Alerting

After upgrading to 6.5.0, why are we receiving "In handler 'savedsearch': Could not flush changes to disk" error when modifying an alert?

dpanych
Communicator

We upgraded to 6.5.0 from 6.4.x, and now every time we attempt to save a change made to an alert, we get the following error:

In handler 'savedsearch': Could not flush changes to disk: /nobody/search/savedsearches/Test/search: ConfPathMapper: C:\Program Files\Splunk\etc\apps\search\local
On 6.4.x, saving changes worked 100% and now on 6.5.0 it does not. We didn't do anything unusual with the upgrade. What could this be? I checked both Splunk and Windows file system permissions and they both seem fine.

0 Karma
1 Solution

dpanych
Communicator

Figured out the cause. I guess having (1) Splunk_TA_nix - version 5.1.2 and (2) config_analytics - version 1.8 installed on Splunk 6.5.x causes the file-write issue. We removed the config_analytics app and things are working smoothly again.

View solution in original post

0 Karma

dpanych
Communicator

Figured out the cause. I guess having (1) Splunk_TA_nix - version 5.1.2 and (2) config_analytics - version 1.8 installed on Splunk 6.5.x causes the file-write issue. We removed the config_analytics app and things are working smoothly again.

0 Karma

scott_sackrider
Explorer

How did you find this out? Having a similar issue, but the suspected apps aren't installed. Appreciate the note.

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...