Monitoring Splunk

Why am I getting errors when I try to disable scheduled searches associated with Deployment Monitor app?

OldManEd
Builder

I'm trying to make a mirror copy of my Splunk 5.0.5 instance on a test instance to test a 6.1.3 upgrade. I'm trying to make a backup of the 5.0.5 Search Head configuration directory, "/opt/splunk/etc", with all the scheduled searches disabled so when I bring up the test instance, I won't get errors.

I've had no problems disabling most of the scheduled searches, except those associated with the Deployment Monitor application. When I try to disable any scheduled searches associated with the deployment app, I get the following error;

Error occurred attempting to disable DM indexthru week over week: In handler 'savedsearch': Data could not be written: /nobody/SplunkDeploymentMonitor/savedsearches/DM indexthru week over week/disabled: 1.

I searched for the directory above and could not find it. I then tried to disable the app, but could not accomplish that either.

Does anyone have any experience with this problem? If I delete the Deployment Monitor app with that take care of the problem?

Any suggestions will be appreciated.

Update: I was able to find the search in the following file;

/opt/splunk/etc/apps/SplunkDeploymentMonitor/default/savedsearches.conf

But that's not where the Manager>Searches and Reports page is looking for it. Hmmm...

0 Karma
1 Solution

OldManEd
Builder

I could not find a suitable answer for this issue so I decided to simply remove the application completely. This eliminated all the associated scheduled searches that I was having issues with.

View solution in original post

0 Karma

OldManEd
Builder

I could not find a suitable answer for this issue so I decided to simply remove the application completely. This eliminated all the associated scheduled searches that I was having issues with.

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...