<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to resolve messages about 'File Integrity checks' for Splunk files in Monitoring Splunk</title>
    <link>https://community.splunk.com/t5/Monitoring-Splunk/How-to-resolve-messages-about-File-Integrity-checks-for-Splunk/m-p/208567#M2140</link>
    <description>&lt;P&gt;getting this too... I'm trying to clear any non-INFO issues logged in splunkd.log. Also trying to document things in my deployment by adding to README files (and commenting in other conf files) -- which of course changes the hash and triggers this WARNing. Most annoying...&lt;/P&gt;

&lt;P&gt;Wish there was a way to update the hashes for the "InstalledFilesHashChecker" hash table...&lt;/P&gt;

&lt;P&gt;6.5, cluster, deployment server, etc...&lt;/P&gt;

&lt;P&gt;BTW, Luke, the link you provided is for file monitoring, this is not that. This is a hash check at startup to compare existing files to a manifest of ones originally installed.&lt;/P&gt;</description>
    <pubDate>Wed, 30 Nov 2016 16:32:46 GMT</pubDate>
    <dc:creator>Michael</dc:creator>
    <dc:date>2016-11-30T16:32:46Z</dc:date>
    <item>
      <title>How to resolve messages about 'File Integrity checks' for Splunk files</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/How-to-resolve-messages-about-File-Integrity-checks-for-Splunk/m-p/208557#M2130</link>
      <description>&lt;P&gt;Getting this message "File Integrity checks found files that did not match the system-provided manifest. See splunkd.log for details."&lt;BR /&gt;
&lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/1891iD67797F4E7EC811D/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;Anyone seen this before? Any idea what it's about?&lt;/P&gt;

&lt;P&gt;Seeing this in the splunkd.log:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;09-24-2016 11:12:26.554 -0400 WARN  InstalledFilesHashChecker - An installed file="/opt/splunk/etc/log.cfg" did not pass hash-checking due to reason="content mismatch"
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;I'm using log-local.cfg so I'm wondering what I messed up here.&lt;/P&gt;</description>
      <pubDate>Sat, 24 Sep 2016 15:03:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/How-to-resolve-messages-about-File-Integrity-checks-for-Splunk/m-p/208557#M2130</guid>
      <dc:creator>sloshburch</dc:creator>
      <dc:date>2016-09-24T15:03:57Z</dc:date>
    </item>
    <item>
      <title>Re: How to resolve messages about 'File Integrity checks' for Splunk files</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/How-to-resolve-messages-about-File-Integrity-checks-for-Splunk/m-p/208558#M2131</link>
      <description>&lt;P&gt;What version of Splunk are you using?&lt;BR /&gt;
You can read about file system monitoring here:&lt;BR /&gt;
&lt;A href="http://docs.splunk.com/Documentation/Splunk/6.4.3/Data/Monitorchangestoyourfilesystem"&gt;http://docs.splunk.com/Documentation/Splunk/6.4.3/Data/Monitorchangestoyourfilesystem&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 26 Sep 2016 10:28:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/How-to-resolve-messages-about-File-Integrity-checks-for-Splunk/m-p/208558#M2131</guid>
      <dc:creator>lukejadamec</dc:creator>
      <dc:date>2016-09-26T10:28:50Z</dc:date>
    </item>
    <item>
      <title>Re: How to resolve messages about 'File Integrity checks' for Splunk files</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/How-to-resolve-messages-about-File-Integrity-checks-for-Splunk/m-p/208559#M2132</link>
      <description>&lt;P&gt;This actually isn't the FIM feature. Looks like something else but I'm checking if it's just a bug.&lt;/P&gt;</description>
      <pubDate>Mon, 26 Sep 2016 13:32:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/How-to-resolve-messages-about-File-Integrity-checks-for-Splunk/m-p/208559#M2132</guid>
      <dc:creator>sloshburch</dc:creator>
      <dc:date>2016-09-26T13:32:52Z</dc:date>
    </item>
    <item>
      <title>Re: How to resolve messages about 'File Integrity checks' for Splunk files</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/How-to-resolve-messages-about-File-Integrity-checks-for-Splunk/m-p/208560#M2133</link>
      <description>&lt;P&gt;is there a search head cluster involved?&lt;/P&gt;</description>
      <pubDate>Mon, 26 Sep 2016 13:58:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/How-to-resolve-messages-about-File-Integrity-checks-for-Splunk/m-p/208560#M2133</guid>
      <dc:creator>rsennett_splunk</dc:creator>
      <dc:date>2016-09-26T13:58:02Z</dc:date>
    </item>
    <item>
      <title>Re: How to resolve messages about 'File Integrity checks' for Splunk files</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/How-to-resolve-messages-about-File-Integrity-checks-for-Splunk/m-p/208561#M2134</link>
      <description>&lt;P&gt;SHC is being used and it appears this is only happening there now. Checking if the config over there is good. Running on 6.5.0.&lt;/P&gt;</description>
      <pubDate>Tue, 04 Oct 2016 12:18:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/How-to-resolve-messages-about-File-Integrity-checks-for-Splunk/m-p/208561#M2134</guid>
      <dc:creator>sloshburch</dc:creator>
      <dc:date>2016-10-04T12:18:08Z</dc:date>
    </item>
    <item>
      <title>Re: How to resolve messages about 'File Integrity checks' for Splunk files</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/How-to-resolve-messages-about-File-Integrity-checks-for-Splunk/m-p/208562#M2135</link>
      <description>&lt;P&gt;Is there already a solution to this error? I'm getting the same messages and the splunkd.log is not informative.&lt;/P&gt;</description>
      <pubDate>Tue, 11 Oct 2016 07:53:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/How-to-resolve-messages-about-File-Integrity-checks-for-Splunk/m-p/208562#M2135</guid>
      <dc:creator>mbschriek</dc:creator>
      <dc:date>2016-10-11T07:53:19Z</dc:date>
    </item>
    <item>
      <title>Re: How to resolve messages about 'File Integrity checks' for Splunk files</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/How-to-resolve-messages-about-File-Integrity-checks-for-Splunk/m-p/208563#M2136</link>
      <description>&lt;P&gt;Using Splunk 6.5 (clustered environment) here and also getting the messages.&lt;/P&gt;

