Splunk Enterprise

SH cluster, can't delete objects

verbal_666
Builder

We recently turned a single SH into a 3 SHs Cluster.

Now we cannot manager some object, since we have not the "move" or "delete" actions...

Example, in savedsearch.config, we have many alerts (66), many of them, with same permission, managed by Admin, have not the "move" and "delete" icon in Actions, others have them in Web UI.

Splunk 6.4.3 build b03109c2bad4

Bug? Need an update? Is there a fix?

Thanks.

Tags (1)
0 Karma

skalliger
Motivator

It's not a problem of the cluster, but of your config location. Your files are stored under default, am I correct?
You can only delete or move objects via the GUI when they're stored under local.

Skalli

0 Karma

verbal_666
Builder

Need to verify it. Tomorrow i'll do. Maybe it's so! Tomorrow i'll verify and try a move of the objects with splunkd down. Thanks for now.

0 Karma

skalliger
Motivator

You're welcome. I hope that was the problem, keep us updated.

0 Karma

verbal_666
Builder

Had not time today to test. Also is a shared Environment, i can't shutdown processes as i want whenever i want 😉 i'll test it asap... the only thing i can say just now: we have surely many .conf divided in both default & local path; so i'll need also to merge them 😞 a big work... see asap... thanks

0 Karma

koshyk
Super Champion

it is not that simple to change a non-cluster SH to a cluster SH. Did you setup a deployer?
What i would do is to backup your configs, clean up all SH cluster members from scratch, set-it up and deploy from deployer using the backedup code.

0 Karma

verbal_666
Builder

I came now, with a "little" delay, in front of difference between Deployment & Deployer!!! 😐 😐 😐

So, we have a Deployment to distribuite apps to Forwarders. This is not the point.

And, YES, we have a Deployer to distribute apps to SHs, but still not working. So, the fact is here. Next step is to make the Deployer working.

Thanks. And sorry for the misunderstanding 🙂

0 Karma

verbal_666
Builder

Yes. We have 1 DS inside and 2 Indexers.

So, there no "easy fix"? I really didn't want just to backup all .conf, maybe join them, and redistribute 😞

But if it's the only solution... we approach the problem so...

Thanks.

0 Karma

verbal_666
Builder

Here's the Web UI example, to see...

alt text

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Defend at Machine Speed: Your Guide to Security Sessions at .conf26

Splunk .conf26   With threats moving at machine speed and attack surfaces expanding across hybrid ...

Where Innovation Takes Flight: The Splunk4Aviation Flight Sim Lands at .conf26

If you hear someone at .conf26 shouting "gear down, GEAR DOWN" across the show floor, you have found us.  The ...

Turn Cisco Telemetry Into Action with Cisco Data Fabric, powered by the Splunk ...

The surge in machine data is already hitting enterprise budgets, and the agentic era will only intensify it. ...