Splunk Enterprise Security

What is the difference between splunk_managment_console and splunk_monitoring_console?

scottrunyon
Contributor

After upgrade from 6.4.3 to 6.5.0, I am getting messages on my search head with Enterprise Security indicating duplicates -
"Search peer xxxxxxxx has the following message: Configuration file settings may be duplicated in multiple apps: stanza="DMC Alert - Abnormal State of Indexer Processor" file="savedsearches" apps="splunk_management_console,splunk_monitoring_console"
or
Search peer xxxxxxxx has the following message: Configuration file settings may be duplicated in multiple apps: stanza="DMC License Usage Data Cube" file="savedsearches" apps="splunk_monitoring_console,splunk_management_console"

If the configuration files are duplicate, which one is the valid one?

1 Solution

jcrabb_splunk
Splunk Employee
Splunk Employee

The DMC or "Distributed Management Console" was replaced by the "Monitoring Console" in 6.5. Similar functionality, with new additions/improvements in 6.5, but the app was renamed.

Jacob
Sr. Technical Support Engineer

View solution in original post

jcrabb_splunk
Splunk Employee
Splunk Employee

The DMC or "Distributed Management Console" was replaced by the "Monitoring Console" in 6.5. Similar functionality, with new additions/improvements in 6.5, but the app was renamed.

Jacob
Sr. Technical Support Engineer

scottrunyon
Contributor

Does that mean I can delete DMC from my systems?

0 Karma

jcrabb_splunk
Splunk Employee
Splunk Employee

Possibly. In my instance that I upgraded which contained the configured DMC for my deployment, the app was removed and the relevant user directories renamed to reflect the change to "monitoring console" as part of the migration process:

# $SPLUNK_HOME/var/log/splunk/migration.log.<date/time>


Renamed splunk_management_console directory for user: splunk-system-user to splunk_monitoring_console
Renamed splunk_management_console directory for user: admin to splunk_monitoring_console

Looking in my apps directory, I do not see "splunk_management_console". If you are managing that app through some deployment means, it may have put it back. In theory, you should be able to remove it but just double check that the monitoring console is working as expected, the migration log reflects updates to the user directories (if applicable) and make a copy of the "splunk_management_console" as a precaution. Once it is removed, restart the instance.

Jacob
Sr. Technical Support Engineer
0 Karma

scottrunyon
Contributor

Looking in the migration.log, the systems that still have DMC show "Failed cli cmd _py_internal" . I am renaming the directories, crossing my fingers and hoping this works.

Thanks for the quick response.

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...