<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Why does Splunk assist constantly fail on 9.1.0.1 version after upgrade due to free license? in Installation</title>
    <link>https://community.splunk.com/t5/Installation/Why-does-Splunk-assist-constantly-fail-on-9-1-0-1-version-after/m-p/652916#M13140</link>
    <description>&lt;P&gt;Free license does come with few limitations, which are outlined in below doc: &lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/Admin/MoreaboutSplunkFree" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/latest/Admin/MoreaboutSplunkFree&lt;/A&gt;&lt;/P&gt;&lt;P&gt;I was able to reproduce the same behavior when I switched my instance to use a Free license and started getting:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;Unable to load common tasks. Refresh the page to try again&lt;/LI-CODE&gt;&lt;P&gt;and the app list wouldn't load in the UI.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I switched back to an Enterprise license and that got rid of the UI errors.&lt;/P&gt;</description>
    <pubDate>Wed, 02 Aug 2023 15:08:37 GMT</pubDate>
    <dc:creator>ymb</dc:creator>
    <dc:date>2023-08-02T15:08:37Z</dc:date>
    <item>
      <title>Why does Splunk assist constantly fail on 9.1.0.1 version after upgrade due to free license?</title>
      <link>https://community.splunk.com/t5/Installation/Why-does-Splunk-assist-constantly-fail-on-9-1-0-1-version-after/m-p/652510#M13117</link>
      <description>&lt;P&gt;hey, we're in the process of upgrading on our splunk single instances from 8.2.5 to 9.1.0.1 due to EOL.&lt;BR /&gt;&lt;BR /&gt;we have two splunk instances - production which is under the enterprise license, test which is under the free license.&lt;BR /&gt;&lt;BR /&gt;we've first started upgrading our test splunk instance with the free license and we instantly saw these errors:&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;07-31-2023 07:01:44.412 +0000 ERROR ExecProcessor [670742 ExecProcessor] - message from "/opt/splunk/bin/python3.7 /opt/splunk/etc/apps/splunk_assist/bin/uiassets_modular_input.py" [modular_input:349] [execute] [834704] Modular input: Splunk Assist exit with exception: Traceback (most recent call last):
07-31-2023 07:01:44.412 +0000 ERROR ExecProcessor [670742 ExecProcessor] - message from "/opt/splunk/bin/python3.7 /opt/splunk/etc/apps/splunk_assist/bin/uiassets_modular_input.py"   File "/opt/splunk/etc/apps/splunk_assist/bin/assist/modular_input.py", line 342, in execute
07-31-2023 07:01:44.412 +0000 ERROR ExecProcessor [670742 ExecProcessor] - message from "/opt/splunk/bin/python3.7 /opt/splunk/etc/apps/splunk_assist/bin/uiassets_modular_input.py"     self.do_run(input_definition["inputs"])
07-31-2023 07:01:44.412 +0000 ERROR ExecProcessor [670742 ExecProcessor] - message from "/opt/splunk/bin/python3.7 /opt/splunk/etc/apps/splunk_assist/bin/uiassets_modular_input.py"   File "/opt/splunk/etc/apps/splunk_assist/bin/uiassets_modular_input.py", line 66, in do_run
07-31-2023 07:01:44.412 +0000 ERROR ExecProcessor [670742 ExecProcessor] - message from "/opt/splunk/bin/python3.7 /opt/splunk/etc/apps/splunk_assist/bin/uiassets_modular_input.py"     if not should_run(self.logger, self.session_key):
07-31-2023 07:01:44.412 +0000 ERROR ExecProcessor [670742 ExecProcessor] - message from "/opt/splunk/bin/python3.7 /opt/splunk/etc/apps/splunk_assist/bin/uiassets_modular_input.py"   File "/opt/splunk/etc/apps/splunk_assist/bin/uiassets_modular_input.py", line 27, in should_run
07-31-2023 07:01:44.412 +0000 ERROR ExecProcessor [670742 ExecProcessor] - message from "/opt/splunk/bin/python3.7 /opt/splunk/etc/apps/splunk_assist/bin/uiassets_modular_input.py"     sh = is_search_head(log, session_key)
