It doesn't fix my issue. The support has provided some workaroud: useAck = false [queue] maxSize = 100MB But all those don't help my at all. Please let me know if you guys have any solutions. Tks. Linh
... View more
I got similar issue after upgrading 8.2.7. I have tried to set: useAck=false disable app Splunk...Forwarders chown -R splunk:splunk /opt/splunk but the problem is still there.
... View more
- SSH to search head. - Go to app folder location .../etc/app/<name>/default - Open savedsearches.conf - Copy search query using that index - Add that search savedsearches.conf in ../etc/app/<name>/local - Add disabled = 1 - Restart That is how I solved it by disabling the search query.
... View more
Hi @woodcock , I received this error when I run | inputlookup windows_app The following error(s) occurred while the search ran. Therefore, search results might be incomplete. The lookup table 'windows_apps' requires a .csv or KV store lookup definition. The lookup table 'windows_apps' is invalid. Do you think what is missing? I run from the search head. Tks Linh.
... View more
Hi. I am upgrading from 8.1.0 to 8.2.1. I received the bundle replication issue as below: Problem replicating config (bundle) to search peer ' 10.150.x.x:8089 ', Upload bundle="/opt/splunk/var/run/SHD01-1625054310.bundle" to peer name=IND01 uri=https://10.150.x.x:8089 failed; http_status=409 http_description="Conflict". I received an error for each member of indexer cluster. My search head is a standalone server. Could anyone please help? Linh
... View more