<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk apply shcluster-bundle fail in Deployment Architecture</title>
    <link>https://community.splunk.com/t5/Deployment-Architecture/Splunk-apply-shcluster-bundle-fail/m-p/237520#M8924</link>
    <description>&lt;P&gt;You should crank up the logging level on the deployer log channel:  ConfDeployment to debug via the the Server Settings | Server Logging UI.  Then run the apply command again and review the details in the splunkd log. &lt;/P&gt;

&lt;P&gt;You may also need to look at the splunkd log on the target server as well and look for error messages.&lt;/P&gt;</description>
    <pubDate>Mon, 25 Jan 2016 16:40:04 GMT</pubDate>
    <dc:creator>sjohnson_splunk</dc:creator>
    <dc:date>2016-01-25T16:40:04Z</dc:date>
    <item>
      <title>Splunk apply shcluster-bundle fail</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Splunk-apply-shcluster-bundle-fail/m-p/237517#M8921</link>
      <description>&lt;P&gt;Having a heck of a time implementing an application. (In this case the app=dnslookup).&lt;/P&gt;

&lt;P&gt;Here is my command and error message.&lt;/P&gt;

&lt;P&gt;&lt;A href="mailto:root@cmgr1.splunk"&gt;root@cmgr1.splunk&lt;/A&gt; (Linux) $ ./splunk apply shcluster-bundle -target &lt;A href="https://fe1.splunk.hq1.xxx.com:8089"&gt;https://fe1.splunk.hq1.xxx.com:8089&lt;/A&gt; -auth admin:xxxxxxxx&lt;BR /&gt;
 Warning: Depending on the configuration changes being pushed, this command might initiate a rolling restart of the cluster members.  Please refer to the documentation for the details. Do you wish to continue? [y/n]: y&lt;BR /&gt;
Error while deploying apps to first member: ConfDeploymentException: Error while updating app=dnslookup on target=&lt;A href="https://10.99.106.31:8089:"&gt;https://10.99.106.31:8089:&lt;/A&gt; Non-200/201 status_code=404; {"messages":[{"type":"ERROR","text":"Application does not exist: "}]}&lt;/P&gt;

&lt;P&gt;I really, really do not want to work with customer support. Please help!&lt;/P&gt;

&lt;OL&gt;
&lt;LI&gt;I have verified iptables is not running&lt;/LI&gt;
&lt;LI&gt;I have verified that there is no firewall blocking traffic.&lt;/LI&gt;
&lt;LI&gt;I have verified that permissions are all correct &lt;/LI&gt;
&lt;/OL&gt;</description>
      <pubDate>Tue, 22 Sep 2015 16:19:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Splunk-apply-shcluster-bundle-fail/m-p/237517#M8921</guid>
      <dc:creator>shandman</dc:creator>
      <dc:date>2015-09-22T16:19:13Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk apply shcluster-bundle fail</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Splunk-apply-shcluster-bundle-fail/m-p/237518#M8922</link>
      <description>&lt;P&gt;Client is trying to update an app (dnslookup) that is supposedly exist on target server (indicated as “target=&lt;A href="https://fe1.splunk.hq1.xxx.com:8089%E2%80%9D"&gt;https://fe1.splunk.hq1.xxx.com:8089”&lt;/A&gt; in the error message). &lt;BR /&gt;
Status 404 indicates that the client was able to establish the connection to the server but the server doesn’t  have the requested resource (which is dnslookup app) and that’s what the error message is indicating.&lt;/P&gt;

&lt;P&gt;Is the app existing on the target at an expected location?&lt;/P&gt;</description>
      <pubDate>Fri, 25 Sep 2015 19:25:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Splunk-apply-shcluster-bundle-fail/m-p/237518#M8922</guid>
      <dc:creator>dbhagi_splunk</dc:creator>
      <dc:date>2015-09-25T19:25:39Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk apply shcluster-bundle fail</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Splunk-apply-shcluster-bundle-fail/m-p/237519#M8923</link>
      <description>&lt;P&gt;I am having the same issue.&lt;/P&gt;

&lt;P&gt;First we try to run the deployer command to push the app to the cluster members, but we get the error above.  I then created the app locally on each search head cluster member, but we still see the same issue: &lt;/P&gt;

