<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk Entreprise Max Upload issue in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Entreprise-Max-Upload-issue/m-p/754794#M23350</link>
    <description>&lt;P&gt;Depends on what you mean by "disk". Data? Config? Generally this boils more or less to "install and restore config/data" and will have more or less the same result.&lt;/P&gt;</description>
    <pubDate>Mon, 27 Oct 2025 12:19:48 GMT</pubDate>
    <dc:creator>PickleRick</dc:creator>
    <dc:date>2025-10-27T12:19:48Z</dc:date>
    <item>
      <title>Splunk Entreprise Max Upload issue</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Entreprise-Max-Upload-issue/m-p/754480#M23273</link>
      <description>&lt;P&gt;Hello Folks,&lt;/P&gt;&lt;P&gt;I am currently using Splunk Entreprise&lt;SPAN&gt;10.0.0 on ubuntu , I am trying to upload an app manually but it told me that the max upload is 512 Mb , i changed the value in web.conf to from 500 to 2000 , restart the service.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I run :&amp;nbsp;/opt/splunk/bin/splunk btool web list settings | grep max_upload , and it returns&amp;nbsp;max_upload_size = 2000 .&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;But when i try uploading again , it gives me the same error. Any idea plese.&lt;/P&gt;&lt;P&gt;Thank you in advance for your help&lt;/P&gt;</description>
      <pubDate>Mon, 20 Oct 2025 10:49:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Entreprise-Max-Upload-issue/m-p/754480#M23273</guid>
      <dc:creator>fedayn05</dc:creator>
      <dc:date>2025-10-20T10:49:15Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Entreprise Max Upload issue</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Entreprise-Max-Upload-issue/m-p/754481#M23274</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/313418"&gt;@fedayn05&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can you please confirm the size of the app your are trying to install? Its definitely smaller than 2000mb right?&amp;nbsp;&lt;/P&gt;&lt;P&gt;What is the specific error returned? Is there also a more detailed error in $SPLUNK_HOME/var/log/splunk/splunkd.log ?&lt;/P&gt;&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":glowing_star:"&gt;🌟&lt;/span&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Did this answer help you?&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;If so, please consider:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Adding karma to show it was useful&lt;/LI&gt;&lt;LI&gt;Marking it as the solution if it resolved your issue&lt;/LI&gt;&lt;LI&gt;Commenting if you need any clarification&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Your feedback encourages the volunteers in this community to continue contributing&lt;/P&gt;</description>
      <pubDate>Mon, 20 Oct 2025 11:18:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Entreprise-Max-Upload-issue/m-p/754481#M23274</guid>
      <dc:creator>livehybrid</dc:creator>
      <dc:date>2025-10-20T11:18:28Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Entreprise Max Upload issue</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Entreprise-Max-Upload-issue/m-p/754484#M23277</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Thaank you for your response , the&amp;nbsp; size of the app is around 800mb , i just set 2000mb as a choice , the error was "&amp;nbsp;Upload failed: Package is too large, must be less than 512 MB&lt;SPAN&gt;",&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I tried to see if an error is produced on splnkd.log , but nothing got out of it .&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thank you&lt;/SPAN&gt;&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;</description>
      <pubDate>Mon, 20 Oct 2025 12:56:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Entreprise-Max-Upload-issue/m-p/754484#M23277</guid>
      <dc:creator>fedayn05</dc:creator>
      <dc:date>2025-10-20T12:56:00Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Entreprise Max Upload issue</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Entreprise-Max-Upload-issue/m-p/754489#M23280</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;1. Verifiy the configuration&amp;nbsp;web.conf&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;SPAN&gt;[settings]&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;max_upload_size = 2000&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;2. Restart Splunk&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;3. Verify configuration in the memory&lt;BR /&gt;&lt;BR /&gt;/opt/splunk/bin/splunk show config web | grep max_upload_size&lt;BR /&gt;&lt;BR /&gt;4. Try upload the file Now.&lt;BR /&gt;&lt;BR /&gt;Thank you!&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 20 Oct 2025 15:26:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Entreprise-Max-Upload-issue/m-p/754489#M23280</guid>
      <dc:creator>vjdev</dc:creator>
