<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: error in savedsearches.conf in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/Error-in-savedsearches-conf-Invalid-key-in-stanza-splunk/m-p/620067#M14446</link>
    <description>&lt;P&gt;Same Problem in 9.0.2:&lt;/P&gt;&lt;P&gt;/opt/splunk/bin/splunk btool check --debug&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;Checking: /opt/splunk/etc/apps/splunk_instrumentation/default/savedsearches.conf
		Invalid key in stanza [instrumentation.usage.tlsBestPractices] in /opt/splunk/etc/apps/splunk_instrumentation/default/savedsearches.conf, line 451: | append [| rest /services/configs/conf-pythonSslClientConfig | eval sslVerifyServerCert (value: if(isnull(sslVerifyServerCert),"unset",sslVerifyServerCert), splunk_server=sha256(splunk_server) | stats values(eai:acl.app) as python_configuredApp values(sslVerifyServerCert) as python_sslVerifyServerCert by splunk_server | eval python_configuredSystem=if(python_configuredApp="system","true","false") | fields python_sslVerifyServerCert, splunk_server, python_configuredSystem] 
| append [| rest /services/configs/conf-web/settings | eval mgmtHostPort=if(isnull(mgmtHostPort),"unset",mgmtHostPort), splunk_server=sha256(splunk_server) | stats values(eai:acl.app) as fwdrMgmtHostPort_configuredApp values(mgmtHostPort) as fwdr_mgmtHostPort by splunk_server | eval fwdrMgmtHostPort_configuredSystem=if(fwdrMgmtHostPort_configuredApp="system","true","false") | fields fwdrMgmtHostPort_sslVerifyServerCert, splunk_server, fwdrMgmtHostPort_configuredSystem] 
| append [| rest /services/configs/conf-server/sslConfig | eval cliVerifyServerName=if(isnull(cliVerifyServerName),"feature",cliVerifyServerName), splunk_server=sha256(splunk_server) | stats values(cliVerifyServerName) as servername_cliVerifyServerName values(eai:acl.app) as servername_configuredApp by splunk_server | eval cli_configuredSystem=if(cli_configuredApp="system","true","false") | fields cli_sslVerifyServerCert, splunk_server, cli_configuredSystem] 
| stats values(*) as * by splunk_server | eval date=now() | makejson output=data | eval _time=date, date=strftime(date,"%Y-%m-%d") | fields data date _time).&lt;/LI-CODE&gt;</description>
    <pubDate>Tue, 08 Nov 2022 09:42:24 GMT</pubDate>
    <dc:creator>dfgrtKJH</dc:creator>
    <dc:date>2022-11-08T09:42:24Z</dc:date>
    <item>
      <title>Error in savedsearches.conf-  Invalid key in stanza - splunk_instrumentation - savedseaches.conf v8.2.9</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Error-in-savedsearches-conf-Invalid-key-in-stanza-splunk/m-p/619849#M14430</link>
      <description>&lt;P&gt;As my original subject led to some weird error message about message flooding - here it is again:&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Subject: Invalid key in stanza - splunk_instrumentation - savedseaches.conf v8.2.9&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Version 8.2.9 (Linux, tgz-version) brings the "Invalid key in stanza" error in line 451 of `/opt/splunk/etc/apps/splunk_instrumentation/default/savedsearches.conf` - file. This wasn't the case in v.8.27.&lt;/P&gt;
&lt;P&gt;It turns out that the named file differs in one character between the two versions:&lt;/P&gt;
&lt;P&gt;A space added after the "\" (for line continuation) in v8.2.9. After removing that single space the `splunk restart` command run through without errors.&lt;/P&gt;</description>
      <pubDate>Tue, 08 Nov 2022 15:52:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Error-in-savedsearches-conf-Invalid-key-in-stanza-splunk/m-p/619849#M14430</guid>
      <dc:creator>rvany</dc:creator>
      <dc:date>2022-11-08T15:52:25Z</dc:date>
    </item>
    <item>
      <title>Re: error in savedsearches.conf</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Error-in-savedsearches-conf-Invalid-key-in-stanza-splunk/m-p/620067#M14446</link>
      <description>&lt;P&gt;Same Problem in 9.0.2:&lt;/P&gt;&lt;P&gt;/opt/splunk/bin/splunk btool check --debug&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;Checking: /opt/splunk/etc/apps/splunk_instrumentation/default/savedsearches.conf
		Invalid key in stanza [instrumentation.usage.tlsBestPractices] in /opt/splunk/etc/apps/splunk_instrumentation/default/savedsearches.conf, line 451: | append [| rest /services/configs/conf-pythonSslClientConfig | eval sslVerifyServerCert (value: if(isnull(sslVerifyServerCert),"unset",sslVerifyServerCert), splunk_server=sha256(splunk_server) | stats values(eai:acl.app) as python_configuredApp values(sslVerifyServerCert) as python_sslVerifyServerCert by splunk_server | eval python_configuredSystem=if(python_configuredApp="system","true","false") | fields python_sslVerifyServerCert, splunk_server, python_configuredSystem] 
