Splunk Enterprise

Cannot edit the index setting. As Argument "coldPath_expanded" is not supported by this handler.

All-done-steak
Loves-to-Learn Lots

Cannot edit the index setting as it shows an error said "Argument "coldPath_expanded" is not supported by this handler".

Splunk Enterprise version: 8.2.4

 

Splunk1.JPG

Labels (1)
0 Karma

PickleRick
SplunkTrust
SplunkTrust

Since there is no such setting for indexes.conf there are two possible reasons.

1. Less likely - you have this setting set somewhere. Look for it with either find | grep or with splunk btool and remove

2. More likely - you hit some frontend issue and coldPath_expanded is a variable existing only on your browser's side for some strange reason. In such case it's probably a support case material.

0 Karma

VatsalJagani
SplunkTrust
SplunkTrust
Agreed, if it is UI issue, then go with Splunk support case.
0 Karma

VatsalJagani
SplunkTrust
SplunkTrust

@All-done-steak- Please check indexes.conf in the Splunk backend. There seems to be some issue with some config written in indexes.conf.

 

You can find indexes.conf files with find command in Linux:

find /opt/splunk -name "indexes.conf"

 

I hope this helps!!!

0 Karma
Get Updates on the Splunk Community!

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...

Purpose in Action: How Splunk Is Helping Power an Inclusive Future for All

At Cisco, purpose isn’t a tagline—it’s a commitment. Cisco’s FY25 Purpose Report outlines how the company is ...

[Upcoming Webinar] Demo Day: Transforming IT Operations with Splunk

Join us for a live Demo Day at the Cisco Store on January 21st 10:00am - 11:00am PST In the fast-paced world ...