<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: /opt/ee_splunk/splunk/etc/apps/splunk_essentials_8_2/default/app.conf' changed. in SHC in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/opt-ee-splunk-splunk-etc-apps-splunk-essentials-8-2-default-app/m-p/557659#M92291</link>
    <description>&lt;P&gt;Instead of copying the directory over from another SH you should re-deploy the app via deployer.&lt;/P&gt;</description>
    <pubDate>Tue, 29 Jun 2021 18:25:06 GMT</pubDate>
    <dc:creator>codebuilder</dc:creator>
    <dc:date>2021-06-29T18:25:06Z</dc:date>
    <item>
      <title>/opt/ee_splunk/splunk/etc/apps/splunk_essentials_8_2/default/app.conf' changed. in SHC</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/opt-ee-splunk-splunk-etc-apps-splunk-essentials-8-2-default-app/m-p/556814#M92145</link>
      <description>&lt;P&gt;Hi all&lt;/P&gt;&lt;P&gt;Some how&amp;nbsp;splunk_essentials_8_2 directopry got removed from this directory /opt/splunk/etc/apps .later i replicated this directory from other instance.But i see the below error.can some one help with this.&lt;/P&gt;&lt;P&gt;Validating installed files against hashes from '/opt/ee_splunk/splunk/splunk-8.2.0-e053ef3c985f-linux-2.6-x86_64-manifest'&lt;BR /&gt;File '/opt/ee_splunk/splunk/etc/apps/splunk_essentials_8_2/default/app.conf' changed.&lt;BR /&gt;Problems were found, please review your files and move customizations to local&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 23 Jun 2021 06:22:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/opt-ee-splunk-splunk-etc-apps-splunk-essentials-8-2-default-app/m-p/556814#M92145</guid>
      <dc:creator>btshivanand</dc:creator>
      <dc:date>2021-06-23T06:22:53Z</dc:date>
    </item>
    <item>
      <title>Re: /opt/ee_splunk/splunk/etc/apps/splunk_essentials_8_2/default/app.conf' changed. in SHC</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/opt-ee-splunk-splunk-etc-apps-splunk-essentials-8-2-default-app/m-p/557659#M92291</link>
      <description>&lt;P&gt;Instead of copying the directory over from another SH you should re-deploy the app via deployer.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Jun 2021 18:25:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/opt-ee-splunk-splunk-etc-apps-splunk-essentials-8-2-default-app/m-p/557659#M92291</guid>
      <dc:creator>codebuilder</dc:creator>
      <dc:date>2021-06-29T18:25:06Z</dc:date>
    </item>
    <item>
      <title>Re: /opt/ee_splunk/splunk/etc/apps/splunk_essentials_8_2/default/app.conf' changed. in SHC</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/opt-ee-splunk-splunk-etc-apps-splunk-essentials-8-2-default-app/m-p/557982#M92329</link>
      <description>&lt;P&gt;Just delete following line:&amp;nbsp;&lt;SPAN&gt;'/opt/ee_splunk/splunk/etc/apps/splunk_essentials_8_2/default/app.conf&lt;/SPAN&gt;&lt;BR /&gt;From the splunk manifest in /opt/ee_splunk/splunk&lt;/P&gt;&lt;P&gt;Sometimes Apps created during the installation ( The ones that splunk keeps a manifest), if they get pushed by the SHC deployer,&amp;nbsp; the checksum can get modified when the members get it.&lt;/P&gt;&lt;P&gt;I had the same issue with this App and the only way I could get it working was by deleting the record...&lt;/P&gt;&lt;P&gt;The App booked a one way flight to Belize when I created the Search Head Cluster.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 01 Jul 2021 06:16:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/opt-ee-splunk-splunk-etc-apps-splunk-essentials-8-2-default-app/m-p/557982#M92329</guid>
      <dc:creator>aledantas2k12</dc:creator>
      <dc:date>2021-07-01T06:16:53Z</dc:date>
    </item>
    <item>
      <title>Re: /opt/ee_splunk/splunk/etc/apps/splunk_essentials_8_2/default/app.conf' changed. in SHC</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/opt-ee-splunk-splunk-etc-apps-splunk-essentials-8-2-default-app/m-p/559666#M92554</link>
      <description>&lt;P&gt;I am having a similar issue but in my case the complete app gets removed from all shc members. I feel like removing the hash is more of a hack than a solution.&lt;/P&gt;&lt;P&gt;This is a default app that shouldn't be removed; seems like a bug to me.&lt;/P&gt;</description>
      <pubDate>Thu, 15 Jul 2021 17:52:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/opt-ee-splunk-splunk-etc-apps-splunk-essentials-8-2-default-app/m-p/559666#M92554</guid>
      <dc:creator>Forseti_</dc:creator>
      <dc:date>2021-07-15T17:52:57Z</dc:date>
    </item>
    <item>
      <title>Re: /opt/ee_splunk/splunk/etc/apps/splunk_essentials_8_2/default/app.conf' changed. in SHC</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/opt-ee-splunk-splunk-etc-apps-splunk-essentials-8-2-default-app/m-p/559719#M92557</link>
      <description>&lt;P&gt;Hi mate.&lt;/P&gt;&lt;P&gt;It's the same issue. The whole app gets removed from all SHC members. It's a hack indeed, but only solution since the app got removed and there is no way to put it back without changing the hash.&lt;BR /&gt;&lt;BR /&gt;Indeed. It's a bug...&lt;/P&gt;</description>
      <pubDate>Thu, 15 Jul 2021 23:38:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/opt-ee-splunk-splunk-etc-apps-splunk-essentials-8-2-default-app/m-p/559719#M92557</guid>
      <dc:creator>aledantas2k12</dc:creator>
      <dc:date>2021-07-15T23:38:20Z</dc:date>
    </item>
    <item>
      <title>Re: /opt/ee_splunk/splunk/etc/apps/splunk_essentials_8_2/default/app.conf' changed. in SHC</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/opt-ee-splunk-splunk-etc-apps-splunk-essentials-8-2-default-app/m-p/576019#M101794</link>
      <description>&lt;P&gt;&lt;SPAN&gt;This is a known issue reported in this version, please verify the following information: SPL-208259, SPL-210931, SPL-211811&lt;/SPAN&gt;&lt;BR /&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/8.2.2/ReleaseNotes/KnownIssues" target="_blank" rel="noopener"&gt;https://docs.splunk.com/Documentation/Splunk/8.2.2/ReleaseNotes/KnownIssues&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Workaround:&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Copy splunk_essentials_8_2 into the deployer's $SPLUNK_HOME/etc/shcluster/apps.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 23 Nov 2021 13:46:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/opt-ee-splunk-splunk-etc-apps-splunk-essentials-8-2-default-app/m-p/576019#M101794</guid>
      <dc:creator>Losde</dc:creator>
      <dc:date>2021-11-23T13:46:38Z</dc:date>
    </item>
  </channel>
</rss>

