We just stood up a new Splunk Light instance, version 7.2.0. I created a search and then saved it as an alert. When I try to change it to anything aside from private, I get the following error message:
In handler 'savedsearch': Data could not be written:
/nobody/search/savedsearches/SplunkOnlyAlert/search:
host="usoms0090"
The host is the same as the Splunk instance itself.
Any suggestions on how to fix this issue?
This might be caused by files which are not owned by the splunk user.
For instance, if this applies to local.meta, you will get an error that metadata can not be written.