07-31-2023 07:01:44.412 +0000 ERROR ExecProcessor [670742 ExecProcessor] - message from "/opt/splunk/bin/python3.7 /opt/splunk/etc/apps/splunk_assist/bin/uiassets_modular_input.py"   File "/opt/splunk/etc/apps/splunk_assist/bin/assist/serverinfo.py", line 153, in is_search_head
07-31-2023 07:01:44.412 +0000 ERROR ExecProcessor [670742 ExecProcessor] - message from "/opt/splunk/bin/python3.7 /opt/splunk/etc/apps/splunk_assist/bin/uiassets_modular_input.py"     cluster_mode = get_cluster_mode(log, session_key)
07-31-2023 07:01:44.412 +0000 ERROR ExecProcessor [670742 ExecProcessor] - message from "/opt/splunk/bin/python3.7 /opt/splunk/etc/apps/splunk_assist/bin/uiassets_modular_input.py"   File "/opt/splunk/etc/apps/splunk_assist/bin/assist/serverinfo.py", line 257, in get_cluster_mode
07-31-2023 07:01:44.412 +0000 ERROR ExecProcessor [670742 ExecProcessor] - message from "/opt/splunk/bin/python3.7 /opt/splunk/etc/apps/splunk_assist/bin/uiassets_modular_input.py"     raiseAllErrors=True
07-31-2023 07:01:44.412 +0000 ERROR ExecProcessor [670742 ExecProcessor] - message from "/opt/splunk/bin/python3.7 /opt/splunk/etc/apps/splunk_assist/bin/uiassets_modular_input.py"   File "/opt/splunk/lib/python3.7/site-packages/splunk/rest/__init__.py", line 646, in simpleRequest
07-31-2023 07:01:44.412 +0000 ERROR ExecProcessor [670742 ExecProcessor] - message from "/opt/splunk/bin/python3.7 /opt/splunk/etc/apps/splunk_assist/bin/uiassets_modular_input.py"     raise splunk.LicenseRestriction
07-31-2023 07:01:44.412 +0000 ERROR ExecProcessor [670742 ExecProcessor] - message from "/opt/splunk/bin/python3.7 /opt/splunk/etc/apps/splunk_assist/bin/uiassets_modular_input.py" splunk.LicenseRestriction: [HTTP 402] Current license does not allow the requested action
07-31-2023 07:01:44.412 +0000 ERROR ExecProcessor [670742 ExecProcessor] - message from "/opt/splunk/bin/python3.7 /opt/splunk/etc/apps/splunk_assist/bin/uiassets_modular_input.py" .&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;this splunk assist issue seems to come from the usage of free license on splunk.&lt;BR /&gt;&lt;BR /&gt;I tried to disable the splunk-assist app but it wouldn't let me:&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;Cannot disable app: splunk_assist&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;BR /&gt;as a result of the previous errors, we are seeing UI errors as well:&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;Unable to load common tasks. Refresh the page to try again.&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;any idea on how to proceed?&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 31 Jul 2023 18:59:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Why-does-Splunk-assist-constantly-fail-on-9-1-0-1-version-after/m-p/652510#M13117</guid>
      <dc:creator>ori</dc:creator>
      <dc:date>2023-07-31T18:59:26Z</dc:date>
    </item>
    <item>
      <title>Re: Why does Splunk assist constantly fail on 9.1.0.1 version after upgrade due to free license?</title>
      <link>https://community.splunk.com/t5/Installation/Why-does-Splunk-assist-constantly-fail-on-9-1-0-1-version-after/m-p/652916#M13140</link>
      <description>&lt;P&gt;Free license does come with few limitations, which are outlined in below doc: &lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/Admin/MoreaboutSplunkFree" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/latest/Admin/MoreaboutSplunkFree&lt;/A&gt;&lt;/P&gt;&lt;P&gt;I was able to reproduce the same behavior when I switched my instance to use a Free license and started getting:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;Unable to load common tasks. Refresh the page to try again&lt;/LI-CODE&gt;&lt;P&gt;and the app list wouldn't load in the UI.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I switched back to an Enterprise license and that got rid of the UI errors.&lt;/P&gt;</description>
