Splunk IT Service Intelligence

ITSI - unable to delete correlation search with name in square brackets

abarneb
Explorer

I've created a couple of correlation searches using square brackets in the name(name format: [system name][environment][description]). I was able to create the searches and I see that they are picked up by the default aggregation policy. The problem is that I am not able to edit, disable or delete these correlations searches. Has anybody else experienced this issue and/or have a suggestion on how to remove these correlation searches?

Error message:
"Could not disable search. Status: 500 (Internal Server Error) Details:"

We are using ITSI versjon 3.0.1.

0 Karma

szhou_splunk
Splunk Employee
Splunk Employee

Version 3.0.1 is pretty old. Newer version(4.x) should have the issue.

0 Karma