Deployment Architecture

How do I fix "The following issues were found with submitted configuration ... Value supplied is illegal" when trying to add a new index?

jackal713
Path Finder

Hello splunkers,
I ran into this earlier and couldn't find a post on it. So, now that I fixed myself, I thought I would share.
Issue: When trying to add a new index I get the following error message.
The following issues were found with submitted configuration:
stanza=osnixperf parameter=frozenTimePeriodInSecs Value supplied='604800 #7 days' is illegal; default='188697600'
stanza=oswinperf parameter=frozenTimePeriodInSecs Value supplied='604800 #7 days' is illegal; default='188697600'

This is the result of a typo in the indexes.conf file for the "Org_all_indexes" custom app. File path for me was splunk\etc\apps\org_all_indexes\default\indexes.conf
For me it was on line 66 and line 93. The comment (#7 days) needs to be move to a new line.
After making the changes you will need to restart Splunk.
Note: This app does not have a local folder.

Hope that this will save others some time.
Happy Splunking

Tags (2)
1 Solution

martin_mueller
SplunkTrust
SplunkTrust

self-answered in the question 🙂

View solution in original post

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

self-answered in the question 🙂

0 Karma
Get Updates on the Splunk Community!

🔐 Trust at Every Hop: How mTLS in Splunk Enterprise 10.0 Makes Security Simpler

From Idea to Implementation: Why Splunk Built mTLS into Splunk Enterprise 10.0  mTLS wasn’t just a checkbox ...

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

Splunk Decoded: Business Transactions vs Business IQ

It’s the morning of Black Friday, and your e-commerce site is handling 10x normal traffic. Orders are flowing, ...