All Apps and Add-ons

Splunk Enterprise Security not able to write/ read to savedsearches.conf file

mnizamuddin
Engager

Hello All, 

I'm having an issue where I am unable to create new correlation searches. I get the following error:
There was an error saving the correlation search: In handler 'savedsearch': Data could not be written: /nobody/SplunkEnterpriseSecuritySuite/savedsearches/Threat

Also, the existing searches are not running nor showing up in ES.

Labels (2)
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

Check the ownership and permissions on the savedsearches.conf file(s).  If you're running SELinux, check the settings to make sure Splunk has access.

---
If this reply helps you, an upvote would be appreciated.

View solution in original post

mnizamuddin
Engager

@richgalloway - Yes, the file ownership was set incorrectly. Thank you for your help. 

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Check the ownership and permissions on the savedsearches.conf file(s).  If you're running SELinux, check the settings to make sure Splunk has access.

---
If this reply helps you, an upvote would be appreciated.

View solution in original post