I'm trying to make a mirror copy of my Splunk 5.0.5 instance on a test instance to test a 6.1.3 upgrade. I'm trying to make a backup of the 5.0.5 Search Head configuration directory, "/opt/splunk/etc", with all the scheduled searches disabled so when I bring up the test instance, I won't get errors.
I've had no problems disabling most of the scheduled searches, except those associated with the Deployment Monitor application. When I try to disable any scheduled searches associated with the deployment app, I get the following error;
Error occurred attempting to disable DM indexthru week over week: In handler 'savedsearch': Data could not be written: /nobody/SplunkDeploymentMonitor/savedsearches/DM indexthru week over week/disabled: 1.
I searched for the directory above and could not find it. I then tried to disable the app, but could not accomplish that either.
Does anyone have any experience with this problem? If I delete the Deployment Monitor app with that take care of the problem?
Any suggestions will be appreciated.
Update: I was able to find the search in the following file;
/opt/splunk/etc/apps/SplunkDeploymentMonitor/default/savedsearches.conf
But that's not where the Manager>Searches and Reports page is looking for it. Hmmm...
I could not find a suitable answer for this issue so I decided to simply remove the application completely. This eliminated all the associated scheduled searches that I was having issues with.
I could not find a suitable answer for this issue so I decided to simply remove the application completely. This eliminated all the associated scheduled searches that I was having issues with.