- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
mnizamuddin
Engager
12-31-2020
02:04 PM
Hello All,
I'm having an issue where I am unable to create new correlation searches. I get the following error:
There was an error saving the correlation search: In handler 'savedsearch': Data could not be written: /nobody/SplunkEnterpriseSecuritySuite/savedsearches/Threat
Also, the existing searches are not running nor showing up in ES.
1 Solution
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

richgalloway

SplunkTrust
01-01-2021
08:05 AM
Check the ownership and permissions on the savedsearches.conf file(s). If you're running SELinux, check the settings to make sure Splunk has access.
---
If this reply helps you, Karma would be appreciated.
If this reply helps you, Karma would be appreciated.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
ephemeric
Contributor
08-23-2021
06:05 AM
grep "denied" /var/log/audit/audit.log
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
mnizamuddin
Engager
01-05-2021
05:25 PM
@richgalloway - Yes, the file ownership was set incorrectly. Thank you for your help.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

richgalloway

SplunkTrust
01-01-2021
08:05 AM
Check the ownership and permissions on the savedsearches.conf file(s). If you're running SELinux, check the settings to make sure Splunk has access.
---
If this reply helps you, Karma would be appreciated.
If this reply helps you, Karma would be appreciated.
