All Apps and Add-ons

Filters does not allow editing of values?

gesman
Communicator

Trying to add filter to stream, so that 'http_method' would match "POST".
While editing stream - added filter:
"http.method", "exactly matches" - but "Value" field is disabled and clicking on small pencil icon doesn't do anything.
Tried doing the same with another browser - same result - cannot add/edit values for filters - value field always disabled.

How can i add/edit filters for streams?

Tags (1)
0 Karma

mdickey_splunk
Splunk Employee
Splunk Employee

I believe this is fixed now in 6.1.1. Please see http://docs.splunk.com/Documentation/StreamApp/latest/ReleaseNotes/FixedProblems (STREAM-1527 may apply to other browsers/versions as well).

0 Karma

gesman
Communicator

I found that on different deployment - this feature works. I used RPM-based install on the working one.
On non-working I used TAR-based install.

So maybe it's something to do with permissions. To overcome that I manually edited .conf file where filters are actually reside and restarted splunk to activate that.

Gleb

0 Karma

mdickey_splunk
Splunk Employee
Splunk Employee

This seems to work for certain browsers/versions but not others. It is a known bug that we believe is fixed in the soon-to-be-released 6.1.1 maintenance release.

0 Karma

gesman
Communicator

Actually that may be the cause - as second (working) setup uses older browsers (QA server within financial company - older browsers are a norm here) vs. non-working setup is my home-based.

Looking forward to update.

0 Karma
Get Updates on the Splunk Community!

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...

Cloud Monitoring Console - Unlocking Greater Visibility in SVC Usage Reporting

For Splunk Cloud customers, understanding and optimizing Splunk Virtual Compute (SVC) usage and resource ...

Automatic Discovery Part 3: Practical Use Cases

If you’ve enabled Automatic Discovery in your install of the Splunk Distribution of the OpenTelemetry ...