Splunk Enterprise

Cannot edit the index setting. As Argument "coldPath_expanded" is not supported by this handler.

All-done-steak
Loves-to-Learn Lots

Cannot edit the index setting as it shows an error said "Argument "coldPath_expanded" is not supported by this handler".

Splunk Enterprise version: 8.2.4

 

Splunk1.JPG

Labels (1)
0 Karma

PickleRick
SplunkTrust
SplunkTrust

Since there is no such setting for indexes.conf there are two possible reasons.

1. Less likely - you have this setting set somewhere. Look for it with either find | grep or with splunk btool and remove

2. More likely - you hit some frontend issue and coldPath_expanded is a variable existing only on your browser's side for some strange reason. In such case it's probably a support case material.

0 Karma

VatsalJagani
SplunkTrust
SplunkTrust
Agreed, if it is UI issue, then go with Splunk support case.
0 Karma

VatsalJagani
SplunkTrust
SplunkTrust

@All-done-steak- Please check indexes.conf in the Splunk backend. There seems to be some issue with some config written in indexes.conf.

 

You can find indexes.conf files with find command in Linux:

find /opt/splunk -name "indexes.conf"

 

I hope this helps!!!

0 Karma
Get Updates on the Splunk Community!

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Shape the Future of Splunk: Join the Product Research Lab!

Join the Splunk Product Research Lab and connect with us in the Slack channel #product-research-lab to get ...