Any ideas what's the cause of this error when searching either the index or sourcetype for AWS Cloudwatch data. I can see the data being updated in the index (aws-cloudwatch) but I'm not able to do a search without generating this error.
AWS add-on version (1.1.0)
Splunk (6.1)
Splunk App for AWS (3.0.2)
Thanks
Hal
Commented out the following line and I'm now able to search the index. (default/props.conf)
[aws:cloudwatch]
Commented out the following line and I'm now able to search the index. (default/props.conf)
[aws:cloudwatch]
Hi @amaddio, to make backend configuration changes in Splunk Cloud, you will need to open a Support ticket with Splunk requesting those changes to be made on your behalf.
Please note that if you comment out KV_MODE in props.conf, the field extractions won't apply. So to keep the field extractions yet get around the issue noted above, it's best to follow this solution: http://answers.splunk.com/answers/229960/why-am-i-seeing-this-error-failed-to-find-a-valid.html
(Copy the multikv.conf file from etc/apps/Splunk_TA_aws/default on the search head to the indexer (or cluster master if it's a an indexer cluster) and restart the Splunk service).
Hello,
I have the same issue, how can I change this setting with a Splunk Cloud Server ?
Thank you,