Splunk Enterprise

SH cluster, can't delete objects

verbal_666
Builder

We recently turned a single SH into a 3 SHs Cluster.

Now we cannot manager some object, since we have not the "move" or "delete" actions...

Example, in savedsearch.config, we have many alerts (66), many of them, with same permission, managed by Admin, have not the "move" and "delete" icon in Actions, others have them in Web UI.

Splunk 6.4.3 build b03109c2bad4

Bug? Need an update? Is there a fix?

Thanks.

Tags (1)
0 Karma

skalliger
Motivator

It's not a problem of the cluster, but of your config location. Your files are stored under default, am I correct?
You can only delete or move objects via the GUI when they're stored under local.

Skalli

0 Karma

verbal_666
Builder

Need to verify it. Tomorrow i'll do. Maybe it's so! Tomorrow i'll verify and try a move of the objects with splunkd down. Thanks for now.

0 Karma

skalliger
Motivator

You're welcome. I hope that was the problem, keep us updated.

0 Karma

verbal_666
Builder

Had not time today to test. Also is a shared Environment, i can't shutdown processes as i want whenever i want 😉 i'll test it asap... the only thing i can say just now: we have surely many .conf divided in both default & local path; so i'll need also to merge them 😞 a big work... see asap... thanks

0 Karma

koshyk
Super Champion

it is not that simple to change a non-cluster SH to a cluster SH. Did you setup a deployer?
What i would do is to backup your configs, clean up all SH cluster members from scratch, set-it up and deploy from deployer using the backedup code.

0 Karma

verbal_666
Builder

I came now, with a "little" delay, in front of difference between Deployment & Deployer!!! 😐 😐 😐

So, we have a Deployment to distribuite apps to Forwarders. This is not the point.

And, YES, we have a Deployer to distribute apps to SHs, but still not working. So, the fact is here. Next step is to make the Deployer working.

Thanks. And sorry for the misunderstanding 🙂

0 Karma

verbal_666
Builder

Yes. We have 1 DS inside and 2 Indexers.

So, there no "easy fix"? I really didn't want just to backup all .conf, maybe join them, and redistribute 😞

But if it's the only solution... we approach the problem so...

Thanks.

0 Karma

verbal_666
Builder

Here's the Web UI example, to see...

alt text

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas

Watch Now Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas     Do you ever feel ...

Build and Launch AI Agents from Your Splunk Workflows

Replay Tech Talk Build and Launch AI Agents from Your Splunk Workflows     We’ve all been there: juggling ...

index This | What kind of room has no doors?

IndexEducation Cover Art Banner Cisco.png August 2026 Edition  Hayyy Splunk Education Enthusiasts and the ...