When I try to configure the "Splunk Add-on for Unix and Linux" app in Splunk Cloud I receive an error message that states: "There was an unexpected problem while saving the inputs. Please reload the page and try again."
This error message is vague and I am not sure what to do next.
Does anyone have a solution?
What did you find in the log?
index=_internal source="*splunkd.log"
Here are a few of the messages in the log:
INFO TcpOutputProc - Found currently active indexer. Connected to idx=[Ip address]:9997, reuse=1
ERROR ExecProcessor - message from "Applications/SplunkForwarder/etc/apps/Splunk_TA_nix/bin/protocol.sh" netstat: sysctl: net.inet.ip.input_perf_data: No such file or directory
HttpListener - Socket error from [IP address] :33544 while idling: error:1407609C
INFO ChunkedLBProcessor - Failed to find EVENT_BREAKER regex in props.conf for sourcetype::Unix:Service. Reverting to the default EVENT_BREAKER regex for now
So I am currently on a 15 day free trial so apparently I am not entitled to open support tickets - I contacted the sales team via voicemail and via email. I'll post back here once I have a solution.
Did you get a response from support?