<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: unable to find a saved search asset_discovery in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/unable-to-find-a-saved-search-asset-discovery/m-p/23273#M607</link>
    <description>&lt;P&gt;thanks for the response. I've got the app installed in the search peers. i'm thinking maybe i remove from the search peers (indexers). run the app on a heavy forwarder and have this push/tag events into the indexer cluster. &lt;/P&gt;

&lt;P&gt;i've removed from the search head for the time being, so the annoying messages are gone. &lt;/P&gt;

&lt;P&gt;whats weird is that everything is functioning correctly. the app works really well. it is just that yellow warning message.&lt;/P&gt;</description>
    <pubDate>Thu, 12 Apr 2012 00:36:54 GMT</pubDate>
    <dc:creator>chrispolk</dc:creator>
    <dc:date>2012-04-12T00:36:54Z</dc:date>
    <item>
      <title>unable to find a saved search asset_discovery</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/unable-to-find-a-saved-search-asset-discovery/m-p/23267#M601</link>
      <description>&lt;P&gt;Hi everyone, &lt;/P&gt;

&lt;P&gt;I've been playing around with the Splunk Asset Discovery app. I think it will be of use to our organisation, but having some issues. &lt;/P&gt;

&lt;P&gt;My environment looks like this, 3 separate systems: &lt;BR /&gt;
2x Splunk indexers&lt;BR /&gt;
1x Search head. &lt;/P&gt;

&lt;P&gt;Each system has the asset discovery app install. Indexers are the ones actually running the nmap scripts. &lt;/P&gt;

&lt;P&gt;On our search head I am getting these warnings. Warnings come up no matter what you are doing (even regular searches). It is very annoying: &lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;[indexer1] Unable to find a saved search asset_discovery&lt;/LI&gt;
&lt;LI&gt;[indexer2] Unable to find a saved search asset_discovery&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;The app is working correctly on the search head. Data/graphs/etc all functioning. It is just this warning message&lt;/P&gt;

&lt;P&gt;Anyone have any ideas? or know of a way to just disable the warning? &lt;/P&gt;</description>
      <pubDate>Tue, 10 Apr 2012 14:48:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/unable-to-find-a-saved-search-asset-discovery/m-p/23267#M601</guid>
      <dc:creator>chrispolk</dc:creator>
      <dc:date>2012-04-10T14:48:30Z</dc:date>
    </item>
    <item>
      <title>Re: unable to find a saved search asset_discovery</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/unable-to-find-a-saved-search-asset-discovery/m-p/23268#M602</link>
      <description>&lt;P&gt;in the savedsearches.conf there are :&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;# Base Search
[asset_discovery]
search = index=asset_discovery
is_visible = false
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;And in eventtypes.conf :&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;# eventtypes.conf

[ping_scan]
search = savedsearch=asset_discovery sourcetype=ping_scan "Host:" "Status:"

[port_scan]
search = savedsearch=asset_discovery sourcetype=port_scan "Host:" "Ports:" "Ignored State:"
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Do you have those? And do you see config error when you start splunk from command line?&lt;/P&gt;</description>
      <pubDate>Tue, 10 Apr 2012 15:09:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/unable-to-find-a-saved-search-asset-discovery/m-p/23268#M602</guid>
      <dc:creator>MarioM</dc:creator>
      <dc:date>2012-04-10T15:09:16Z</dc:date>
    </item>
    <item>
      <title>Re: unable to find a saved search asset_discovery</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/unable-to-find-a-saved-search-asset-discovery/m-p/23269#M603</link>
      <description>&lt;P&gt;the savedsearches.conf and eventtypes.conf are present and correct for all systems (search head and indexers).&lt;/P&gt;

&lt;P&gt;I tested restarting splunk on command line and there was no config errors. ran btool as well. &lt;/P&gt;

&lt;P&gt;Also checked permissions on the asset_discovery saved searches on the indexers, currently set to global and everyone has permissions to read results.&lt;/P&gt;</description>
      <pubDate>Tue, 10 Apr 2012 15:17:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/unable-to-find-a-saved-search-asset-discovery/m-p/23269#M603</guid>
      <dc:creator>chrispolk</dc:creator>
      <dc:date>2012-04-10T15:17:10Z</dc:date>
    </item>
    <item>
      <title>Re: unable to find a saved search asset_discovery</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/unable-to-find-a-saved-search-asset-discovery/m-p/23270#M604</link>
      <description>&lt;P&gt;have dig into internal index (index=_internal asset_discovery)?&lt;BR /&gt;
Have you try by only putting the app on the search head?&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 11:39:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/unable-to-find-a-saved-search-asset-discovery/m-p/23270#M604</guid>
      <dc:creator>MarioM</dc:creator>
      <dc:date>2020-09-28T11:39:22Z</dc:date>
    </item>
    <item>
      <title>Re: unable to find a saved search asset_discovery</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/unable-to-find-a-saved-search-asset-discovery/m-p/23271#M605</link>
      <description>&lt;P&gt;I haven't tried only having the app on the search head. I'd prefer to have our indexers doing the heavy lifting (running scans).&lt;/P&gt;

&lt;P&gt;nothing stands out on the search "index=_internal asset_discovery"&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 11:39:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/unable-to-find-a-saved-search-asset-discovery/m-p/23271#M605</guid>
      <dc:creator>chrispolk</dc:creator>
      <dc:date>2020-09-28T11:39:43Z</dc:date>
    </item>
    <item>
      <title>Re: unable to find a saved search asset_discovery</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/unable-to-find-a-saved-search-asset-discovery/m-p/23272#M606</link>
      <description>&lt;P&gt;Hi Chris&lt;/P&gt;

&lt;P&gt;The root cause here is that in the app "asset_discovery" , the eventtype in this case is referencing a savedsearch. But in a distributed search setting, splunk doesn't replicate savedsearches.conf from the search-head to the peers.&lt;/P&gt;

&lt;P&gt;The problem is that the app is not using a conventional definition for the eventtypes. that is not supported.&lt;/P&gt;

&lt;P&gt;Workarounds : &lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;install the app in the search-peers&lt;/LI&gt;
&lt;LI&gt;change the bundle replication whitelist to add the savedsearches.conf ( will be more costly for all your apps / searches )&lt;/LI&gt;
&lt;LI&gt;ask the author of the app to update his app to be compatible with distributed search.&lt;/LI&gt;
&lt;LI&gt;wait for an enhancement in splunk to allow this.&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Thu, 12 Apr 2012 00:06:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/unable-to-find-a-saved-search-asset-discovery/m-p/23272#M606</guid>
      <dc:creator>yannK</dc:creator>
      <dc:date>2012-04-12T00:06:03Z</dc:date>
    </item>
    <item>
      <title>Re: unable to find a saved search asset_discovery</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/unable-to-find-a-saved-search-asset-discovery/m-p/23273#M607</link>
      <description>&lt;P&gt;thanks for the response. I've got the app installed in the search peers. i'm thinking maybe i remove from the search peers (indexers). run the app on a heavy forwarder and have this push/tag events into the indexer cluster. &lt;/P&gt;

&lt;P&gt;i've removed from the search head for the time being, so the annoying messages are gone. &lt;/P&gt;

&lt;P&gt;whats weird is that everything is functioning correctly. the app works really well. it is just that yellow warning message.&lt;/P&gt;</description>
      <pubDate>Thu, 12 Apr 2012 00:36:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/unable-to-find-a-saved-search-asset-discovery/m-p/23273#M607</guid>
      <dc:creator>chrispolk</dc:creator>
      <dc:date>2012-04-12T00:36:54Z</dc:date>
    </item>
  </channel>
</rss>

