Splunk Enterprise

SmartStore with HCP - why does delete fail?

lmichalski_2
Explorer

Hi,

Did anyone succeeded with configuring Splunk with HCP?
CacheManager is able to upload and download buckets - it works perfectly.

 

But every time Splunk tries to freeze bucket, transaction fails with error 501 (not implemented).
The same if I try to do it from splunk CLI to manually remove bucket/file.

WARN S3Client - command=remove transactionId=0x7fb4332dXXXX rTxnId=0x7fb427bfXXXX status=completed success=N uri=https://splunk.XXXXXXXXXXX.com.pl/buckets/test/db/d7/cd/66~7FD81528-13C4-4063-A45C-26DE9D698D42/rece... statusCode=501 statusDescription="Not Implemented" payload="<?xml version='1.0' encoding='UTF-8'?>\n<Error>\n <Code>NotImplemented</Code>\n <Message>Only the current version of an object can be deleted.</Message>\n <RequestId>160104XXXXX31</RequestId>\n <HostId>aGNwLXIuYmXXXXXXXXXXXXXMTA4</HostId>\n</Error>\n\n"

We tried to disable and enable versioning on HCP, does not help.

Had anyone such issue? What additional is needed to configure on HCP or Splunk.

Labels (1)
0 Karma

Nisha18789
Builder

hello @lmichalski_2 , could you please advise if you were able to make the delete work? We are facing exactly the same problem. Any help is much appreciated.

Tags (1)
0 Karma

lmichalski_2
Explorer

Hello!

Please add 

remote.s3.supports_versioning = false

to server.conf and restart Splunk.

You can disable versioning on HCP only if you have 1 standalone indexer.
In distributed environment do not disable versioning on HCP!

Nisha18789
Builder

thanks @lmichalski_2 , we actually have a distributed environment, so in case case shall we add 

remote.s3.supports_versioning = true

in server.conf and restart? 

0 Karma

lmichalski_2
Explorer

Yes, push it from Cluster Master (or eventually: put on every search peer in system/local/server.conf).

Do not try to disable versioning on HCP.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Supercharging Windows Security Detection Performance: Introducing Hybrid Field ...

Windows event logs—from Security auditing and Sysmon to PowerShell script blocks—form the operational backbone ...

Ditch the Manual Grind: Building AI Agents with Splunk

Ditch the Manual Grind: Building AI Agents with Splunk Let’s be real: your team’s time is being eaten alive. ...

Cisco Data Fabric from Architecture to Investigation, Better SOC Visibility, and More ...

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...