Splunk Search

Misconfigured view error after upgrade to 4.2.3

tasdienes
Engager

I upgraded from 4.2.2 to 4.2.3 (Windows). After the upgrade, this message appears in the top of my browser:

Misconfigured view 'search_ui_activity' - Unknown parameter 'suppressionList' is defined for module ViewstateAdapter. Make sure the parameter is specified in ViewstateAdapter.conf.

Anyone know what to do about that?

0 Karma
1 Solution

rroberts
Splunk Employee
Splunk Employee

Check your ViewstateAdapter.conf in $SPLUNK_HOME/share/splunk/search_mrsparkle/modules/results . Does it have a...

[param:suppressionList]

required = false

...stanza?

View solution in original post

araitz
Splunk Employee
Splunk Employee

My guess is that this is a problem with how Simple XML converts to Advanced XML. If you add "&showsource=1" to the end of the URL, you can grab the converted advanced XML, paste it into a new view, remove the suppressionList param for ViewstateAdapter, and then see if the issue goes away.

jdunlea_splunk
Splunk Employee
Splunk Employee

I did as you said, and added this stanza to the ViewstateAdapter.conf file, but even after restarting splunk i still get the error.

I am using advanced XML. Any ideas??

0 Karma

araitz
Splunk Employee
Splunk Employee

What view is this? Is this simple or advanced XML?

0 Karma

rroberts
Splunk Employee
Splunk Employee

Check your ViewstateAdapter.conf in $SPLUNK_HOME/share/splunk/search_mrsparkle/modules/results . Does it have a...

[param:suppressionList]

required = false

...stanza?

araitz
Splunk Employee
Splunk Employee

So was it simple or advanced XML? In other words, which view was this?

0 Karma

tasdienes
Engager

It did not. I added that, and the message went away. Thanks!

0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk on November 6 at 11AM PT, and empower your SOC to reach new heights! Duration: ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...