&lt;P&gt;At https://[your_splunk]:8089/services/server/status//installed-file-integrity you can find an overview of the files that did not match the system-provided manifest.&lt;/P&gt;

&lt;P&gt;Looks like default files that were changed.&lt;/P&gt;</description>
      <pubDate>Thu, 13 Oct 2016 14:57:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/How-to-resolve-messages-about-File-Integrity-checks-for-Splunk/m-p/208563#M2136</guid>
      <dc:creator>sanderdenheijer</dc:creator>
      <dc:date>2016-10-13T14:57:35Z</dc:date>
    </item>
    <item>
      <title>Re: How to resolve messages about 'File Integrity checks' for Splunk files</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/How-to-resolve-messages-about-File-Integrity-checks-for-Splunk/m-p/208564#M2137</link>
      <description>&lt;P&gt;Great catch! Root cause was some stuff I was screwing around with in regards to the &lt;CODE&gt;introspection_generator_addon&lt;/CODE&gt; and &lt;CODE&gt;user-prefs&lt;/CODE&gt; which were blowing away the default config. So, this is all my fault but thanks for catching the endpoint which exposed the root cause!&lt;/P&gt;</description>
      <pubDate>Fri, 14 Oct 2016 22:22:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/How-to-resolve-messages-about-File-Integrity-checks-for-Splunk/m-p/208564#M2137</guid>
      <dc:creator>sloshburch</dc:creator>
      <dc:date>2016-10-14T22:22:35Z</dc:date>
    </item>
    <item>
      <title>Re: How to resolve messages about 'File Integrity checks' for Splunk files</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/How-to-resolve-messages-about-File-Integrity-checks-for-Splunk/m-p/208565#M2138</link>
      <description>&lt;P&gt;Your info helped me out too &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 17 Oct 2016 15:55:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/How-to-resolve-messages-about-File-Integrity-checks-for-Splunk/m-p/208565#M2138</guid>
      <dc:creator>machiel</dc:creator>
      <dc:date>2016-10-17T15:55:26Z</dc:date>
    </item>
    <item>
      <title>Re: How to resolve messages about 'File Integrity checks' for Splunk files</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/How-to-resolve-messages-about-File-Integrity-checks-for-Splunk/m-p/208566#M2139</link>
      <description>&lt;P&gt;Me too! I (changed the metadata file to promote/share view but it was no more usefull anyway). Thanx.&lt;/P&gt;</description>
      <pubDate>Fri, 25 Nov 2016 09:28:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/How-to-resolve-messages-about-File-Integrity-checks-for-Splunk/m-p/208566#M2139</guid>
      <dc:creator>fab73</dc:creator>
      <dc:date>2016-11-25T09:28:06Z</dc:date>
    </item>
    <item>
      <title>Re: How to resolve messages about 'File Integrity checks' for Splunk files</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/How-to-resolve-messages-about-File-Integrity-checks-for-Splunk/m-p/208567#M2140</link>
      <description>&lt;P&gt;getting this too... I'm trying to clear any non-INFO issues logged in splunkd.log. Also trying to document things in my deployment by adding to README files (and commenting in other conf files) -- which of course changes the hash and triggers this WARNing. Most annoying...&lt;/P&gt;

