexes and inputs configurations are not internally consistent. For more information, run 'splunk btool check --debug' cannot find non-empty stack=download-trial for pool=auto_generated_pool_download-trial, skipping Done **// Content of my transforms.conf file** [header_nullq] DEST_KEY = queue REGEX = ^TimeStamp FORMAT = nullqueue Is it due to the upgrade? How to resolve this issue? Can somebody please help here? Thanks, Jitendra

Viewing all articles
Browse latest Browse all 457

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>