Getting Data In

When I try to add or delete port 9997, why do I get the same "Error occurred attempting to remove 9997...Could not find config id for port"?

alexlit
Explorer

When I try deleting port 9997, I get the following problem:

Error occurred attempting to remove 9997: In handler 'cooked': Could not find config id for port 9997.

When I try to add port 9997, I get the following error message:

Error occurred attempting to remove 9997: In handler 'cooked': Could not find config id for port 9997.

Do you know what could be a problem? I am using Windows.

lguinn2
Legend

When you say you are "trying to delete," what do you mean? Exactly what commands are you using?

You can always remove or change a port by editing the configuration file, and then restarting Splunk. So if $SPLUNK_HOME/etc/system/local/inputs.conf contains

[splunktcp-ssl:9997]

[SSL]
password=(obfuscated out)
rootCA = /some_file_path/cacert.pem
serverCert = /some_file_path/server.pem

or

[splunktcp://:9997]

You can change the 9997 to something else, or remove the entire stanza. (In this example, these are single-line stanzas.) Then restart Splunk so that your changes take effect.

0 Karma

lloydd518
Path Finder

Sorry, should have been more specific. This is all work that is being carried out from inside the Splunk UI.. it throws an error/exception.. cannot delete the receiving port...when trying to remove the receiver port 9997.
Wondered if it was a bug related to having not created my SSL receiving port in the UI (which you cant do anyway.. not a feature in the Splunk UI).
Wondered if it was a bug whereby you create a receiver in the CLI then try to remove it via the Splunk UI.

0 Karma

lguinn2
Legend

I would agree that an error/exception is a bug. Feel free to file a ticket with Splunk Support.

And I always recommend that you un-do something using the same technique as when you originally did it.

0 Karma

lloydd518
Path Finder

In your $splunk_home/etc/system/local/inputs.conf file...

is it an SSL type
[splunktcp-ssl:9997] listener ?

[SSL]
password=********(obfuscated out)
rootCA = /some_file_path/cacert.pem
serverCert = /some_file_path/server.pem

Mine is.. and I'm having a similar issue to you.

I'm using Splunk 6.3.2... what version are you using ?

0 Karma
Get Updates on the Splunk Community!

Threat Hunting Unlocked: How to Uplevel Your Threat Hunting With the PEAK Framework ...

WATCH NOWAs AI starts tackling low level alerts, it's more critical than ever to uplevel your threat hunting ...

Splunk APM: New Product Features + Community Office Hours Recap!

Howdy Splunk Community! Over the past few months, we’ve had a lot going on in the world of Splunk Application ...

Index This | Forward, I’m heavy; backward, I’m not. What am I?

April 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...