&lt;P&gt;Wish there was a way to update the hashes for the "InstalledFilesHashChecker" hash table...&lt;/P&gt;

&lt;P&gt;6.5, cluster, deployment server, etc...&lt;/P&gt;

&lt;P&gt;BTW, Luke, the link you provided is for file monitoring, this is not that. This is a hash check at startup to compare existing files to a manifest of ones originally installed.&lt;/P&gt;</description>
      <pubDate>Wed, 30 Nov 2016 16:32:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/How-to-resolve-messages-about-File-Integrity-checks-for-Splunk/m-p/208567#M2140</guid>
      <dc:creator>Michael</dc:creator>
      <dc:date>2016-11-30T16:32:46Z</dc:date>
    </item>
    <item>
      <title>Re: How to resolve messages about 'File Integrity checks' for Splunk files</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/How-to-resolve-messages-about-File-Integrity-checks-for-Splunk/m-p/208568#M2141</link>
      <description>&lt;P&gt;That's a great example. I think in mine, it's just the meta files. Both shouldn't be so dramatic IMO. If you open a case on this, ask support to link to SPL-133233.&lt;/P&gt;</description>
      <pubDate>Wed, 30 Nov 2016 19:14:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/How-to-resolve-messages-about-File-Integrity-checks-for-Splunk/m-p/208568#M2141</guid>
      <dc:creator>sloshburch</dc:creator>
      <dc:date>2016-11-30T19:14:24Z</dc:date>
    </item>
    <item>
      <title>Re: How to resolve messages about 'File Integrity checks' for Splunk files</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/How-to-resolve-messages-about-File-Integrity-checks-for-Splunk/m-p/208569#M2142</link>
      <description>&lt;P&gt;A peer of mine, Justin, showed me that &lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/Admin/Limitsconf"&gt;limits.conf&lt;/A&gt; has a setting, &lt;CODE&gt;installed_files_integrity&lt;/CODE&gt;, that controls if the integrity items are exposed to the UI, splunkd.log, or not at all. I consider this a win!&lt;/P&gt;</description>
      <pubDate>Tue, 31 Jan 2017 14:15:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/How-to-resolve-messages-about-File-Integrity-checks-for-Splunk/m-p/208569#M2142</guid>
      <dc:creator>sloshburch</dc:creator>
      <dc:date>2017-01-31T14:15:52Z</dc:date>
    </item>
    <item>
      <title>Re: How to resolve messages about 'File Integrity checks' for Splunk files</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/How-to-resolve-messages-about-File-Integrity-checks-for-Splunk/m-p/208570#M2143</link>
      <description>&lt;P&gt;I get following the above url "404: Page not found".  I don't have any "installed-file-integrity" page&lt;/P&gt;</description>
      <pubDate>Wed, 22 Feb 2017 00:56:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/How-to-resolve-messages-about-File-Integrity-checks-for-Splunk/m-p/208570#M2143</guid>
      <dc:creator>borkborkbork</dc:creator>
      <dc:date>2017-02-22T00:56:59Z</dc:date>
    </item>
    <item>
      <title>Re: How to resolve messages about 'File Integrity checks' for Splunk files</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/How-to-resolve-messages-about-File-Integrity-checks-for-Splunk/m-p/208571#M2144</link>
      <description>&lt;P&gt;Sounds like you might have gone to the wrong URI or port. Wanna past the URL here?&lt;/P&gt;</description>
      <pubDate>Mon, 27 Feb 2017 19:56:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/How-to-resolve-messages-about-File-Integrity-checks-for-Splunk/m-p/208571#M2144</guid>
      <dc:creator>sloshburch</dc:creator>
      <dc:date>2017-02-27T19:56:09Z</dc:date>
    </item>
    <item>
      <title>Re: How to resolve messages about 'File Integrity checks' for Splunk files</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/How-to-resolve-messages-about-File-Integrity-checks-for-Splunk/m-p/208572#M2145</link>
