I am documenting an upgrade and get the following error messages for my saved searches:
could not find user in splunk etc/passwd corresponding to id=-1 from savedsearch: TEST_SAVED_SEARCH ... simply using as is for meta
I've tried manually putting in -1 into the passwd file. I've tried to hunt down the saved search file and nothing appears to be working. I'd like to continue the upgrade, but I can't afford to lose the numerous saved searches and data.
Any ideas?
Thanks.
OK. The answer was pretty simple.
Open up the saved search file at /opt/splunk/etc/system/local and change the userid from -1 to 1.
I'd guess it was because I created them using the free version?
OK. The answer was pretty simple.
Open up the saved search file at /opt/splunk/etc/system/local and change the userid from -1 to 1.
I'd guess it was because I created them using the free version?