Getting Data In

[Error 409 Object Exists] is this a bug?

verbal_666
Builder

Hallo.
Don't know if it's a bug or not, but... SPLUNK 8.2.12...

1. Create a simple EventType for "MYTEST" with tag "MYTEST", with a simple search like "index=_internal source=*splunkd.log"
2. The EventType and Tag are created OK
3. Change the permission to share EventType in App for */RW
4. ALL IS OK

verbal_666_1-1699445769267.png

verbal_666_2-1699445781589.png


NOW, delete both the objects, System is now empty.

1. ReCreate a simple EventType for "MYTEST" with tag "MYTEST", as before
2. The EventType and Tag are created OK
3. Change the permission to share EventType in App for */RW
4. NOW WE GET "Splunk could not update permissions for resource saved/eventtypes [HTTP 409] [{'type': 'ERROR', 'code': None, 'text': 'Cannot overwrite existing app object'}]"

verbal_666_3-1699445968796.png

5. We can only CANCEL and get back, where the EventType is shared in App, BUT WITH NO TAG ASSOCIATED!

verbal_666_4-1699446121702.png

5. Now we edit the EventType and add the Tag
6. From now on we have a double Tag and need to leave it so to preserve the shared Tag/EventType

verbal_666_5-1699446208116.png

 

Is this behavious normal??? 🙄🙄🙄

Thanks.

Labels (1)
0 Karma

verbal_666
Builder

The only way to reset the situation, is to manually edit the

"etc/users/user/app/local/eventtypes.conf & tags.conf"
"etc/apps/app/local/eventtypes.conf & tags.conf"
"etc/apps/app/metadata/local.meta"

and delete the objects there.
And restart the Splunkd. But if you are inside a cluster, it's not much comfortable 😐

0 Karma
Get Updates on the Splunk Community!

Index This | Why did the turkey cross the road?

November 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...