Getting Data In

[Error 409 Object Exists] is this a bug?

verbal_666
Builder

Hallo.
Don't know if it's a bug or not, but... SPLUNK 8.2.12...

1. Create a simple EventType for "MYTEST" with tag "MYTEST", with a simple search like "index=_internal source=*splunkd.log"
2. The EventType and Tag are created OK
3. Change the permission to share EventType in App for */RW
4. ALL IS OK

verbal_666_1-1699445769267.png

verbal_666_2-1699445781589.png


NOW, delete both the objects, System is now empty.

1. ReCreate a simple EventType for "MYTEST" with tag "MYTEST", as before
2. The EventType and Tag are created OK
3. Change the permission to share EventType in App for */RW
4. NOW WE GET "Splunk could not update permissions for resource saved/eventtypes [HTTP 409] [{'type': 'ERROR', 'code': None, 'text': 'Cannot overwrite existing app object'}]"

verbal_666_3-1699445968796.png

5. We can only CANCEL and get back, where the EventType is shared in App, BUT WITH NO TAG ASSOCIATED!

verbal_666_4-1699446121702.png

5. Now we edit the EventType and add the Tag
6. From now on we have a double Tag and need to leave it so to preserve the shared Tag/EventType

verbal_666_5-1699446208116.png

 

Is this behavious normal??? 🙄🙄🙄

Thanks.

Labels (1)
0 Karma

verbal_666
Builder

The only way to reset the situation, is to manually edit the

"etc/users/user/app/local/eventtypes.conf & tags.conf"
"etc/apps/app/local/eventtypes.conf & tags.conf"
"etc/apps/app/metadata/local.meta"

and delete the objects there.
And restart the Splunkd. But if you are inside a cluster, it's not much comfortable 😐

0 Karma
Get Updates on the Splunk Community!

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

🔐 Trust at Every Hop: How mTLS in Splunk Enterprise 10.0 Makes Security Simpler

From Idea to Implementation: Why Splunk Built mTLS into Splunk Enterprise 10.0  mTLS wasn’t just a checkbox ...