Splunk Enterprise Security

What is the difference between splunk_managment_console and splunk_monitoring_console?

scottrunyon
Contributor

After upgrade from 6.4.3 to 6.5.0, I am getting messages on my search head with Enterprise Security indicating duplicates -
"Search peer xxxxxxxx has the following message: Configuration file settings may be duplicated in multiple apps: stanza="DMC Alert - Abnormal State of Indexer Processor" file="savedsearches" apps="splunk_management_console,splunk_monitoring_console"
or
Search peer xxxxxxxx has the following message: Configuration file settings may be duplicated in multiple apps: stanza="DMC License Usage Data Cube" file="savedsearches" apps="splunk_monitoring_console,splunk_management_console"

If the configuration files are duplicate, which one is the valid one?

1 Solution

jcrabb_splunk
Splunk Employee
Splunk Employee

The DMC or "Distributed Management Console" was replaced by the "Monitoring Console" in 6.5. Similar functionality, with new additions/improvements in 6.5, but the app was renamed.

Jacob
Sr. Technical Support Engineer

View solution in original post

jcrabb_splunk
Splunk Employee
Splunk Employee

The DMC or "Distributed Management Console" was replaced by the "Monitoring Console" in 6.5. Similar functionality, with new additions/improvements in 6.5, but the app was renamed.

Jacob
Sr. Technical Support Engineer

scottrunyon
Contributor

Does that mean I can delete DMC from my systems?

0 Karma

jcrabb_splunk
Splunk Employee
Splunk Employee

Possibly. In my instance that I upgraded which contained the configured DMC for my deployment, the app was removed and the relevant user directories renamed to reflect the change to "monitoring console" as part of the migration process:

# $SPLUNK_HOME/var/log/splunk/migration.log.<date/time>


Renamed splunk_management_console directory for user: splunk-system-user to splunk_monitoring_console
Renamed splunk_management_console directory for user: admin to splunk_monitoring_console

Looking in my apps directory, I do not see "splunk_management_console". If you are managing that app through some deployment means, it may have put it back. In theory, you should be able to remove it but just double check that the monitoring console is working as expected, the migration log reflects updates to the user directories (if applicable) and make a copy of the "splunk_management_console" as a precaution. Once it is removed, restart the instance.

Jacob
Sr. Technical Support Engineer
0 Karma

scottrunyon
Contributor

Looking in the migration.log, the systems that still have DMC show "Failed cli cmd _py_internal" . I am renaming the directories, crossing my fingers and hoping this works.

Thanks for the quick response.

0 Karma
Get Updates on the Splunk Community!

Observability | Use Synthetic Monitoring for Website Metadata Verification

If you are on Splunk Observability Cloud, you may already have Synthetic Monitoringin your observability ...

More Ways To Control Your Costs With Archived Metrics | Register for Tech Talk

Tuesday, May 14, 2024  |  11AM PT / 2PM ET Register to Attend Join us for this Tech Talk and learn how to ...

.conf24 | Personalize your .conf experience with Learning Paths!

Personalize your .conf24 Experience Learning paths allow you to level up your skill sets and dive deeper ...