All Apps and Add-ons

Deploying Splunk_TA_Windows Add-on to Cluster Errors With "No Spec File"

snowmizer
Communicator

I am trying to deploy the latest version of the Splunk_TA_Windows Add-on (from July 30, 2014) to my cluster. When I deploy the bundle I get the messages:

TSTSplunkCM01.int.hlc.com:No spec file for: /opt/splunk/etc/master-apps/Splunk_TA_windows/default/admon.conf

TSTSplunkCM01.int.hlc.com:No spec file for: /opt/splunk/etc/master-apps/Splunk_TA_windows/default/eventgen.conf

...

This same error shows up for the perfmon.conf, regmon-filters.conf, paletteinputs.conf, palettepallettes.conf, palettepanels.conf, palettesearches.conf and splunk_msftapp.conf. These errors prevent the configuration bundle from being distributed.

Has anyone else seen this message and how did you fix it?

Thanks.

alt text

1 Solution

snowmizer
Communicator

Actually we figured out that the problem was the "Invalid key..." message from the inputs.conf file. Once I commented out these lines in the default inputs.conf file all messages disappeared.

View solution in original post

snowmizer
Communicator

Actually we figured out that the problem was the "Invalid key..." message from the inputs.conf file. Once I commented out these lines in the default inputs.conf file all messages disappeared.

pwmcity
Path Finder

Hey I'm having the exact same issues
(http://answers.splunk.com/answers/154933/no-spec-file-and-invalid-key-in-stanza-when-pushing-windows...)

Are you saying that once you comment out the invalid stanza keys (useEnglishOnly) in the default\inputs.conf (which are disabled anyway), then the other errors (no spec file) are ignored and the apps push to the cluster?

I'm just trying to figure out the minimum changes required to the default app (to preserve upgrade path) that it will deploy without errors.

0 Karma

RicoSuave
Builder

Have you checked your indexers in the cluster to make sure it did not get pushed out? Usually we will just warn about typos in conf files though this shouldn't prevent a bundle from being pushed out.

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...