Splunk IT Service Intelligence

ITSI - unable to delete correlation search with name in square brackets


I've created a couple of correlation searches using square brackets in the name(name format: [system name][environment][description]). I was able to create the searches and I see that they are picked up by the default aggregation policy. The problem is that I am not able to edit, disable or delete these correlations searches. Has anybody else experienced this issue and/or have a suggestion on how to remove these correlation searches?

Error message:
"Could not disable search. Status: 500 (Internal Server Error) Details:"

We are using ITSI versjon 3.0.1.

0 Karma

Splunk Employee
Splunk Employee

Version 3.0.1 is pretty old. Newer version(4.x) should have the issue.

0 Karma
Did you miss .conf21 Virtual?

Good news! The event's keynotes and many of its breakout sessions are now available online, and still totally FREE!