| append [| rest /services/configs/conf-web/settings | eval mgmtHostPort=if(isnull(mgmtHostPort),"unset",mgmtHostPort), splunk_server=sha256(splunk_server) | stats values(eai:acl.app) as fwdrMgmtHostPort_configuredApp values(mgmtHostPort) as fwdr_mgmtHostPort by splunk_server | eval fwdrMgmtHostPort_configuredSystem=if(fwdrMgmtHostPort_configuredApp="system","true","false") | fields fwdrMgmtHostPort_sslVerifyServerCert, splunk_server, fwdrMgmtHostPort_configuredSystem] 
| append [| rest /services/configs/conf-server/sslConfig | eval cliVerifyServerName=if(isnull(cliVerifyServerName),"feature",cliVerifyServerName), splunk_server=sha256(splunk_server) | stats values(cliVerifyServerName) as servername_cliVerifyServerName values(eai:acl.app) as servername_configuredApp by splunk_server | eval cli_configuredSystem=if(cli_configuredApp="system","true","false") | fields cli_sslVerifyServerCert, splunk_server, cli_configuredSystem] 
| stats values(*) as * by splunk_server | eval date=now() | makejson output=data | eval _time=date, date=strftime(date,"%Y-%m-%d") | fields data date _time).&lt;/LI-CODE&gt;</description>
      <pubDate>Tue, 08 Nov 2022 09:42:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Error-in-savedsearches-conf-Invalid-key-in-stanza-splunk/m-p/620067#M14446</guid>
      <dc:creator>dfgrtKJH</dc:creator>
      <dc:date>2022-11-08T09:42:24Z</dc:date>
    </item>
    <item>
      <title>Re: error in savedsearches.conf</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Error-in-savedsearches-conf-Invalid-key-in-stanza-splunk/m-p/620074#M14448</link>
      <description>&lt;UL&gt;&lt;LI&gt;In 9.0.2, I changed /opt/splunk/etc/apps/splunk_instrumentation/default/savedsearches.conf line 447 and removed the space at the end of the line after the "\" character.&lt;/LI&gt;&lt;LI&gt;sha256sum /opt/splunk/etc/apps/splunk_instrumentation/default/savedsearches.conf&lt;BR /&gt;e00229cf2b4fee8ecf2232d98358d1a32563bb7edf6a60ec2274e765fb51e22d&lt;/LI&gt;&lt;LI&gt;edit /opt/splunk/splunk-9.0.2-17e00c557dc1-linux-2.6-x86_64-manifest&lt;/LI&gt;&lt;LI&gt;restart splunk&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Problem solved. The changed file is now identical to the same file in version 9.0.1.&lt;/P&gt;&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/149"&gt;@splunk&lt;/a&gt;Please fix this typo in the file&lt;/P&gt;</description>
      <pubDate>Tue, 08 Nov 2022 10:50:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Error-in-savedsearches-conf-Invalid-key-in-stanza-splunk/m-p/620074#M14448</guid>
      <dc:creator>dfgrtKJH</dc:creator>
      <dc:date>2022-11-08T10:50:01Z</dc:date>
    </item>
    <item>
      <title>Re: error in savedsearches.conf</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Error-in-savedsearches-conf-Invalid-key-in-stanza-splunk/m-p/620076#M14449</link>
      <description>&lt;P&gt;Yes, that's exactly the line for th 8.2.9 version although the sha256sum is different there.&lt;/P&gt;</description>
      <pubDate>Tue, 08 Nov 2022 10:55:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Error-in-savedsearches-conf-Invalid-key-in-stanza-splunk/m-p/620076#M14449</guid>
      <dc:creator>rvany</dc:creator>
      <dc:date>2022-11-08T10:55:00Z</dc:date>
    </item>
    <item>
      <title>Re: error in savedsearches.conf</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Error-in-savedsearches-conf-Invalid-key-in-stanza-splunk/m-p/620282#M14473</link>
      <description>&lt;P&gt;Yeah it works!&lt;/P&gt;&lt;P&gt;Not good that Splunk distributes bugged packages.&lt;/P&gt;&lt;P&gt;Thank you &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/156747"&gt;@dfgrtKJH&lt;/a&gt; !&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; Marco&lt;/P&gt;</description>
      <pubDate>Wed, 09 Nov 2022 13:59:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Error-in-savedsearches-conf-Invalid-key-in-stanza-splunk/m-p/620282#M14473</guid>
      <dc:creator>sistemistiposta</dc:creator>
      <dc:date>2022-11-09T13:59:43Z</dc:date>
    </item>
    <item>
      <title>Re: error in savedsearches.conf</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Error-in-savedsearches-conf-Invalid-key-in-stanza-splunk/m-p/620695#M14506</link>
      <description>&lt;P&gt;Thank you for the feedback. We have an internal bug number to address and fix it now.&lt;/P&gt;</description>
