Monitoring Splunk

Why am I getting errors when I try to disable scheduled searches associated with Deployment Monitor app?

OldManEd
Builder

I'm trying to make a mirror copy of my Splunk 5.0.5 instance on a test instance to test a 6.1.3 upgrade. I'm trying to make a backup of the 5.0.5 Search Head configuration directory, "/opt/splunk/etc", with all the scheduled searches disabled so when I bring up the test instance, I won't get errors.

I've had no problems disabling most of the scheduled searches, except those associated with the Deployment Monitor application. When I try to disable any scheduled searches associated with the deployment app, I get the following error;

Error occurred attempting to disable DM indexthru week over week: In handler 'savedsearch': Data could not be written: /nobody/SplunkDeploymentMonitor/savedsearches/DM indexthru week over week/disabled: 1.

I searched for the directory above and could not find it. I then tried to disable the app, but could not accomplish that either.

Does anyone have any experience with this problem? If I delete the Deployment Monitor app with that take care of the problem?

Any suggestions will be appreciated.

Update: I was able to find the search in the following file;

/opt/splunk/etc/apps/SplunkDeploymentMonitor/default/savedsearches.conf

But that's not where the Manager>Searches and Reports page is looking for it. Hmmm...

0 Karma
1 Solution

OldManEd
Builder

I could not find a suitable answer for this issue so I decided to simply remove the application completely. This eliminated all the associated scheduled searches that I was having issues with.

View solution in original post

0 Karma

OldManEd
Builder

I could not find a suitable answer for this issue so I decided to simply remove the application completely. This eliminated all the associated scheduled searches that I was having issues with.

0 Karma
Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Get the T-shirt to Prove You Survived Splunk University Bootcamp

As if Splunk University, in Las Vegas, in-person, with three days of bootcamps and labs weren’t enough, now ...

Wondering How to Build Resiliency in the Cloud?

IT leaders are choosing Splunk Cloud as an ideal cloud transformation platform to drive business resilience,  ...