Security

Why am I unable to delete calculated fields from Splunk Web?

akawacz
Path Finder

Hi

I am having an issue with deleting/editing calculated fields in Splunk Web. Any idea, how I can remove these two?

The name is like this:

csv : EVALTYPE : EVAL A
csv : EVALTYPE : EVAL B

They are for different field names and have the same eval expression.

I think Splunk does not like the use of : two times because I have created a third calculated filed with only one : and was able to remove it easily.

Error I am getting:
Deleting:

Error occurred attempting to remove csv : EVALTYPE : EVALTYPE: In handler 'props-eval': Object 'csv : EVALTYPE : EVALTYPE' does not exist in user=aaa, app=bbb: props.conf [csv] EVALTYPE : EVALTYPE.

Changing permission:

Splunk could not update permissions for resource data/props/calcfields [HTTP 409] [{'type': 'ERROR', 'code': None, 'text': 'No eligible entity'}]

Editing:

Encountered the following error while trying to update: In handler 'props-eval': Object 'csv : EVALTYPE : EVALTYPE' does not exist in user=aaa, app=bbb: props.conf [rnw-csv] EVALTYPE : EVALTYPE

thank you

0 Karma
1 Solution

woodcock
Esteemed Legend

Open a support case to report the bug and manually edit the props.conf file with CLI.

View solution in original post

0 Karma

woodcock
Esteemed Legend

Open a support case to report the bug and manually edit the props.conf file with CLI.

0 Karma

layamba
Explorer

Did anyone ever open a support case to report this? I just had same issue with 7.0.0.

0 Karma
Get Updates on the Splunk Community!

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer at Splunk .conf24 ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...