Alerting

After upgrading to 6.5.0, why are we receiving "In handler 'savedsearch': Could not flush changes to disk" error when modifying an alert?

dpanych
Communicator

We upgraded to 6.5.0 from 6.4.x, and now every time we attempt to save a change made to an alert, we get the following error:

In handler 'savedsearch': Could not flush changes to disk: /nobody/search/savedsearches/Test/search: ConfPathMapper: C:\Program Files\Splunk\etc\apps\search\local
On 6.4.x, saving changes worked 100% and now on 6.5.0 it does not. We didn't do anything unusual with the upgrade. What could this be? I checked both Splunk and Windows file system permissions and they both seem fine.

0 Karma
1 Solution

dpanych
Communicator

Figured out the cause. I guess having (1) Splunk_TA_nix - version 5.1.2 and (2) config_analytics - version 1.8 installed on Splunk 6.5.x causes the file-write issue. We removed the config_analytics app and things are working smoothly again.

View solution in original post

0 Karma

dpanych
Communicator

Figured out the cause. I guess having (1) Splunk_TA_nix - version 5.1.2 and (2) config_analytics - version 1.8 installed on Splunk 6.5.x causes the file-write issue. We removed the config_analytics app and things are working smoothly again.

0 Karma

scott_sackrider
Explorer

How did you find this out? Having a similar issue, but the suspected apps aren't installed. Appreciate the note.

0 Karma
Get Updates on the Splunk Community!

Detecting Remote Code Executions With the Splunk Threat Research Team

REGISTER NOWRemote code execution (RCE) vulnerabilities pose a significant risk to organizations. If ...

Observability | Use Synthetic Monitoring for Website Metadata Verification

If you are on Splunk Observability Cloud, you may already have Synthetic Monitoringin your observability ...

More Ways To Control Your Costs With Archived Metrics | Register for Tech Talk

Tuesday, May 14, 2024  |  11AM PT / 2PM ET Register to Attend Join us for this Tech Talk and learn how to ...