Getting Data In

[Error 409 Object Exists] is this a bug?

verbal_666
Builder

Hallo.
Don't know if it's a bug or not, but... SPLUNK 8.2.12...

1. Create a simple EventType for "MYTEST" with tag "MYTEST", with a simple search like "index=_internal source=*splunkd.log"
2. The EventType and Tag are created OK
3. Change the permission to share EventType in App for */RW
4. ALL IS OK

verbal_666_1-1699445769267.png

verbal_666_2-1699445781589.png


NOW, delete both the objects, System is now empty.

1. ReCreate a simple EventType for "MYTEST" with tag "MYTEST", as before
2. The EventType and Tag are created OK
3. Change the permission to share EventType in App for */RW
4. NOW WE GET "Splunk could not update permissions for resource saved/eventtypes [HTTP 409] [{'type': 'ERROR', 'code': None, 'text': 'Cannot overwrite existing app object'}]"

verbal_666_3-1699445968796.png

5. We can only CANCEL and get back, where the EventType is shared in App, BUT WITH NO TAG ASSOCIATED!

verbal_666_4-1699446121702.png

5. Now we edit the EventType and add the Tag
6. From now on we have a double Tag and need to leave it so to preserve the shared Tag/EventType

verbal_666_5-1699446208116.png

 

Is this behavious normal??? 🙄🙄🙄

Thanks.

Labels (1)
0 Karma

verbal_666
Builder

The only way to reset the situation, is to manually edit the

"etc/users/user/app/local/eventtypes.conf & tags.conf"
"etc/apps/app/local/eventtypes.conf & tags.conf"
"etc/apps/app/metadata/local.meta"

and delete the objects there.
And restart the Splunkd. But if you are inside a cluster, it's not much comfortable 😐

0 Karma
Get Updates on the Splunk Community!

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

 Prepare to elevate your security operations with the powerful upgrade to Splunk Enterprise Security 8.x! This ...

Get Early Access to AI Playbook Authoring: Apply for the Alpha Private Preview ...

Passionate about security automation? Apply now to our AI Playbook Authoring Alpha private preview ...

Reduce and Transform Your Firewall Data with Splunk Data Management

Managing high-volume firewall data has always been a challenge. Noisy events and verbose traffic logs often ...