&lt;P&gt;[splunk@ bin]$ ./splunk apply shcluster-bundle -target &lt;A href="https://ClusterMember3.labcorp.com:808" target="_blank"&gt;https://ClusterMember3.labcorp.com:808&lt;/A&gt;                                                                                                            9 -auth admin:labcorp1&lt;BR /&gt;
 Warning: Depending on the configuration changes being pushed, this command might initiate a rollin                                                                                                            g restart of the cluster members.  Please refer to the documentation for the details. Do you wish t                                                                                                            o continue? [y/n]: y&lt;BR /&gt;
Error while deploying apps to target=&lt;A href="https://ClusterMember3.labcorp.com:8089" target="_blank"&gt;https://ClusterMember3.labcorp.com:8089&lt;/A&gt; with members=3: ConfDeploy                                                                                                            mentException: Error while updating app=admin_app on target=&lt;A href="https://10.111.1.192:8089:" target="_blank"&gt;https://10.111.1.192:8089:&lt;/A&gt; Non-200/201                                                                                                             status_code=404; {"messages":[{"type":"ERROR","text":"Application does not exist: "}]}&lt;BR /&gt;
Error while deploying apps to target=&lt;A href="https://ClusterMember3.labcorp.com:8089" target="_blank"&gt;https://ClusterMember3.labcorp.com:8089&lt;/A&gt; with members=3: ConfDeploy                                                                                                            mentException: Error while updating app=admin_app on target=&lt;A href="https://10.111.1.193:8089:" target="_blank"&gt;https://10.111.1.193:8089:&lt;/A&gt; Non-200/201                                                                                                             status_code=404; {"messages":[{"type":"ERROR","text":"Application does not exist: "}]}&lt;/P&gt;

&lt;P&gt;Thanks,&lt;BR /&gt;
JB&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 08:32:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Splunk-apply-shcluster-bundle-fail/m-p/237519#M8923</guid>
      <dc:creator>butzowj</dc:creator>
      <dc:date>2020-09-29T08:32:38Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk apply shcluster-bundle fail</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Splunk-apply-shcluster-bundle-fail/m-p/237520#M8924</link>
      <description>&lt;P&gt;You should crank up the logging level on the deployer log channel:  ConfDeployment to debug via the the Server Settings | Server Logging UI.  Then run the apply command again and review the details in the splunkd log. &lt;/P&gt;

&lt;P&gt;You may also need to look at the splunkd log on the target server as well and look for error messages.&lt;/P&gt;</description>
      <pubDate>Mon, 25 Jan 2016 16:40:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Splunk-apply-shcluster-bundle-fail/m-p/237520#M8924</guid>
      <dc:creator>sjohnson_splunk</dc:creator>
      <dc:date>2016-01-25T16:40:04Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk apply shcluster-bundle fail</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Splunk-apply-shcluster-bundle-fail/m-p/237521#M8925</link>
      <description>&lt;P&gt;I just tested by deploying this on my Search Head Cluster and below is my experience .&lt;/P&gt;

&lt;P&gt;1) Before deploying the app - I installed dnslookup on the deployer server.&lt;BR /&gt;
2) After installing this App on the deployer -when I restarted it it throws the following message&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;$SPLUNk_HOME/bin/splunk restart
Stopping splunkd...
Shutting down.  Please wait, as this may take a few minutes.
..                                                         [  OK  ]
Stopping splunk helpers...
                                                           [  OK  ]
Done.

Splunk&amp;gt; See your world.  Maybe wish you hadn't.

Checking prerequisites...
        Checking http port [24400]: open
        Checking mgmt port [24401]: open
        Checking appserver port [127.0.0.1:24405]: open
        Checking kvstore port [24406]: open
        Checking configuration...  Done.
        Checking critical directories...        Done
        Checking indexes...
                Validated: _audit _internal _introspection _thefishbucket history main msad perfmon summary winevents
        Done
        Checking filesystem compatibility...  Done
        Checking conf files for problems...
                Invalid key in stanza [install] in /opt/splunk/etc/apps/dnslookup/default/app.conf, line 10: author  (value:  Travis Freeland).
                Invalid key in stanza [install] in //opt/splunk/etc/apps/dnslookup/default/app.conf, line 11: description  (value:  dnslookup &amp;lt;forward|reverse&amp;gt; &amp;lt;input field&amp;gt; &amp;lt;outputfield&amp;gt;, servicelookup &amp;lt;input field&amp;gt; &amp;lt;output field&amp;gt; &amp;lt;optional services file path&amp;gt;).
                Your indexes and inputs configurations are not internally consistent. For more information, run 'splunk btool check --debug'
        Done
        Checking default conf files for edits...
        Validating installed files against hashes from '/opt/splunk/splunk-6.3.0-aa7d4b1ccb80-linux-2.6-x86_64-manifest'
        All installed files intact.
        Done
All preliminary checks passed.

