Monitoring Splunk

Why am I getting errors when I try to disable scheduled searches associated with Deployment Monitor app?

OldManEd
Builder

I'm trying to make a mirror copy of my Splunk 5.0.5 instance on a test instance to test a 6.1.3 upgrade. I'm trying to make a backup of the 5.0.5 Search Head configuration directory, "/opt/splunk/etc", with all the scheduled searches disabled so when I bring up the test instance, I won't get errors.

I've had no problems disabling most of the scheduled searches, except those associated with the Deployment Monitor application. When I try to disable any scheduled searches associated with the deployment app, I get the following error;

Error occurred attempting to disable DM indexthru week over week: In handler 'savedsearch': Data could not be written: /nobody/SplunkDeploymentMonitor/savedsearches/DM indexthru week over week/disabled: 1.

I searched for the directory above and could not find it. I then tried to disable the app, but could not accomplish that either.

Does anyone have any experience with this problem? If I delete the Deployment Monitor app with that take care of the problem?

Any suggestions will be appreciated.

Update: I was able to find the search in the following file;

/opt/splunk/etc/apps/SplunkDeploymentMonitor/default/savedsearches.conf

But that's not where the Manager>Searches and Reports page is looking for it. Hmmm...

0 Karma
1 Solution

OldManEd
Builder

I could not find a suitable answer for this issue so I decided to simply remove the application completely. This eliminated all the associated scheduled searches that I was having issues with.

View solution in original post

0 Karma

OldManEd
Builder

I could not find a suitable answer for this issue so I decided to simply remove the application completely. This eliminated all the associated scheduled searches that I was having issues with.

0 Karma
Get Updates on the Splunk Community!

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...

Tech Talk | Elevating Digital Service Excellence: The Synergy of Splunk RUM & APM

Elevating Digital Service Excellence: The Synergy of Real User Monitoring and Application Performance ...