      <description>&lt;P&gt;I don't think we posted this on here yet, but here's some background: &lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/Admin/ChecktheintegrityofyourSplunksoftwarefiles"&gt;http://docs.splunk.com/Documentation/Splunk/latest/Admin/ChecktheintegrityofyourSplunksoftwarefiles&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 22 Mar 2017 20:43:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/How-to-resolve-messages-about-File-Integrity-checks-for-Splunk/m-p/208572#M2145</guid>
      <dc:creator>sloshburch</dc:creator>
      <dc:date>2017-03-22T20:43:22Z</dc:date>
    </item>
    <item>
      <title>Re: How to resolve messages about 'File Integrity checks' for Splunk files</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/How-to-resolve-messages-about-File-Integrity-checks-for-Splunk/m-p/208573#M2146</link>
      <description>&lt;BLOCKQUOTE&gt;
&lt;P&gt;./splunk validate files&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;</description>
      <pubDate>Tue, 28 Mar 2017 19:52:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/How-to-resolve-messages-about-File-Integrity-checks-for-Splunk/m-p/208573#M2146</guid>
      <dc:creator>vskoryk_splunk</dc:creator>
      <dc:date>2017-03-28T19:52:08Z</dc:date>
    </item>
    <item>
      <title>Re: How to resolve messages about 'File Integrity checks' for Splunk files</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/How-to-resolve-messages-about-File-Integrity-checks-for-Splunk/m-p/208574#M2147</link>
      <description>&lt;P&gt;Yes! In fact, we just had the docs team include this banner message's text in our docs. So hopefully anyone else running into this will more easily find the docs in an internet search:&lt;BR /&gt;
&lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/Admin/ChecktheintegrityofyourSplunksoftwarefiles#Interpret_results_of_an_integrity_check"&gt;http://docs.splunk.com/Documentation/Splunk/latest/Admin/ChecktheintegrityofyourSplunksoftwarefiles#Interpret_results_of_an_integrity_check&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 31 Mar 2017 12:17:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/How-to-resolve-messages-about-File-Integrity-checks-for-Splunk/m-p/208574#M2147</guid>
      <dc:creator>sloshburch</dc:creator>
      <dc:date>2017-03-31T12:17:43Z</dc:date>
    </item>
    <item>
      <title>Re: How to resolve messages about 'File Integrity checks' for Splunk files</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/How-to-resolve-messages-about-File-Integrity-checks-for-Splunk/m-p/208575#M2148</link>
      <description>&lt;P&gt;I received this error after following another thread that stated you uninstall apps by disabling them, removing the folders from ./etc/apps and then restarting. Any idea how to fix this?&lt;/P&gt;</description>
      <pubDate>Mon, 08 May 2017 14:57:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/How-to-resolve-messages-about-File-Integrity-checks-for-Splunk/m-p/208575#M2148</guid>
      <dc:creator>adepasquale</dc:creator>
      <dc:date>2017-05-08T14:57:24Z</dc:date>
    </item>
    <item>
      <title>Re: How to resolve messages about 'File Integrity checks' for Splunk files</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/How-to-resolve-messages-about-File-Integrity-checks-for-Splunk/m-p/208576#M2149</link>
      <description>&lt;P&gt;@adepasquale - The message means that files that come with Splunk (listed in the manifest file) were changed after install. This might mean you removed a required app like the launcher or search app. Tread carefully there and make you everything in a base install exists. Alternatively, use the answers listed in this post to hide the messages and/or learn how to learn what files were changed.&lt;/P&gt;</description>
      <pubDate>Tue, 09 May 2017 13:10:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/How-to-resolve-messages-about-File-Integrity-checks-for-Splunk/m-p/208576#M2149</guid>
      <dc:creator>sloshburch</dc:creator>
      <dc:date>2017-05-09T13:10:49Z</dc:date>
    </item>
  </channel>
</rss>

