Here is list of my finding for version 0.3.3:
Invalid key in stanza [] in default.meta, line 5: owner = admin.
Why owner is not allowed for all objects? It works just fine on 9.1.x
Stanza [tcpout-server://idx01.splunk.lab:9997] does not seem to be a valid stanza.
Invalid key in stanza [tcpout-server://idx01.splunk.lab:9997] in outputs.conf, line 30: sslAltNameToCheck = idx01.splunk.lab.
Perfectly working configuration for SSL configuration with SAN verification.
Invalid key in stanza [monitor://C:\inetpub\logs\LogFiles\W3SVC*\*.log] in inputs.conf, line 6: ignoreOlderThan = 7d.
Why? Since documented under:
https://docs.splunk.com/Documentation/Splunk/9.1.5/Admin/Inputsconf#MONITOR:
Invalid key in stanza [http://name] in inputs.conf, line 7: queueSize = 256KB.
Why? Since documented under:
https://docs.splunk.com/Documentation/Splunk/9.1.5/Admin/Inputsconf#HTTP_Event_Collector_.28HEC.29_-_Local_stanza_for_each_token
Invalid key in stanza [splunktcp-ssl:9997] in inputs.conf, line 6: inputShutdownTimeout = 60.
Option used for encrypted version.
Invalid key in stanza [house_keeping://default] in inputs.conf, line 34: interval = 300.
Custom config for modular input.
Invalid key in stanza [install] in app.conf, line 22: state_change_requires_restart = true .
Documented in: https://docs.splunk.com/Documentation/Splunk/9.1.5/Admin/Appconf#.5Binstall.5D
Invalid key in stanza [script:alertqueue] in restmap.conf, line 14: match = /alertqueue.
Invalid key in stanza [script:alertqueue] in restmap.conf, line 20: requireAuthentication = true.
Per endpoint attributes:
https://docs.splunk.com/Documentation/Splunk/9.1.5/Admin/Restmapconf#GLOBAL_SETTINGS
Here is list of my finding for version 0.3.3:
Why owner is not allowed for all objects? It works just fine on 9.1.x
Why? Since documented under:
https://docs.splunk.com/Documentation/Splunk/9.1.5/Admin/Inputsconf#MONITOR:
Why? Since documented under:
https://docs.splunk.com/Documentation/Splunk/9.1.5/Admin/Inputsconf#HTTP_Event_Collector_.28HEC.29_-_Local_stanza_for_each_token
Option used for encrypted version.
Custom config for modular input.
Documented in: https://docs.splunk.com/Documentation/Splunk/9.1.5/Admin/Appconf#.5Binstall.5D
Per endpoint attributes:
https://docs.splunk.com/Documentation/Splunk/9.1.5/Admin/Restmapconf#GLOBAL_SETTINGS