Starting splunk server daemon (splunkd)...
Done
                                                           [  OK  ]
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;3) To resolve the above issue before deploying app - fixed the $SPLUNK_HOME_DEPLOYER/etc/apps/dnslookup/default/apps.conf   and comment  out the two lines shows below in bold-text.  (i.e attribute author and description under stanza [install])&lt;/P&gt;

&lt;P&gt;-----------$SPLUNK_HOME_DEPLOYER/etc/apps/dnslookup/default/apps.conf---------&lt;/P&gt;

&lt;P&gt;[package]&lt;BR /&gt;
id = dnslookup&lt;/P&gt;

&lt;P&gt;[install]&lt;BR /&gt;
is_configured = 0&lt;BR /&gt;
**#author = Travis Freeland&lt;/P&gt;

&lt;H1&gt;description = dnslookup   , servicelookup   **&lt;/H1&gt;

&lt;P&gt;build = 1&lt;BR /&gt;
install_source_checksum = 5224a17b098abd2d668cb74836b9c1b394c4f373&lt;/P&gt;

&lt;P&gt;[ui]&lt;BR /&gt;
is_visible = 0&lt;BR /&gt;
label = dnslookup&lt;/P&gt;

&lt;P&gt;[launcher]&lt;BR /&gt;
author = Travis Freeland&lt;BR /&gt;
description = dnslookup   , servicelookup&lt;BR /&gt;&lt;BR /&gt;
version = 0.1&lt;/P&gt;

&lt;P&gt;NOTE: Since this is not Splunk provided app , but has been devloped by  Travis Freeland  I have provided feedback for above issue to be resolved..&lt;/P&gt;

&lt;P&gt;4) Once the above issue was fixed copied the app from $SPLUNk_HOME_DEPLOYER/etc/apps/dnslookup  to $SPLUNk_HOME_DEPLOYER/etc/shcluster/apps/dnslookup  and deployed the bundle using command &lt;/P&gt;

&lt;P&gt;&lt;CODE&gt;$SPLUNK_HOME_DEPLOYER/bin/splunk apply  shcluster-bundle -target   https://:8089&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;Warning: Depending on the configuration changes being pushed, this command might initiate a rolling restart of the cluster members.  Please refer to the documentation for the details. Do you wish to continue? [y/n]: y&lt;BR /&gt;
Your session is invalid.  Please login.&lt;BR /&gt;
Splunk username: admin&lt;BR /&gt;
Password:&lt;BR /&gt;
&lt;STRONG&gt;Bundle has been pushed successfully to all the cluster members&lt;/STRONG&gt;&lt;/P&gt;

&lt;P&gt;5) The App got deployed without any issue.&lt;/P&gt;

&lt;P&gt;6) In your case have you been able to deploy other apps besides this app.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 08:33:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Splunk-apply-shcluster-bundle-fail/m-p/237521#M8925</guid>
      <dc:creator>rbal_splunk</dc:creator>
      <dc:date>2020-09-29T08:33:05Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk apply shcluster-bundle fail</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Splunk-apply-shcluster-bundle-fail/m-p/237522#M8926</link>
      <description>&lt;P&gt;Ran into the same error where there was a folder with the name "-" (dash) in $SPLUNK_HOME/etc/shcluster/apps/.  Removing that directory resolved the issue.&lt;/P&gt;</description>
      <pubDate>Thu, 28 Apr 2016 18:15:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Splunk-apply-shcluster-bundle-fail/m-p/237522#M8926</guid>
      <dc:creator>jcrabb_splunk</dc:creator>
      <dc:date>2016-04-28T18:15:02Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk apply shcluster-bundle fail</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Splunk-apply-shcluster-bundle-fail/m-p/237523#M8927</link>
      <description>&lt;P&gt;i fixed it by changing the max_content_length in server.conf. &lt;/P&gt;

&lt;P&gt;As stated, the file exceeds max_content_length in server.conf of 800 MB. This can be increased by adding the following to $SPLUNK_HOME/etc/system/local/server.conf.&lt;/P&gt;

&lt;P&gt;[httpServer]&lt;BR /&gt;
 max_content_length = 1600000000&lt;/P&gt;

&lt;P&gt;my bundle had a huge lookups and that was causing this error. &lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 12:41:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Splunk-apply-shcluster-bundle-fail/m-p/237523#M8927</guid>
      <dc:creator>yahuja_splunk</dc:creator>
      <dc:date>2020-09-29T12:41:13Z</dc:date>
    </item>
  </channel>
</rss>

