0

Eventtype 'uberAgent_index_query' does not exist or is disabled

We are getting this error showing up in our dashboards

• Eventtype 'uberAgent_index_query' does not exist or is disabled.
• [indexer host1] Eventtype 'uberAgent_index_query' does not exist or is disabled.
• [indexer host2] Eventtype 'uberAgent_index_query' does not exist or is disabled.
• [indexer host3] Eventtype 'uberAgent_index_query' does not exist or is disabled.
• [indexer host4] Eventtype 'uberAgent_index_query' does not exist or is disabled.
• [indexer host5] Eventtype 'uberAgent_index_query' does not exist or is disabled.
• [indexer host6] Eventtype 'uberAgent_index_query' does not exist or is disabled.
• [indexer host7] Eventtype 'uberAgent_index_query' does not exist or is disabled.
• [indexer host8] Eventtype 'uberAgent_index_query' does not exist or is disabled.

The issue is similar to this:
https://community.splunk.com/t5/All-Apps-and-Add-ons/ERROR-SearchParser-The-search-specifies-a-macro-cs-get-index/m-p/419675

When we disabled the EventType the error goes away.

5 comments

  • 0
    Avatar
    Dominik Britz

    Hi Mark,

    Which version of Splunk and of the uberAgent Splunk apps are you using?

  • 0
    Avatar
    Mark Swenson

    Splunk 8.0.7

    uberAgent UXM 6.0.0

  • 0
    Avatar
    Dominik Britz

    Thanks, Mark,

    uberAgent uses macros in the eventtypes.conf. For that to work, the macros.conf file needs to be replicated in your cluster. That is configured in uberAgent's distsearch.conf:

    [replicationSettings:refineConf]
    replicate.macros = true

    Please make sure that the distsearch.conf is available in the search head app. Please also make sure that you use the latest version of eventtypes.conf.

  • 0
    Avatar
    Mark Swenson

    We tried that fix and are still seeing that same issue.

  • 0
    Avatar
    Dominik Britz

    I'm sending this to our support system as we need to see some logs.

Please sign in to leave a comment.