      <pubDate>Mon, 14 Nov 2022 01:00:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Error-in-savedsearches-conf-Invalid-key-in-stanza-splunk/m-p/620695#M14506</guid>
      <dc:creator>jerryz_splunk</dc:creator>
      <dc:date>2022-11-14T01:00:53Z</dc:date>
    </item>
    <item>
      <title>Re: Error in savedsearches.conf-  Invalid key in stanza - splunk_instrumentation - savedseaches.conf v8.2.9</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Error-in-savedsearches-conf-Invalid-key-in-stanza-splunk/m-p/621090#M14524</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/50341"&gt;@rvany&lt;/a&gt;thanks for the community entry, this has taken away the doubts about ourselves &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;And first thought something went wrong during installation on our system, but we found the "problem" on all of our server.&lt;/P&gt;&lt;P&gt;With a patch (bash script) we fixed the "typo" (we don't know if it has a negative impact on Splunk's behaviour or it is just an typo)&amp;nbsp; and change the sha256sum of the file in the manifest file so that no error message comes up when Splunk starts.&lt;/P&gt;&lt;P&gt;This should have been noticed by Splunk when testing the software.&lt;/P&gt;</description>
      <pubDate>Wed, 16 Nov 2022 15:56:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Error-in-savedsearches-conf-Invalid-key-in-stanza-splunk/m-p/621090#M14524</guid>
      <dc:creator>manuelostertag</dc:creator>
      <dc:date>2022-11-16T15:56:39Z</dc:date>
    </item>
    <item>
      <title>Re: error in savedsearches.conf</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Error-in-savedsearches-conf-Invalid-key-in-stanza-splunk/m-p/625058#M14881</link>
      <description>&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;P&gt;This is not fixed in the new version 9.0.3.&lt;/P&gt;&lt;P&gt;Very sad...&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Thu, 22 Dec 2022 09:06:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Error-in-savedsearches-conf-Invalid-key-in-stanza-splunk/m-p/625058#M14881</guid>
      <dc:creator>dfgrtKJH</dc:creator>
      <dc:date>2022-12-22T09:06:01Z</dc:date>
    </item>
    <item>
      <title>Re: error in savedsearches.conf</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Error-in-savedsearches-conf-Invalid-key-in-stanza-splunk/m-p/625066#M14882</link>
      <description>&lt;P&gt;The fix of this is scheduled in 9.0.4. Thanks for yor patience. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 22 Dec 2022 10:12:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Error-in-savedsearches-conf-Invalid-key-in-stanza-splunk/m-p/625066#M14882</guid>
      <dc:creator>jerryz_splunk</dc:creator>
      <dc:date>2022-12-22T10:12:20Z</dc:date>
    </item>
    <item>
      <title>Re: error in savedsearches.conf</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Error-in-savedsearches-conf-Invalid-key-in-stanza-splunk/m-p/630846#M15402</link>
      <description>&lt;P&gt;I didn't see mention of the issue in 9.0.3 but I can confirm that the issue is also in 9.0.3.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I implemented the recommended change and it resolved the error.&lt;/P&gt;&lt;P&gt;sha256sum shows the following after making the change:&lt;/P&gt;&lt;LI-CODE lang="python"&gt;e00229cf2b4fee8ecf2232d98358d1a32563bb7edf6a60ec2274e765fb51e22d  savedsearches.conf&lt;/LI-CODE&gt;&lt;P&gt;Thanks all! I'm glad I wasn't the only one running into this. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Feb 2023 17:55:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Error-in-savedsearches-conf-Invalid-key-in-stanza-splunk/m-p/630846#M15402</guid>
      <dc:creator>jeffh-cf</dc:creator>
      <dc:date>2023-02-14T17:55:47Z</dc:date>
    </item>
    <item>
      <title>Re: Error in savedsearches.conf-  Invalid key in stanza - splunk_instrumentation - savedseaches.conf v8.2.9</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Error-in-savedsearches-conf-Invalid-key-in-stanza-splunk/m-p/631970#M15481</link>
      <description>&lt;P&gt;Luckily, the error is solved in 8.2.10 &lt;span class="lia-unicode-emoji" title=":grinning_face_with_sweat:"&gt;😅&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 23 Feb 2023 08:07:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Error-in-savedsearches-conf-Invalid-key-in-stanza-splunk/m-p/631970#M15481</guid>
      <dc:creator>manuelostertag</dc:creator>
      <dc:date>2023-02-23T08:07:28Z</dc:date>
    </item>
  </channel>
</rss>

