I'm doing some field extractions for a sourcetype and Splunk is saying the field has already been extracted. I went to the Splunk manager and clicked on the Field Extractions link. The page loads, but it's blank. The following error message is displayed:
In handler 'extractions': Admin handler 'extractions' not found.
Sounds more like a bug, or an attempt to do this on a light forwarder, than something easy to handle in answers. If it's a light forwarder, this isn't shocking. If not, we should probably work this via support, sorry.
Yeah, it's not a light forwarder. I'll create a case and upload a diag.