      <pubDate>Wed, 02 Aug 2023 15:08:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Why-does-Splunk-assist-constantly-fail-on-9-1-0-1-version-after/m-p/652916#M13140</guid>
      <dc:creator>ymb</dc:creator>
      <dc:date>2023-08-02T15:08:37Z</dc:date>
    </item>
    <item>
      <title>Re: Why does Splunk assist constantly fail on 9.1.0.1 version after upgrade due to free license?</title>
      <link>https://community.splunk.com/t5/Installation/Why-does-Splunk-assist-constantly-fail-on-9-1-0-1-version-after/m-p/657167#M13243</link>
      <description>&lt;P&gt;Free license or not free license, Splunk UI should not display cryptic error message.&amp;nbsp; I consider this a usability bug because the license type can easily be handled with clearer message.&lt;/P&gt;&lt;P&gt;You can disable Splunk Assist. &amp;nbsp;But that will not solve this problem.&lt;/P&gt;&lt;P&gt;To disable the application, go to $SPLUNK_HOME/etc/apps/splunk_assist. &amp;nbsp;Create a directory local/, then create a file app.conf to override allow_disable=true in [install] stanza, like this:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;cd $SPLUNK_HOME/etc/apps/splunk_assist
mkdir local
cat &amp;lt;&amp;lt;EOM &amp;gt;local/app.conf
[install]
allows_disable = false
EOM&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;After restarting Splunk, you can then disable splunk_assist. &amp;nbsp;But the error will persist even when Splunk Assist is disabled. &amp;nbsp;BTW, if you launch splunk_assist directly, you will be able to see the error message&lt;/P&gt;&lt;BLOCKQUOTE&gt;&lt;SPAN class=""&gt;Unable&lt;/SPAN&gt; &lt;SPAN class=""&gt;to&lt;/SPAN&gt; &lt;SPAN class=""&gt;obtain&lt;/SPAN&gt; &lt;SPAN class=""&gt;template&lt;/SPAN&gt;&lt;SPAN&gt; "&lt;/SPAN&gt;&lt;SPAN class=""&gt;beam:/templates/start.html&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;: ...&amp;nbsp;TopLevelLookupException&lt;SPAN&gt;(&lt;/SPAN&gt;_&lt;SPAN&gt;("&lt;/SPAN&gt;Splunk has failed to locate the template for uri&lt;SPAN&gt; '&lt;/SPAN&gt;%s&lt;SPAN&gt;'&lt;/SPAN&gt;.&lt;SPAN&gt;" &lt;/SPAN&gt;% uri&lt;SPAN&gt;)) &lt;/SPAN&gt;TopLevelLookupException: Splunk has failed to locate the template for uri&lt;SPAN&gt; '&lt;/SPAN&gt;beam:/templates/start.html&lt;SPAN&gt;'.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&lt;SPAN class=""&gt;The problem is that a 9.1 upgrade enables a feature called&amp;nbsp;&lt;SPAN&gt;enable_home_vnext. &amp;nbsp;It is a fine feature (with tons of marketing plugs) except for this bug:&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;Splunk should detect the free license and handle the error without showing a cryptic error message. (It can show, for example, "this feature is unavailable for the installed license" like it does with a bunch of other features.)&lt;/SPAN&gt;&lt;/P&gt;&lt;H3&gt;Workaround&lt;/H3&gt;&lt;P&gt;&lt;SPAN class=""&gt;The only workaround I have discovered so far is to disable &lt;SPAN&gt;enable_home_vnext in&lt;/SPAN&gt;&amp;nbsp;[feature:page_migration] stanza from web-features.conf. &amp;nbsp;([feature:page_migration] is introduced in 9.x but is in web.conf. web-features.conf is introduced in 9.1.1; a skeleton local/web-features.conf is created by installer but the stanza is not in it.)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;cd $SPLUNK_HOME/etc/system/local
cat &amp;lt;&amp;lt;EOM&amp;gt;&amp;gt;web-features.conf
[feature:page_migration]
enable_home_vnext = false
