Deployment Architecture

splunk validate cluster-bundle fails with "no spec file" but spec exists

droth333
Explorer

Hi!
Why on splunk validate cluster-bundle do I get these errors:

No spec file for: /opt/splunk/etc/master-apps/SA-ldapsearch/local/ldap.conf
No spec file for: /opt/splunk/etc/master-apps/SA-ldapsearch/default/ldap.conf
No spec file for: /opt/splunk/etc/master-apps/SA-ldapsearch/default/logging.conf
No spec file for: /opt/splunk/etc/master-apps/SA-ldapsearch/default/ssl.conf

But the corresponding apps README has:

[splunk@scsplunkdeploy1 README]$ ls -l
total 16
-rwxrwxr-x 1 splunk splunk 3971 Nov 4 11:58 ldap.conf.spec
-rwxrwxr-x 1 splunk splunk 5616 Nov 4 11:58 logging.conf.spec
-rwxrwxr-x 1 splunk splunk 1588 Nov 4 11:58 ssl.conf.spec

How do I fix this?

Thanks,
Dave

0 Karma

jkat54
SplunkTrust
SplunkTrust

Seems awkward. What happens if you remove the spec files? I have a suspicion the warning goes away. In either case it doesn't matter and can be ignored.

0 Karma
Get Updates on the Splunk Community!

Introducing Splunk Enterprise 9.2

WATCH HERE! Watch this Tech Talk to learn about the latest features and enhancements shipped in the new Splunk ...

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...