<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: &amp;quot;File Integrity checks found 1 files that did not match the system-provided manifest. See splunkd.log for details.&amp;quot; in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/quot-File-Integrity-checks-found-1-files-that-did-not-match-the/m-p/364003#M7132</link>
    <description>&lt;P&gt;go to a fresh Splunk instance, copy /opt/splunk/etc/users/users.ini from the fresh instance to yours, be sure to keep the file modified times ...   restart.   &lt;/P&gt;

&lt;P&gt;this will go away&lt;/P&gt;</description>
    <pubDate>Tue, 03 Oct 2017 21:20:12 GMT</pubDate>
    <dc:creator>darrenfuller</dc:creator>
    <dc:date>2017-10-03T21:20:12Z</dc:date>
    <item>
      <title>"File Integrity checks found 1 files that did not match the system-provided manifest. See splunkd.log for details."</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/quot-File-Integrity-checks-found-1-files-that-did-not-match-the/m-p/363999#M7128</link>
      <description>&lt;P&gt;I have no idea where this message is coming from. I see the subject message in the WebUI but when I restart splunk it tells me all is OK. Here is the output from a restart:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[dev]root@ip-10-94-18-55:/opt/splunk/etc/users:#/opt/splunk/bin/splunk restart
Stopping splunkd...
Shutting down.  Please wait, as this may take a few minutes.
.............                                              [  OK  ]
Stopping splunk helpers...
                                                           [  OK  ]
Done.

Splunk&amp;gt; Needle. Haystack. Found.

Checking prerequisites...
    Checking http port [8000]: open
    Checking mgmt port [8089]: open
    Checking appserver port [127.0.0.1:8065]: open
    Checking kvstore port [8191]: open
    Checking configuration...  Done.
    Checking critical directories...    Done
    Checking indexes...
        Validated: _audit _internal _introspection _telemetry _thefishbucket aws_anomaly_detection aws_topology_daily_snapshot aws_topology_history aws_topology_monthly_snapshot aws_topology_playback aws_vpc_flow_logs history main summary
    Done


Bypassing local license checks since this instance is configured with a remote license master.

    Checking filesystem compatibility...  Done
    Checking conf files for problems...
        Invalid key in stanza [ui] in /opt/splunk/etc/apps/SA-ge_splunk_health/local/app.conf, line 12: version  (value:  1.0).
        Invalid key in stanza [calendar_heatmap] in /opt/splunk/etc/apps/calendar_heatmap_app/default/visualizations.conf, line 6: supports_drilldown  (value:  True).
        Your indexes and inputs configurations are not internally consistent. For more information, run 'splunk btool check --debug'
    Done
    Checking default conf files for edits...
    Validating installed files against hashes from '/opt/splunk/splunk-6.5.2-67571ef4b87d-linux-2.6-x86_64-manifest'
    All installed files intact.
    Done
All preliminary checks passed.

Starting splunk server daemon (splunkd)...
Done
                                                           [  OK  ]

Waiting for web server at &lt;A href="https://127.0.0.1:8000" target="test_blank"&gt;https://127.0.0.1:8000&lt;/A&gt; to be available................. Done


If you get stuck, we're here to help.
Look for answers here: &lt;A href="http://docs.splunk.com" target="test_blank"&gt;http://docs.splunk.com&lt;/A&gt;

The Splunk web interface is at &lt;A href="https://ip-10-94-18-55:8000" target="test_blank"&gt;https://ip-10-94-18-55:8000&lt;/A&gt;
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;I ran the REST API call to &lt;A href="https://10.94.18.55:8089/services/server/status/installed-file-integrity"&gt;https://10.94.18.55:8089/services/server/status/installed-file-integrity&lt;/A&gt; and it tells me that the file /opt/splunk/etc/users/users.ini has been modified. What am I missing here?&lt;/P&gt;