EOM&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;After this, you will see your previous launcher home page instead of the migration page. (You &lt;EM&gt;may&lt;/EM&gt; need to to restart splunkd.&amp;nbsp; I had at least one instance for which I did not perform restart after editing.)&amp;nbsp; I hope Splunk will not take the legacy launch page away before fixing the bug in the new page.&lt;/P&gt;&lt;H3&gt;What changed?&lt;/H3&gt;&lt;P&gt;The new index _configtracker added in 9.x makes it much easier to track changes made over time. &amp;nbsp;Because I was upgrading from 9.0.5, I can see the exact changes 9.1 upgrade has made. &amp;nbsp;For example, to see web feature changes,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index="_configtracker" (data.path=*/system/default/web-features.conf)
| spath path=data.changes{}
| fields - data.changes{}.*
| mvexpand data.changes{}
| spath input=data.changes{}
| spath input=data.changes{} path=properties{}
| fields - properties{}.*
| mvexpand properties{}
| spath input=properties{}
| stats latest(*_value) as *_value by data.action name stanza data.path _time
| eval data.path = replace('data.path', ".*/[sS]plunk/etc", "")
| fieldformat _time = strftime(_time, "%F")
| table name *_value stanza data.* _time&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;On my laptop instance (defaults), this shows&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;name&lt;/TD&gt;&lt;TD&gt;new_value&lt;/TD&gt;&lt;TD&gt;old_value&lt;/TD&gt;&lt;TD&gt;stanza&lt;/TD&gt;&lt;TD&gt;data.action&lt;/TD&gt;&lt;TD&gt;data.path&lt;/TD&gt;&lt;TD&gt;_time&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;disable_highcharts_accessibility&lt;/TD&gt;&lt;TD&gt;false&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;feature:highcharts_accessibility&lt;/TD&gt;&lt;TD&gt;update&lt;/TD&gt;&lt;TD&gt;/system/default/web-features.conf&lt;/TD&gt;&lt;TD&gt;2023-09-08&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;enable_acuif_pages&lt;/TD&gt;&lt;TD&gt;false&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;feature::windows_rce&lt;/TD&gt;&lt;TD&gt;update&lt;/TD&gt;&lt;TD&gt;/system/default/web-features.conf&lt;/TD&gt;&lt;TD&gt;2023-09-08&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;enable_autoformatted_comments&lt;/TD&gt;&lt;TD&gt;false&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;feature:search_auto_format&lt;/TD&gt;&lt;TD&gt;update&lt;/TD&gt;&lt;TD&gt;/system/default/web-features.conf&lt;/TD&gt;&lt;TD&gt;2023-09-08&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;enable_dashboards_external_content_restriction&lt;/TD&gt;&lt;TD&gt;true&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;feature:dashboards_csp&lt;/TD&gt;&lt;TD&gt;update&lt;/TD&gt;&lt;TD&gt;/system/default/web-features.conf&lt;/TD&gt;&lt;TD&gt;2023-09-08&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;enable_dashboards_redirection_restriction&lt;/TD&gt;&lt;TD&gt;true&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;feature:dashboards_csp&lt;/TD&gt;&lt;TD&gt;update&lt;/TD&gt;&lt;TD&gt;/system/default/web-features.conf&lt;/TD&gt;&lt;TD&gt;2023-09-08&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;enable_events_viz&lt;/TD&gt;&lt;TD&gt;true&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;feature:dashboard_studio&lt;/TD&gt;&lt;TD&gt;update&lt;/TD&gt;&lt;TD&gt;/system/default/web-features.conf&lt;/TD&gt;&lt;TD&gt;2023-09-08&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;enable_home_vnext&lt;/TD&gt;&lt;TD&gt;true&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;feature:page_migration&lt;/TD&gt;&lt;TD&gt;update&lt;/TD&gt;&lt;TD&gt;/system/default/web-features.conf&lt;/TD&gt;&lt;TD&gt;2023-09-08&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;enable_inputs_on_canvas&lt;/TD&gt;&lt;TD&gt;true&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;feature:dashboard_studio&lt;/TD&gt;&lt;TD&gt;update&lt;/TD&gt;&lt;TD&gt;/system/default/web-features.conf&lt;/TD&gt;&lt;TD&gt;2023-09-08&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;enable_jQuery2&lt;/TD&gt;&lt;TD&gt;false&lt;/TD&gt;&lt;TD&gt;true&lt;/TD&gt;&lt;TD&gt;feature:quarantine_files&lt;/TD&gt;&lt;TD&gt;update&lt;/TD&gt;&lt;TD&gt;/system/default/web-features.conf&lt;/TD&gt;&lt;TD&gt;2023-09-08&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;enable_search_v2_endpoint&lt;/TD&gt;&lt;TD&gt;false&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;feature:search_v2_endpoint&lt;/TD&gt;&lt;TD&gt;update&lt;/TD&gt;&lt;TD&gt;/system/default/web-features.conf&lt;/TD&gt;&lt;TD&gt;2023-09-08&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;enable_share_job_control&lt;/TD&gt;&lt;TD&gt;true&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;feature:share_job&lt;/TD&gt;&lt;TD&gt;update&lt;/TD&gt;&lt;TD&gt;/system/default/web-features.conf&lt;/TD&gt;&lt;TD&gt;2023-09-08&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;enable_show_hide&lt;/TD&gt;&lt;TD&gt;true&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;feature:dashboard_studio&lt;/TD&gt;&lt;TD&gt;update&lt;/TD&gt;&lt;TD&gt;/system/default/web-features.conf&lt;/TD&gt;&lt;TD&gt;2023-09-08&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;enable_triggered_alerts_vnext&lt;/TD&gt;&lt;TD&gt;true&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;feature:page_migration&lt;/TD&gt;&lt;TD&gt;update&lt;/TD&gt;&lt;TD&gt;/system/default/web-features.conf&lt;/TD&gt;&lt;TD&gt;2023-09-08&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;enable_unsupported_hotlinked_imports&lt;/TD&gt;&lt;TD&gt;false&lt;/TD&gt;&lt;TD&gt;true&lt;/TD&gt;&lt;TD&gt;feature:quarantine_files&lt;/TD&gt;&lt;TD&gt;update&lt;/TD&gt;&lt;TD&gt;/system/default/web-features.conf&lt;/TD&gt;&lt;TD&gt;2023-09-08&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;internal.dashboards_trusted_domain.flowmilldocs&lt;/TD&gt;&lt;TD&gt;docs.flowmill.com&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;feature:dashboards_csp&lt;/TD&gt;&lt;TD&gt;update&lt;/TD&gt;&lt;TD&gt;/system/default/web-features.conf&lt;/TD&gt;&lt;TD&gt;2023-09-08&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;internal.dashboards_trusted_domain.rigorhelp&lt;/TD&gt;&lt;TD&gt;help.rigor.com&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;feature:dashboards_csp&lt;/TD&gt;&lt;TD&gt;update&lt;/TD&gt;&lt;TD&gt;/system/default/web-features.conf&lt;/TD&gt;&lt;TD&gt;2023-09-08&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;internal.dashboards_trusted_domain.splunkapps&lt;/TD&gt;&lt;TD&gt;apps.splunk.com&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;feature:dashboards_csp&lt;/TD&gt;&lt;TD&gt;update&lt;/TD&gt;&lt;TD&gt;/system/default/web-features.conf&lt;/TD&gt;&lt;TD&gt;2023-09-08&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;internal.dashboards_trusted_domain.splunkbase&lt;/TD&gt;&lt;TD&gt;splunkbase.com&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;feature:dashboards_csp&lt;/TD&gt;&lt;TD&gt;update&lt;/TD&gt;&lt;TD&gt;/system/default/web-features.conf&lt;/TD&gt;&lt;TD&gt;2023-09-08&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;internal.dashboards_trusted_domain.splunkbasesplunk&lt;/TD&gt;&lt;TD&gt;splunkbase.splunk.com&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;feature:dashboards_csp&lt;/TD&gt;&lt;TD&gt;update&lt;/TD&gt;&lt;TD&gt;/system/default/web-features.conf&lt;/TD&gt;&lt;TD&gt;2023-09-08&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;internal.dashboards_trusted_domain.splunkdev&lt;/TD&gt;&lt;TD&gt;dev.splunk.com&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;feature:dashboards_csp&lt;/TD&gt;&lt;TD&gt;update&lt;/TD&gt;&lt;TD&gt;/system/default/web-features.conf&lt;/TD&gt;&lt;TD&gt;2023-09-08&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;internal.dashboards_trusted_domain.splunkdocs&lt;/TD&gt;&lt;TD&gt;docs.splunk.com&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;feature:dashboards_csp&lt;/TD&gt;&lt;TD&gt;update&lt;/TD&gt;&lt;TD&gt;/system/default/web-features.conf&lt;/TD&gt;&lt;TD&gt;2023-09-08&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;internal.dashboards_trusted_domain.splunkdownload&lt;/TD&gt;&lt;TD&gt;&lt;A