All Apps and Add-ons

Splunk App for Microsoft Exchange: How to get the the app to pass all the prerequisites?

gomezcl
New Member

Hello,

I am new to splunk and i installed the Exchange App and got all the prerequisites done except the first one that asks for v6.2.0 I have the newest version installed but it will not pass the test since Key Value store must be enabled. I checked in the server.conf file and it is enabled so I'm not sure what else to do. Anyone know how to get the exchange app to pass all the prerequisites?


0 Karma

malmoore
Splunk Employee
Splunk Employee

I've seen this problem occur in test environments.

Are you running this in a nix environment? If so, this is likely a permissions issue, and if it is what I think it is, we might need to file a bug. It *might have been fixed in 6.2.1, so give that a try first.

Here's what's going on:

  1. KV store is enabled by default. The problem is, one of the files in the distribution has permissions that are too lax.
  2. When the KV store service starts up, it finds that this file has bad permissions, and then only fails with an error message to $SPLUNK_HOME/var/log/splunk/mongod.log:

    2014-12-18T15:39:43.555Z permissions on /opt/splunk-dash/var/lib/splunk/kvstore/mongo/splunk.key are too open

  3. In order to fix the problem and ensure that KV store is running, you need to change the permissions of this file so that the KV store service doesn't complain and not start.

To fix this:

From a shell (or Terminal window), issue

chmod 700 /opt/splunk/var/lib/splunk/kvstore/mongo/splunk.key

Restart Splunk and run the guided setup on the Exchange app again.

ChrisG
Splunk Employee
Splunk Employee

Wait...are you saying you are not running Splunk Enterprise 6.2? Or are you saying you are running 6.2.1?

0 Karma

gomezcl
New Member

Do you have a link to the download page? I just downloaded this 2 days ago. Not sure why i didn't get the latest download??

0 Karma

ChrisG
Splunk Employee
Splunk Employee

The download link is: http://www.splunk.com/download

6.2.1 was released yesterday. 🙂

0 Karma

ChrisG
Splunk Employee
Splunk Employee

Are you using a free license for Splunk Enterprise? There was a defect in 6.2.0 that KV store didn't work with the free license. That is fixed in 6.2.1.

gomezcl
New Member

Im running 6.2.0

0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...