Alerting

After upgrading to 6.5.0, why are we receiving "In handler 'savedsearch': Could not flush changes to disk" error when modifying an alert?

dpanych
Communicator

We upgraded to 6.5.0 from 6.4.x, and now every time we attempt to save a change made to an alert, we get the following error:

In handler 'savedsearch': Could not flush changes to disk: /nobody/search/savedsearches/Test/search: ConfPathMapper: C:\Program Files\Splunk\etc\apps\search\local
On 6.4.x, saving changes worked 100% and now on 6.5.0 it does not. We didn't do anything unusual with the upgrade. What could this be? I checked both Splunk and Windows file system permissions and they both seem fine.

0 Karma
1 Solution

dpanych
Communicator

Figured out the cause. I guess having (1) Splunk_TA_nix - version 5.1.2 and (2) config_analytics - version 1.8 installed on Splunk 6.5.x causes the file-write issue. We removed the config_analytics app and things are working smoothly again.

View solution in original post

0 Karma

dpanych
Communicator

Figured out the cause. I guess having (1) Splunk_TA_nix - version 5.1.2 and (2) config_analytics - version 1.8 installed on Splunk 6.5.x causes the file-write issue. We removed the config_analytics app and things are working smoothly again.

0 Karma

scott_sackrider
Explorer

How did you find this out? Having a similar issue, but the suspected apps aren't installed. Appreciate the note.

0 Karma
Get Updates on the Splunk Community!

Splunk Observability Cloud | Unified Identity - Now Available for Existing Splunk ...

Raise your hand if you’ve already forgotten your username or password when logging into an account. (We can’t ...

Index This | How many sides does a circle have?

February 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

Registration for Splunk University is Now Open!

Are you ready for an adventure in learning?   Brace yourselves because Splunk University is back, and it's ...