<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Is it possible to use the Splunk Add-on for Unix and Linux on Splunk Light without root access? in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Is-it-possible-to-use-the-Splunk-Add-on-for-Unix-and-Linux-on/m-p/166759#M15855</link>
    <description>&lt;P&gt;Okay, I wonder if something is gummed up with your licensing. Does the UI look like this?&lt;/P&gt;

&lt;P&gt;&lt;IMG src="http://i.imgur.com/lTQcdKk.png?1" alt="Splunk Light licensing" /&gt;&lt;BR /&gt;
(&lt;A href="http://imgur.com/lTQcdKk"&gt;http://imgur.com/lTQcdKk&lt;/A&gt;)&lt;/P&gt;

&lt;P&gt;Or is it the classic green Splunk Enterprise look?&lt;/P&gt;

&lt;P&gt;&lt;IMG src="http://i.imgur.com/HwpYf1y.png" alt="Splunk Enterprise licensing" /&gt;&lt;BR /&gt;
(&lt;A href="http://i.imgur.com/HwpYf1y"&gt;http://i.imgur.com/HwpYf1y&lt;/A&gt;)&lt;/P&gt;</description>
    <pubDate>Thu, 18 Jun 2015 18:05:05 GMT</pubDate>
    <dc:creator>ChrisG</dc:creator>
    <dc:date>2015-06-18T18:05:05Z</dc:date>
    <item>
      <title>Is it possible to use the Splunk Add-on for Unix and Linux on Splunk Light without root access?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Is-it-possible-to-use-the-Splunk-Add-on-for-Unix-and-Linux-on/m-p/166754#M15850</link>
      <description>&lt;P&gt;I'm using Splunk-Light, running it as a non-root user.  That part seems to be going fine so far, but I'm having trouble with the "Splunk Add-on for Unix and Linux".  When I try to enable something like cpu.sh and click save, it simply says that an error has occurred and to reload the page.  Reloading the page doesn't seem to make any difference.  I checked the splunk log at &lt;CODE&gt;$SPLUNK_HOME/var/log/splunk/splunkd.log&lt;/CODE&gt; but didn't see any errors there about my issue.  The log only notes that there is a "New scheduled exec process".&lt;/P&gt;

&lt;P&gt;Is this something that has to do with not having root access to the server?&lt;/P&gt;

&lt;P&gt;Is there somewhere else I should be looking for more information about this error?&lt;/P&gt;

&lt;P&gt;thanks!&lt;/P&gt;</description>
      <pubDate>Thu, 18 Jun 2015 16:03:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Is-it-possible-to-use-the-Splunk-Add-on-for-Unix-and-Linux-on/m-p/166754#M15850</guid>
      <dc:creator>neilnorman</dc:creator>
      <dc:date>2015-06-18T16:03:45Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to use the Splunk Add-on for Unix and Linux on Splunk Light without root access?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Is-it-possible-to-use-the-Splunk-Add-on-for-Unix-and-Linux-on/m-p/166755#M15851</link>
      <description>&lt;P&gt;Did you enable it from within Splunk Light (the Splunk Light Add-Ons page, as described here: &lt;A href="http://docs.splunk.com/Documentation/SplunkLight/6.2.3/GettingStarted/Configureanadd-ontoadddata"&gt;http://docs.splunk.com/Documentation/SplunkLight/6.2.3/GettingStarted/Configureanadd-ontoadddata&lt;/A&gt; ? or did you try to install and configure it manually?&lt;/P&gt;</description>
      <pubDate>Thu, 18 Jun 2015 16:29:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Is-it-possible-to-use-the-Splunk-Add-on-for-Unix-and-Linux-on/m-p/166755#M15851</guid>
      <dc:creator>ChrisG</dc:creator>
      <dc:date>2015-06-18T16:29:17Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to use the Splunk Add-on for Unix and Linux on Splunk Light without root access?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Is-it-possible-to-use-the-Splunk-Add-on-for-Unix-and-Linux-on/m-p/166756#M15852</link>
      <description>&lt;P&gt;I completely removed the app with the instructions from &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.2.3/Admin/Managingappobjects#Uninstall_an_app_or_add-on" target="_blank"&gt;http://docs.splunk.com/Documentation/Splunk/6.2.3/Admin/Managingappobjects#Uninstall_an_app_or_add-on&lt;/A&gt; . Then tried to install it from the web app, but get an error of&lt;/P&gt;