      <dc:date>2025-10-20T15:26:02Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Entreprise Max Upload issue</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Entreprise-Max-Upload-issue/m-p/754490#M23281</link>
      <description>&lt;P&gt;Hello vjdev,&lt;/P&gt;&lt;P&gt;1- The web.conf returns :&amp;nbsp;&lt;SPAN&gt;max_upload_size = 2000&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;2- i did restart splunk (both via CLI and GUI)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;3- i run this&amp;nbsp;/opt/splunk/bin/splunk show config web | grep max_upload_size and it returns&amp;nbsp;max_upload_size = 2000&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;So i really do not know if this is a bug or another config somewhere is overatting the web.conf file&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thank you for your response&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 20 Oct 2025 16:07:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Entreprise-Max-Upload-issue/m-p/754490#M23281</guid>
      <dc:creator>fedayn05</dc:creator>
      <dc:date>2025-10-20T16:07:31Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Entreprise Max Upload issue</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Entreprise-Max-Upload-issue/m-p/754491#M23282</link>
      <description>&lt;P&gt;What is your environment? Are you sure you're changing the settings on the right component? (yes I know it's a very basic question but sometimes we miss the obvious)&lt;/P&gt;</description>
      <pubDate>Mon, 20 Oct 2025 16:30:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Entreprise-Max-Upload-issue/m-p/754491#M23282</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2025-10-20T16:30:19Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Entreprise Max Upload issue</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Entreprise-Max-Upload-issue/m-p/754497#M23284</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/313418"&gt;@fedayn05&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is very odd, if you've run&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;/opt/splunk/bin/splunk btool web list settings | grep max_upload_size&lt;/LI-CODE&gt;&lt;P&gt;then it would confirm that it the max_upload_size is in the correct stanza (settings) in the correct file (web.conf) and its not commented out or mis-spelt.&lt;/P&gt;&lt;P&gt;Just to check&amp;nbsp; - its just plain-old 2000 right? not 2000MB or 2000mb&lt;/P&gt;&lt;P&gt;Can I also confirm that you are running Splunk on Linux?&amp;nbsp;&lt;/P&gt;&lt;P&gt;Which version are you on?&amp;nbsp;&lt;/P&gt;&lt;P&gt;Im suspecting there may be an issue with 10.0.x here but trying to rule things out. Also - the default is 500 not 512 so makes me wonder if there is another setting somewhere??&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":glowing_star:"&gt;🌟&lt;/span&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Did this answer help you?&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;If so, please consider:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Adding karma to show it was useful&lt;/LI&gt;&lt;LI&gt;Marking it as the solution if it resolved your issue&lt;/LI&gt;&lt;LI&gt;Commenting if you need any clarification&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Your feedback encourages the volunteers in this community to continue contributing&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 20 Oct 2025 19:17:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Entreprise-Max-Upload-issue/m-p/754497#M23284</guid>
      <dc:creator>livehybrid</dc:creator>
      <dc:date>2025-10-20T19:17:39Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Entreprise Max Upload issue</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Entreprise-Max-Upload-issue/m-p/754499#M23285</link>
      <description>&lt;P&gt;Okay&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/313418"&gt;@fedayn05&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Ive been down a rabbit hole on this one and found that the 512mb limit is hard-coded in the UI component in &amp;gt;= 10.0.0&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="livehybrid_0-1760989307640.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/40587i164F7859B5092A2F/image-size/medium?v=v2&amp;amp;px=400" role="button" title="livehybrid_0-1760989307640.png" alt="livehybrid_0-1760989307640.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;I was testing uploading of ES 8.x on a local Splunk 10.0.1 install and found the same issue you had which led me to this.