&lt;P&gt;ANy help is MUCH apprecaietd as this is very annoying.&lt;/P&gt;</description>
      <pubDate>Mon, 02 Oct 2017 19:32:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/quot-File-Integrity-checks-found-1-files-that-did-not-match-the/m-p/363999#M7128</guid>
      <dc:creator>brent_weaver</dc:creator>
      <dc:date>2017-10-02T19:32:51Z</dc:date>
    </item>
    <item>
      <title>Re: "File Integrity checks found 1 files that did not match the system-provided manifest. See splunkd.log for details."</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/quot-File-Integrity-checks-found-1-files-that-did-not-match-the/m-p/364000#M7129</link>
      <description>&lt;P&gt;did you edit some files under the default folders ?&lt;/P&gt;</description>
      <pubDate>Tue, 03 Oct 2017 05:53:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/quot-File-Integrity-checks-found-1-files-that-did-not-match-the/m-p/364000#M7129</guid>
      <dc:creator>xisura</dc:creator>
      <dc:date>2017-10-03T05:53:08Z</dc:date>
    </item>
    <item>
      <title>Re: "File Integrity checks found 1 files that did not match the system-provided manifest. See splunkd.log for details."</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/quot-File-Integrity-checks-found-1-files-that-did-not-match-the/m-p/364001#M7130</link>
      <description>&lt;P&gt;I would never do that, so no.&lt;/P&gt;</description>
      <pubDate>Tue, 03 Oct 2017 19:15:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/quot-File-Integrity-checks-found-1-files-that-did-not-match-the/m-p/364001#M7130</guid>
      <dc:creator>brent_weaver</dc:creator>
      <dc:date>2017-10-03T19:15:09Z</dc:date>
    </item>
    <item>
      <title>Re: "File Integrity checks found 1 files that did not match the system-provided manifest. See splunkd.log for details."</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/quot-File-Integrity-checks-found-1-files-that-did-not-match-the/m-p/364002#M7131</link>
      <description>&lt;P&gt;The file is /opt/splunk/etc/users/users.ini that it is complaining about. &lt;/P&gt;</description>
      <pubDate>Tue, 03 Oct 2017 19:34:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/quot-File-Integrity-checks-found-1-files-that-did-not-match-the/m-p/364002#M7131</guid>
      <dc:creator>brent_weaver</dc:creator>
      <dc:date>2017-10-03T19:34:08Z</dc:date>
    </item>
    <item>
      <title>Re: "File Integrity checks found 1 files that did not match the system-provided manifest. See splunkd.log for details."</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/quot-File-Integrity-checks-found-1-files-that-did-not-match-the/m-p/364003#M7132</link>
      <description>&lt;P&gt;go to a fresh Splunk instance, copy /opt/splunk/etc/users/users.ini from the fresh instance to yours, be sure to keep the file modified times ...   restart.   &lt;/P&gt;

&lt;P&gt;this will go away&lt;/P&gt;</description>
      <pubDate>Tue, 03 Oct 2017 21:20:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/quot-File-Integrity-checks-found-1-files-that-did-not-match-the/m-p/364003#M7132</guid>
      <dc:creator>darrenfuller</dc:creator>
      <dc:date>2017-10-03T21:20:12Z</dc:date>
    </item>
    <item>
      <title>Re: "File Integrity checks found 1 files that did not match the system-provided manifest. See splunkd.log for details."</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/quot-File-Integrity-checks-found-1-files-that-did-not-match-the/m-p/364004#M7133</link>
      <description>&lt;P&gt;WHen I do this splunk complains about the missing [contrains-uppercase] section. So unfort this did not work.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[contains-uppercase]
212631038" = 212631038_.7c4b2bdd6b5f9690f1813a7ab9d6e76a
212611170" = 212611170_.d3b52ce6b4e8fdfbf8ec32f6d9f015ba
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Wed, 04 Oct 2017 13:48:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/quot-File-Integrity-checks-found-1-files-that-did-not-match-the/m-p/364004#M7133</guid>
      <dc:creator>brent_weaver</dc:creator>
      <dc:date>2017-10-04T13:48:34Z</dc:date>
    </item>
    <item>
      <title>Re: "File Integrity checks found 1 files that did not match the system-provided manifest. See splunkd.log for details."</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/quot-File-Integrity-checks-found-1-files-that-did-not-match-the/m-p/364005#M7134</link>
      <description>&lt;P&gt;same version/edition of Splunk on both?&lt;/P&gt;</description>
      <pubDate>Wed, 04 Oct 2017 13:53:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/quot-File-Integrity-checks-found-1-files-that-did-not-match-the/m-p/364005#M7134</guid>
      <dc:creator>darrenfuller</dc:creator>
      <dc:date>2017-10-04T13:53:02Z</dc:date>
    </item>
    <item>
      <title>Re: "File Integrity checks found 1 files that did not match the system-provided manifest. See splunkd.log for details."</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/quot-File-Integrity-checks-found-1-files-that-did-not-match-the/m-p/364006#M7135</link>
      <description>&lt;P&gt;(and which version/OS are we talking about?&lt;/P&gt;</description>
      <pubDate>Wed, 04 Oct 2017 13:58:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/quot-File-Integrity-checks-found-1-files-that-did-not-match-the/m-p/364006#M7135</guid>
      <dc:creator>darrenfuller</dc:creator>
      <dc:date>2017-10-04T13:58:49Z</dc:date>
    </item>
    <item>
      <title>Re: "File Integrity checks found 1 files that did not match the system-provided manifest. See splunkd.log for details."</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/quot-File-Integrity-checks-found-1-files-that-did-not-match-the/m-p/364007#M7136</link>
      <description>&lt;P&gt;on  my  Splunk 6.5.1 Linux box, users.ini is empty:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;0 -r--r--r--. 1 splunk splunk   0 Nov 18  2016 users.ini
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Wed, 04 Oct 2017 13:59:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/quot-File-Integrity-checks-found-1-files-that-did-not-match-the/m-p/364007#M7136</guid>
      <dc:creator>darrenfuller</dc:creator>
      <dc:date>2017-10-04T13:59:46Z</dc:date>
    </item>
  </channel>
</rss>

