<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Why am I getting error &amp;quot;In handler 'props-extract': Data could not be written:&amp;quot; after configuring extractions for custom fields? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Why-am-I-getting-error-quot-In-handler-props-extract-Data-could/m-p/245839#M73290</link>
    <description>&lt;P&gt;Ok, here's what I did:&lt;BR /&gt;
On the server, I gave full control of &lt;CODE&gt;$Splunk_home&lt;/CODE&gt; to the &lt;CODE&gt;Everyone&lt;/CODE&gt; user group. (Shotgun approach)&lt;BR /&gt;
On the web interface, on the &lt;CODE&gt;save&lt;/CODE&gt; screen for the field extraction, I clicked the &lt;CODE&gt;All Apps&lt;/CODE&gt; button on the &lt;CODE&gt;Permissions&lt;/CODE&gt; row, (&lt;CODE&gt;Owner&lt;/CODE&gt; had been selected by default).  This showed a table of users with columns for name, read permissions, and write permissions.  There was a line for the user group &lt;CODE&gt;Everyone&lt;/CODE&gt;, I checked the &lt;CODE&gt;Write Permissions&lt;/CODE&gt; box, and I was able to save.&lt;/P&gt;

&lt;P&gt;I'm hesitant to advertise it because it's not practicing the tightest security and could use some fine tuning, but I'm on a private network so security is not a big concern for me at the moment, and it works (or seems to)&lt;/P&gt;</description>
    <pubDate>Fri, 27 Nov 2015 19:54:13 GMT</pubDate>
    <dc:creator>_dave_b</dc:creator>
    <dc:date>2015-11-27T19:54:13Z</dc:date>
    <item>
      <title>Why am I getting error "In handler 'props-extract': Data could not be written:" after configuring extractions for custom fields?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-am-I-getting-error-quot-In-handler-props-extract-Data-could/m-p/245835#M73286</link>
      <description>&lt;P&gt;Hello, &lt;/P&gt;

&lt;P&gt;I had created some custom fields in my original Splunk Install, then I installed on a new server.  I'm trying to migrate the custom fields I created.  To try to save some time, I copied the props.conf file over to &lt;CODE&gt;$Splunkhome\etc\users\admin\search\local&lt;/CODE&gt;.  Splunk wasn't picking up on the new fields, so I tried adding them myself manually through the web interface.  When I save, I get this message&lt;/P&gt;

&lt;BLOCKQUOTE&gt;
&lt;P&gt;In handler 'props-extract': Data could not be written:&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;

&lt;P&gt;Does anyone know why it says this, and how can I create my fields to extract?&lt;/P&gt;

&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Wed, 25 Nov 2015 20:44:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-am-I-getting-error-quot-In-handler-props-extract-Data-could/m-p/245835#M73286</guid>
      <dc:creator>_dave_b</dc:creator>
      <dc:date>2015-11-25T20:44:29Z</dc:date>
    </item>
    <item>
      <title>Re: Why am I getting error "In handler 'props-extract': Data could not be written:" after configuring extractions for custom fields?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-am-I-getting-error-quot-In-handler-props-extract-Data-could/m-p/245836#M73287</link>
      <description>&lt;P&gt;You probably copied the file as user &lt;CODE&gt;root&lt;/CODE&gt; but Splunk is running as a lesser-priviliged user (e.g. &lt;CODE&gt;splunk&lt;/CODE&gt;) which does not have permission to write to the file.  You nee to do a &lt;CODE&gt;chown&lt;/CODE&gt; to match the user running splunk or &lt;CODE&gt;chmod&lt;/CODE&gt; to allow others to write to the file.&lt;/P&gt;</description>
      <pubDate>Thu, 26 Nov 2015 00:18:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-am-I-getting-error-quot-In-handler-props-extract-Data-could/m-p/245836#M73287</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2015-11-26T00:18:34Z</dc:date>
    </item>
    <item>
      <title>Re: Why am I getting error "In handler 'props-extract': Data could not be written:" after configuring extractions for custom fields?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-am-I-getting-error-quot-In-handler-props-extract-Data-could/m-p/245837#M73288</link>
      <description>&lt;P&gt;I should have stated that I am running on Windows Server 2012, but you pointed me in a good direction with the security permissions anyways.  After some fiddling around, my field extractions are now being saved and extracted without errors&lt;/P&gt;

&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Fri, 27 Nov 2015 18:35:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-am-I-getting-error-quot-In-handler-props-extract-Data-could/m-p/245837#M73288</guid>
      <dc:creator>_dave_b</dc:creator>
      <dc:date>2015-11-27T18:35:02Z</dc:date>
    </item>
    <item>
      <title>Re: Why am I getting error "In handler 'props-extract': Data could not be written:" after configuring extractions for custom fields?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-am-I-getting-error-quot-In-handler-props-extract-Data-could/m-p/245838#M73289</link>
      <description>&lt;P&gt;For our poor Windows users, do spell out exactly what commands you used to fix it.&lt;/P&gt;</description>
      <pubDate>Fri, 27 Nov 2015 18:41:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-am-I-getting-error-quot-In-handler-props-extract-Data-could/m-p/245838#M73289</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2015-11-27T18:41:57Z</dc:date>
    </item>
    <item>
      <title>Re: Why am I getting error "In handler 'props-extract': Data could not be written:" after configuring extractions for custom fields?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-am-I-getting-error-quot-In-handler-props-extract-Data-could/m-p/245839#M73290</link>
      <description>&lt;P&gt;Ok, here's what I did:&lt;BR /&gt;
On the server, I gave full control of &lt;CODE&gt;$Splunk_home&lt;/CODE&gt; to the &lt;CODE&gt;Everyone&lt;/CODE&gt; user group. (Shotgun approach)&lt;BR /&gt;
On the web interface, on the &lt;CODE&gt;save&lt;/CODE&gt; screen for the field extraction, I clicked the &lt;CODE&gt;All Apps&lt;/CODE&gt; button on the &lt;CODE&gt;Permissions&lt;/CODE&gt; row, (&lt;CODE&gt;Owner&lt;/CODE&gt; had been selected by default).  This showed a table of users with columns for name, read permissions, and write permissions.  There was a line for the user group &lt;CODE&gt;Everyone&lt;/CODE&gt;, I checked the &lt;CODE&gt;Write Permissions&lt;/CODE&gt; box, and I was able to save.&lt;/P&gt;

&lt;P&gt;I'm hesitant to advertise it because it's not practicing the tightest security and could use some fine tuning, but I'm on a private network so security is not a big concern for me at the moment, and it works (or seems to)&lt;/P&gt;</description>
      <pubDate>Fri, 27 Nov 2015 19:54:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-am-I-getting-error-quot-In-handler-props-extract-Data-could/m-p/245839#M73290</guid>
      <dc:creator>_dave_b</dc:creator>
      <dc:date>2015-11-27T19:54:13Z</dc:date>
    </item>
  </channel>
</rss>