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Are you also trying to install ES8? I discovered&amp;nbsp;SPL-282727 which relates to ES8 not being installable via the Web UI in Splunk 10.x (See&amp;nbsp;&amp;nbsp;&lt;A href="https://help.splunk.com/en/splunk-enterprise-security-8/release-notes-and-resources/8.2/splunk-enterprise-security-release-notes/known-issues" target="_blank" rel="noopener"&gt;https://help.splunk.com/en/splunk-enterprise-security-8/release-notes-and-resources/8.2/splunk-enterprise-security-release-notes/known-issues&lt;/A&gt;&amp;nbsp;) and&amp;nbsp;&lt;A href="https://help.splunk.com/en/splunk-enterprise-security-8/release-notes-and-resources/8.2/splunk-enterprise-security-release-notes/release-notes-for-splunk-enterprise-security" target="_blank" rel="noopener"&gt;https://help.splunk.com/en/splunk-enterprise-security-8/release-notes-and-resources/8.2/splunk-enterprise-security-release-notes/release-notes-for-splunk-enterprise-security&lt;/A&gt;&amp;nbsp;also states&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;You cannot upload Splunk Enterprise Security 8.x on an on-premises deployment of Splunk Enterprise 10.x using the UI. You must install Splunk Enterprise Security 8.x using the command line.&lt;/LI-CODE&gt;&lt;P&gt;So the bottom line is that this is a bug - whilst the above is specific to Enterprise Security, even if you arent trying to install ES8 I believe you will be hitting the same issue.&lt;/P&gt;&lt;P&gt;Hopefully this will be resolved soon but in the meantime please install your app a via the CLI.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":glowing_star:"&gt;🌟&lt;/span&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Did this answer help you?&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;If so, please consider:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Adding karma to show it was useful&lt;/LI&gt;&lt;LI&gt;Marking it as the solution if it resolved your issue&lt;/LI&gt;&lt;LI&gt;Commenting if you need any clarification&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Your feedback encourages the volunteers in this community to continue contributing&lt;/P&gt;</description>
      <pubDate>Mon, 20 Oct 2025 19:57:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Entreprise-Max-Upload-issue/m-p/754499#M23285</guid>
      <dc:creator>livehybrid</dc:creator>
      <dc:date>2025-10-20T19:57:23Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Entreprise Max Upload issue</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Entreprise-Max-Upload-issue/m-p/754778#M23343</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Thank you so much for your response and efforts, this really helped me as i thought the issue ewas on my side but it was a bug after all.&lt;/P&gt;&lt;P&gt;I am planning to go the 9.4 version, do you have any guide by chance on howe to switch from Splunk Etreprise 10.x to 9.4.&lt;/P&gt;&lt;P&gt;Thank you for you response once again .&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 27 Oct 2025 08:34:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Entreprise-Max-Upload-issue/m-p/754778#M23343</guid>
      <dc:creator>fedayn05</dc:creator>
      <dc:date>2025-10-27T08:34:34Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Entreprise Max Upload issue</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Entreprise-Max-Upload-issue/m-p/754779#M23344</link>
      <description>&lt;P&gt;There is no official/supported way of downgrading your Splunk Enterprise environment.&lt;/P&gt;&lt;P&gt;You _might_ get away with doing a backup of your runtime data and local configs, razing your environment completely, installing lower version and restoring the backup but it is a relatively risky process (and of course if you have a distributed environment you'd have to do the downgrades in the opposite order from your upgrades). But noone will guarantee that it will not destroy your setup. Especially since you want to downgrade over big version.&lt;/P&gt;</description>
      <pubDate>Mon, 27 Oct 2025 09:19:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Entreprise-Max-Upload-issue/m-p/754779#M23344</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2025-10-27T09:19:39Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Entreprise Max Upload issue</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Entreprise-Max-Upload-issue/m-p/754792#M23349</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Can I then deploy another VM , install the intended Splunk version , then detach the disk from the old Splunk and attach it to the new one.&lt;/P&gt;&lt;P&gt;May this work ?&lt;/P&gt;</description>
      <pubDate>Mon, 27 Oct 2025 12:17:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Entreprise-Max-Upload-issue/m-p/754792#M23349</guid>
      <dc:creator>fedayn05</dc:creator>
      <dc:date>2025-10-27T12:17:39Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Entreprise Max Upload issue</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Entreprise-Max-Upload-issue/m-p/754794#M23350</link>
      <description>&lt;P&gt;Depends on what you mean by "disk". Data? Config? Generally this boils more or less to "install and restore config/data" and will have more or less the same result.&lt;/P&gt;</description>
      <pubDate>Mon, 27 Oct 2025 12:19:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Entreprise-Max-Upload-issue/m-p/754794#M23350</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2025-10-27T12:19:48Z</dc:date>
    </item>
  </channel>
</rss>