&lt;BLOCKQUOTE&gt;
&lt;P&gt;An error occurred while downloading&lt;BR /&gt;
the app: [HTTP 404]&lt;BR /&gt;
&lt;A href="https://127.0.0.1:8089/services/apps/remote/entriesbyid/Splunk_TA_nix" target="_blank"&gt;https://127.0.0.1:8089/services/apps/remote/entriesbyid/Splunk_TA_nix&lt;/A&gt;&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;</description>
      <pubDate>Mon, 28 Sep 2020 20:18:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Is-it-possible-to-use-the-Splunk-Add-on-for-Unix-and-Linux-on/m-p/166756#M15852</guid>
      <dc:creator>neilnorman</dc:creator>
      <dc:date>2020-09-28T20:18:57Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to use the Splunk Add-on for Unix and Linux on Splunk Light without root access?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Is-it-possible-to-use-the-Splunk-Add-on-for-Unix-and-Linux-on/m-p/166757#M15853</link>
      <description>&lt;P&gt;That is odd. If you are enabling it from within Splunk Light, it shouldn't need to go download it. This sounds more like the Splunk Enterprise workflow. So just to confirm one more time: you are using Splunk Light, not a Splunk Enterprise Trial, Splunk Free, or the free Splunk Cloud trial?&lt;/P&gt;</description>
      <pubDate>Thu, 18 Jun 2015 17:54:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Is-it-possible-to-use-the-Splunk-Add-on-for-Unix-and-Linux-on/m-p/166757#M15853</guid>
      <dc:creator>ChrisG</dc:creator>
      <dc:date>2015-06-18T17:54:34Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to use the Splunk Add-on for Unix and Linux on Splunk Light without root access?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Is-it-possible-to-use-the-Splunk-Add-on-for-Unix-and-Linux-on/m-p/166758#M15854</link>
      <description>&lt;P&gt;I started on an Splunk trial, then I got a trial license that made it Splunk Enterprise for a while. But we knew we'd be purchasing Splunk Light the whole time.  It says "Splunk Light" under the current license on the license page.&lt;/P&gt;</description>
      <pubDate>Thu, 18 Jun 2015 17:58:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Is-it-possible-to-use-the-Splunk-Add-on-for-Unix-and-Linux-on/m-p/166758#M15854</guid>
      <dc:creator>neilnorman</dc:creator>
      <dc:date>2015-06-18T17:58:23Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to use the Splunk Add-on for Unix and Linux on Splunk Light without root access?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Is-it-possible-to-use-the-Splunk-Add-on-for-Unix-and-Linux-on/m-p/166759#M15855</link>
      <description>&lt;P&gt;Okay, I wonder if something is gummed up with your licensing. Does the UI look like this?&lt;/P&gt;

&lt;P&gt;&lt;IMG src="http://i.imgur.com/lTQcdKk.png?1" alt="Splunk Light licensing" /&gt;&lt;BR /&gt;
(&lt;A href="http://imgur.com/lTQcdKk"&gt;http://imgur.com/lTQcdKk&lt;/A&gt;)&lt;/P&gt;

&lt;P&gt;Or is it the classic green Splunk Enterprise look?&lt;/P&gt;

&lt;P&gt;&lt;IMG src="http://i.imgur.com/HwpYf1y.png" alt="Splunk Enterprise licensing" /&gt;&lt;BR /&gt;
(&lt;A href="http://i.imgur.com/HwpYf1y"&gt;http://i.imgur.com/HwpYf1y&lt;/A&gt;)&lt;/P&gt;</description>
      <pubDate>Thu, 18 Jun 2015 18:05:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Is-it-possible-to-use-the-Splunk-Add-on-for-Unix-and-Linux-on/m-p/166759#M15855</guid>
      <dc:creator>ChrisG</dc:creator>
      <dc:date>2015-06-18T18:05:05Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to use the Splunk Add-on for Unix and Linux on Splunk Light without root access?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Is-it-possible-to-use-the-Splunk-Add-on-for-Unix-and-Linux-on/m-p/166760#M15856</link>
      <description>&lt;P&gt;I can't see your the picture you linked, but mine is the one that says "splunk&amp;gt;light" and is a sort of orange color.  I think you might be right though. Manage accounts says that I am licensed for 4294967295 accounts.  IIRC Splunk Light only allows 5.&lt;/P&gt;</description>
      <pubDate>Thu, 18 Jun 2015 18:35:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Is-it-possible-to-use-the-Splunk-Add-on-for-Unix-and-Linux-on/m-p/166760#M15856</guid>
      <dc:creator>neilnorman</dc:creator>
      <dc:date>2015-06-18T18:35:45Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to use the Splunk Add-on for Unix and Linux on Splunk Light without root access?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Is-it-possible-to-use-the-Splunk-Add-on-for-Unix-and-Linux-on/m-p/166761#M15857</link>
      <description>&lt;P&gt;Okay splunk &amp;gt; light and orange is definitely Splunk Light. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; Sorry about the issue with my images and links, I have reported it to the Splunk Answers team.&lt;/P&gt;