href="http://www.splunk.com/download" target="_blank" rel="noopener"&gt;www.splunk.com/download&lt;/A&gt;&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;feature:dashboards_csp&lt;/TD&gt;&lt;TD&gt;update&lt;/TD&gt;&lt;TD&gt;/system/default/web-features.conf&lt;/TD&gt;&lt;TD&gt;2023-09-08&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;internal.dashboards_trusted_domain.splunklantern&lt;/TD&gt;&lt;TD&gt;lantern.splunk.com&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;feature:dashboards_csp&lt;/TD&gt;&lt;TD&gt;update&lt;/TD&gt;&lt;TD&gt;/system/default/web-features.conf&lt;/TD&gt;&lt;TD&gt;2023-09-08&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;internal.dashboards_trusted_domain.splunkproducts&lt;/TD&gt;&lt;TD&gt;&lt;A href="http://www.splunk.com/products" target="_blank" rel="noopener"&gt;www.splunk.com/products&lt;/A&gt;&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;feature:dashboards_csp&lt;/TD&gt;&lt;TD&gt;update&lt;/TD&gt;&lt;TD&gt;/system/default/web-features.conf&lt;/TD&gt;&lt;TD&gt;2023-09-08&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;internal.dashboards_trusted_domain.splunkui&lt;/TD&gt;&lt;TD&gt;splunkui.splunk.com&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;feature:dashboards_csp&lt;/TD&gt;&lt;TD&gt;update&lt;/TD&gt;&lt;TD&gt;/system/default/web-features.conf&lt;/TD&gt;&lt;TD&gt;2023-09-08&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;internal.dashboards_trusted_domain.victoropshelp&lt;/TD&gt;&lt;TD&gt;help.victorops.com&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;feature:dashboards_csp&lt;/TD&gt;&lt;TD&gt;update&lt;/TD&gt;&lt;TD&gt;/system/default/web-features.conf&lt;/TD&gt;&lt;TD&gt;2023-09-08&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;I see that you just upgraded from 8 to 9 so this new index doesn't contain data from your upgrade. &amp;nbsp;But you can manually ingest $SPLUNK_HOME/var/log/splunkd/migration.log.* as a one-time job, then do a similar search&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;source=*/splunk/migration.log.* (data.path=*/system/default/web-features.conf)
| spath path=data.changes{}
| fields - data.changes{}.*
| mvexpand data.changes{}
| spath input=data.changes{}
| spath input=data.changes{} path=properties{}
| fields - properties{}.*
| mvexpand properties{}
| spath input=properties{}
| stats latest(*_value) as *_value by data.action name stanza data.path _time
| eval data.path = replace('data.path', ".*/[sS]plunk/etc", "")
| fieldformat _time = strftime(_time, "%F")
| table name *_value stanza data.* _time&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If your system has lots of history, the output will be numerous. &amp;nbsp;You should probably limit search to the last archived migration.log. (The current one is created after your upgrade, so historic data is not in.)&lt;/P&gt;&lt;P&gt;Hope this helps&lt;/P&gt;</description>
      <pubDate>Mon, 11 Sep 2023 15:40:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Why-does-Splunk-assist-constantly-fail-on-9-1-0-1-version-after/m-p/657167#M13243</guid>
      <dc:creator>yuanliu</dc:creator>
      <dc:date>2023-09-11T15:40:11Z</dc:date>
    </item>
  </channel>
</rss>

