Monitoring Splunk

Why am I getting errors when I try to disable scheduled searches associated with Deployment Monitor app?

OldManEd
Builder

I'm trying to make a mirror copy of my Splunk 5.0.5 instance on a test instance to test a 6.1.3 upgrade. I'm trying to make a backup of the 5.0.5 Search Head configuration directory, "/opt/splunk/etc", with all the scheduled searches disabled so when I bring up the test instance, I won't get errors.

I've had no problems disabling most of the scheduled searches, except those associated with the Deployment Monitor application. When I try to disable any scheduled searches associated with the deployment app, I get the following error;

Error occurred attempting to disable DM indexthru week over week: In handler 'savedsearch': Data could not be written: /nobody/SplunkDeploymentMonitor/savedsearches/DM indexthru week over week/disabled: 1.

I searched for the directory above and could not find it. I then tried to disable the app, but could not accomplish that either.

Does anyone have any experience with this problem? If I delete the Deployment Monitor app with that take care of the problem?

Any suggestions will be appreciated.

Update: I was able to find the search in the following file;

/opt/splunk/etc/apps/SplunkDeploymentMonitor/default/savedsearches.conf

But that's not where the Manager>Searches and Reports page is looking for it. Hmmm...

0 Karma
1 Solution

OldManEd
Builder

I could not find a suitable answer for this issue so I decided to simply remove the application completely. This eliminated all the associated scheduled searches that I was having issues with.

View solution in original post

0 Karma

OldManEd
Builder

I could not find a suitable answer for this issue so I decided to simply remove the application completely. This eliminated all the associated scheduled searches that I was having issues with.

0 Karma
Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...