&lt;P&gt;So you might have a licensing issue, which might or might not be related to your original question. The Unix add-on ships with Splunk Light and you should be able to enable it locally, without download. If you have a Support agreement in place, I suggest you file a case for this one, because there might be a couple of intertwined issues.&lt;/P&gt;</description>
      <pubDate>Thu, 18 Jun 2015 18:43:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Is-it-possible-to-use-the-Splunk-Add-on-for-Unix-and-Linux-on/m-p/166761#M15857</guid>
      <dc:creator>ChrisG</dc:creator>
      <dc:date>2015-06-18T18:43:41Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to use the Splunk Add-on for Unix and Linux on Splunk Light without root access?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Is-it-possible-to-use-the-Splunk-Add-on-for-Unix-and-Linux-on/m-p/166762#M15858</link>
      <description>&lt;P&gt;typically, in a case like this, i try to run the script by hand w/the effective UID of the same user that owns the splunkd process. If the script(s) are having problems running as non-root (or otherwise), there should be some indication in STDOUT, if not, then splunkd.log should contain some info.&lt;/P&gt;</description>
      <pubDate>Tue, 11 Oct 2016 20:42:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Is-it-possible-to-use-the-Splunk-Add-on-for-Unix-and-Linux-on/m-p/166762#M15858</guid>
      <dc:creator>jterry</dc:creator>
      <dc:date>2016-10-11T20:42:09Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to use the Splunk Add-on for Unix and Linux on Splunk Light without root access?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Is-it-possible-to-use-the-Splunk-Add-on-for-Unix-and-Linux-on/m-p/643672#M79158</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;&lt;BR /&gt;I will be putting this reply to the posts that I can find.&amp;nbsp; I know it's a late reply to some. But hope this will help you all.&amp;nbsp; And anyone having similar issues in the future.&lt;BR /&gt;&lt;BR /&gt;The issue I will be discussing here is when Splunk update does NOT update from Splunk Web. And when you search for the error you find similar to this:&lt;BR /&gt;&lt;EM&gt;splunk.ResourceNotFound:&amp;nbsp;[HTTP&amp;nbsp;404]&lt;BR /&gt;&lt;/EM&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Explanation on how really it works:&lt;/P&gt;&lt;P&gt;When you try to update the app Splunk Web makes a call to itself 127.0.0.1 on port 8089 for SplunkD&amp;nbsp;&amp;nbsp; at /services/apps/remote/entriesbyid/&amp;lt;your_app&amp;gt; e.g. -&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;A href="https://127.0.0.1:8089/services/apps/remote/entriesbyid/Splunk_TA_windows" target="_blank"&gt;https://127.0.0.1:8089/services/apps/remote/entriesbyid/Splunk_TA_windows&lt;/A&gt;&lt;/P&gt;&lt;P&gt;which you can check yourself by simple CURL:&lt;/P&gt;&lt;P&gt;curl -k --user "admin:changeme" &lt;A href="https://127.0.0.1:8089/services/apps/remote/entriesbyid/Splunk_TA_windows" target="_blank"&gt;https://127.0.0.1:8089/services/apps/remote/entriesbyid/Splunk_TA_windows&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This call is getting proxied via SplunkD process to the internet which would end up calling&amp;nbsp; &lt;A href="https://splunkbase.splunk.com/api/apps/entriesbyid/%3cyour_app%3e" target="_blank"&gt;https://splunkbase.splunk.com/api/apps/entriesbyid/&amp;lt;your_app&amp;gt;&lt;/A&gt;&lt;BR /&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;which you can check yourself by simple CURL:&lt;/P&gt;&lt;P&gt;curl -k&amp;nbsp; &lt;A href="https://splunkbase.splunk.com/api/apps/entriesbyid/Splunk_TA_windows" target="_blank"&gt;https://splunkbase.splunk.com/api/apps/entriesbyid/Splunk_TA_windows&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Now the issues here can be numerous from here on. To give some examples:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Splunk has issues accessing internet from SplunkD process&lt;/LI&gt;&lt;LI&gt;Certificate chain was changed. By default it is configured in server.conf&lt;BR /&gt;[applicationsManagement]&lt;BR /&gt;sslVerifyServerCert = false&lt;/LI&gt;&lt;LI&gt;Proxy and/or Firewall in the middle which is changing certificates.&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;One of the ways you can check for networking issues for that is do a tcpdump for packet capture and check the SSL Conversation:&lt;BR /&gt;tcpdump -i &amp;lt;interface&amp;gt; -s 65535 port 443 -w /tmp/port443.pcap&lt;BR /&gt;&lt;BR /&gt;That's for people who are familiar what packet capture looks like and can understand it's contents.&lt;/P&gt;</description>
      <pubDate>Wed, 17 May 2023 15:50:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Is-it-possible-to-use-the-Splunk-Add-on-for-Unix-and-Linux-on/m-p/643672#M79158</guid>
      <dc:creator>dtsariapkin</dc:creator>
      <dc:date>2023-05-17T15:50:33Z</dc:date>
    </item>
  </channel>
</rss>

