Deployment Architecture

How do I fix "The following issues were found with submitted configuration ... Value supplied is illegal" when trying to add a new index?

jackal713
Path Finder

Hello splunkers,
I ran into this earlier and couldn't find a post on it. So, now that I fixed myself, I thought I would share.
Issue: When trying to add a new index I get the following error message.
The following issues were found with submitted configuration:
stanza=osnixperf parameter=frozenTimePeriodInSecs Value supplied='604800 #7 days' is illegal; default='188697600'
stanza=oswinperf parameter=frozenTimePeriodInSecs Value supplied='604800 #7 days' is illegal; default='188697600'

This is the result of a typo in the indexes.conf file for the "Org_all_indexes" custom app. File path for me was splunk\etc\apps\org_all_indexes\default\indexes.conf
For me it was on line 66 and line 93. The comment (#7 days) needs to be move to a new line.
After making the changes you will need to restart Splunk.
Note: This app does not have a local folder.

Hope that this will save others some time.
Happy Splunking

Tags (2)
1 Solution

martin_mueller
SplunkTrust
SplunkTrust

self-answered in the question 🙂

View solution in original post

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

self-answered in the question 🙂

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...