Splunk IT Service Intelligence

ITSI - unable to delete correlation search with name in square brackets

abarneb
Explorer

I've created a couple of correlation searches using square brackets in the name(name format: [system name][environment][description]). I was able to create the searches and I see that they are picked up by the default aggregation policy. The problem is that I am not able to edit, disable or delete these correlations searches. Has anybody else experienced this issue and/or have a suggestion on how to remove these correlation searches?

Error message:
"Could not disable search. Status: 500 (Internal Server Error) Details:"

We are using ITSI versjon 3.0.1.

0 Karma

szhou_splunk
Splunk Employee
Splunk Employee

Version 3.0.1 is pretty old. Newer version(4.x) should have the issue.

0 Karma
Get Updates on the Splunk Community!

Devesh Logendran, Splunk, and the Singapore Cyber Conquest

At this year’s Splunk University, I had the privilege of chatting with Devesh Logendran, one of the winners in ...

There's No Place Like Chrome and the Splunk Platform

WATCH NOW!Malware. Risky Extensions. Data Exfiltration. End-users are increasingly reliant on browsers to ...

Customer Experience | Join the Customer Advisory Board!

Are you ready to take your Splunk journey to the next level? 🚀 We invite you to join our elite squad ...