Splunk Enterprise

SH cluster, can't delete objects

verbal_666
Builder

We recently turned a single SH into a 3 SHs Cluster.

Now we cannot manager some object, since we have not the "move" or "delete" actions...

Example, in savedsearch.config, we have many alerts (66), many of them, with same permission, managed by Admin, have not the "move" and "delete" icon in Actions, others have them in Web UI.

Splunk 6.4.3 build b03109c2bad4

Bug? Need an update? Is there a fix?

Thanks.

Tags (1)
0 Karma

skalliger
Motivator

It's not a problem of the cluster, but of your config location. Your files are stored under default, am I correct?
You can only delete or move objects via the GUI when they're stored under local.

Skalli

0 Karma

verbal_666
Builder

Need to verify it. Tomorrow i'll do. Maybe it's so! Tomorrow i'll verify and try a move of the objects with splunkd down. Thanks for now.

0 Karma

skalliger
Motivator

You're welcome. I hope that was the problem, keep us updated.

0 Karma

verbal_666
Builder

Had not time today to test. Also is a shared Environment, i can't shutdown processes as i want whenever i want 😉 i'll test it asap... the only thing i can say just now: we have surely many .conf divided in both default & local path; so i'll need also to merge them 😞 a big work... see asap... thanks

0 Karma

koshyk
Super Champion

it is not that simple to change a non-cluster SH to a cluster SH. Did you setup a deployer?
What i would do is to backup your configs, clean up all SH cluster members from scratch, set-it up and deploy from deployer using the backedup code.

0 Karma

verbal_666
Builder

I came now, with a "little" delay, in front of difference between Deployment & Deployer!!! 😐 😐 😐

So, we have a Deployment to distribuite apps to Forwarders. This is not the point.

And, YES, we have a Deployer to distribute apps to SHs, but still not working. So, the fact is here. Next step is to make the Deployer working.

Thanks. And sorry for the misunderstanding 🙂

0 Karma

verbal_666
Builder

Yes. We have 1 DS inside and 2 Indexers.

So, there no "easy fix"? I really didn't want just to backup all .conf, maybe join them, and redistribute 😞

But if it's the only solution... we approach the problem so...

Thanks.

0 Karma

verbal_666
Builder

Here's the Web UI example, to see...

alt text

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...