<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Why is pgrade Failing with OSError type 28? in Splunk Enterprise Security</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Why-is-pgrade-Failing-with-OSError-type-28/m-p/569684#M10334</link>
    <description>&lt;P&gt;Hello All,&lt;/P&gt;
&lt;P&gt;I am testing the upgrade from ES 6.2.0 to 6.6.2.&amp;nbsp; When I do the upgrade it fails with OSError type 28 no space left of device.&amp;nbsp; But there is almost 30GB of disk space free.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;2021-10-04 19:18:28,028 INFO    [615bb5deed7f2dc4595650] _cplogging:216 - [04/Oct/2021:19:18:28] HTTP
Request Headers:
  Remote-Addr: 127.0.0.1
  TE: chunked
  HOST: splunk-sh1.wv.mentorg.com:8000
  ACCEPT-ENCODING: gzip, br
  CACHE-CONTROL: max-age=0
  SEC-CH-UA: "Google Chrome";v="93", " Not;A Brand";v="99", "Chromium";v="93"
  SEC-CH-UA-MOBILE: ?0
  SEC-CH-UA-PLATFORM: "Windows"
  UPGRADE-INSECURE-REQUESTS: 1
  ORIGIN: null
  USER-AGENT: Mozilla/5.0 (Windows NT 6.3; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/93.0.4577.82 Safari/537.36
  ACCEPT: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9
  SEC-FETCH-SITE: same-origin
  SEC-FETCH-MODE: navigate
  SEC-FETCH-USER: ?1
  SEC-FETCH-DEST: document
  ACCEPT-LANGUAGE: en-US,en;q=0.9
  COOKIE: splunkweb_csrf_token_8000=[REDACTED]5649; session_id_8000=[REDACTED]5b74; token_key=[REDACTED]5649; experience_id=[REDACTED]b0c2; splunkd_8000=[REDACTED]tgchx
  REMOTE-USER: admin
  X-SPLUNKD: SKdIpkhtf8PlfUDwvOLunA== 11626949294704615649 ijbs1HY^4Ms541EE5sF6eqHg^iyD5t6QKZRByWhdMDXkj546^eB1lT6y59b9LewgHbLcz0Xa5SKotHijcl__zWhYqh8MZISrCqYVxuLkY7jijwyyXijSUQ9VAJRlcQA3o7tgchx 0
  Content-Type: multipart/form-data; boundary=----WebKitFormBoundaryO0HdVIPxgJr5HUZN
  Content-Length: 675766277
2021-10-04 19:18:28,029 INFO    [615bb5deed7f2dc4595650] error:333 - POST /en-US/manager/appinstall/_upload 127.0.0.1 8065
2021-10-04 19:18:28,029 INFO    [615bb5deed7f2dc4595650] error:334 - 500 Internal Server Error The server encountered an unexpected condition which prevented it from fulfilling the request.
2021-10-04 19:18:28,029 ERROR   [615bb5deed7f2dc4595650] error:335 - Traceback (most recent call last):
  File "/opt/splunk/lib/python3.7/site-packages/cherrypy/_cprequest.py", line 628, in respond
    self._do_respond(path_info)
  File "/opt/splunk/lib/python3.7/site-packages/cherrypy/_cprequest.py", line 680, in _do_respond
    self.body.process()
  File "/opt/splunk/lib/python3.7/site-packages/cherrypy/_cpreqbody.py", line 982, in process
    super(RequestBody, self).process()
  File "/opt/splunk/lib/python3.7/site-packages/cherrypy/_cpreqbody.py", line 559, in process
    proc(self)
  File "/opt/splunk/lib/python3.7/site-packages/cherrypy/_cpreqbody.py", line 225, in process_multipart_form_data
    process_multipart(entity)
  File "/opt/splunk/lib/python3.7/site-packages/cherrypy/_cpreqbody.py", line 217, in process_multipart
    part.process()
  File "/opt/splunk/lib/python3.7/site-packages/cherrypy/_cpreqbody.py", line 557, in process
    self.default_proc()
  File "/opt/splunk/lib/python3.7/site-packages/cherrypy/_cpreqbody.py", line 717, in default_proc
    self.file = self.read_into_file()
  File "/opt/splunk/lib/python3.7/site-packages/cherrypy/_cpreqbody.py", line 732, in read_into_file
    self.read_lines_to_boundary(fp_out=fp_out)
  File "/opt/splunk/lib/python3.7/site-packages/cherrypy/_cpreqbody.py", line 702, in read_lines_to_boundary
    fp_out.write(line)
OSError: [Errno 28] No space left on device&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As you can see there should be plenty of room for a 670MB upload&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;splunk@splunk-sh1:~/var/log/splunk&amp;gt; df -kh /opt/splunk
Filesystem                 Size  Used Avail Use% Mounted on
/dev/mapper/system-splunk   74G   44G   27G  63% /opt
splunk@splunk-sh1:~/var/log/splunk&amp;gt;&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Web.conf&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;splunk@splunk-sh1:~/var/log/splunk&amp;gt; more ~/etc/system/local/web.conf
[settings]
login_content = &amp;lt;h1&amp;gt; &amp;lt;CENTER&amp;gt;Splunk Dev Search Head&amp;lt;/CENTER&amp;gt; &amp;lt;/h1&amp;gt;
max_upload_size = 1024
enableSplunkWebSSL = 1
privKeyPath = /opt/splunk/etc/auth/splunkweb/com.key
caCertPath = /opt/splunk/etc/auth/splunkweb/expJun2022.crt
splunkdConnectionTimeout = 1400
tools.sessions.timeout = 180
sslVersions = ssl3,tls
cipherSuite = TLSv1+HIGH:TLSv1.2+HIGH:@STRENGTH

splunk@splunk-sh1:~/var/log/splunk&amp;gt;&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So I am confused why it would say that there is no space left of the device.&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;ed&lt;/P&gt;</description>
    <pubDate>Mon, 28 Aug 2023 18:12:31 GMT</pubDate>
    <dc:creator>edwardrose</dc:creator>
    <dc:date>2023-08-28T18:12:31Z</dc:date>
    <item>
      <title>Why is pgrade Failing with OSError type 28?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Why-is-pgrade-Failing-with-OSError-type-28/m-p/569684#M10334</link>
      <description>&lt;P&gt;Hello All,&lt;/P&gt;
&lt;P&gt;I am testing the upgrade from ES 6.2.0 to 6.6.2.&amp;nbsp; When I do the upgrade it fails with OSError type 28 no space left of device.&amp;nbsp; But there is almost 30GB of disk space free.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;2021-10-04 19:18:28,028 INFO    [615bb5deed7f2dc4595650] _cplogging:216 - [04/Oct/2021:19:18:28] HTTP
Request Headers:
  Remote-Addr: 127.0.0.1
  TE: chunked
  HOST: splunk-sh1.wv.mentorg.com:8000
  ACCEPT-ENCODING: gzip, br
  CACHE-CONTROL: max-age=0
  SEC-CH-UA: "Google Chrome";v="93", " Not;A Brand";v="99", "Chromium";v="93"
  SEC-CH-UA-MOBILE: ?0
  SEC-CH-UA-PLATFORM: "Windows"
  UPGRADE-INSECURE-REQUESTS: 1
  ORIGIN: null
  USER-AGENT: Mozilla/5.0 (Windows NT 6.3; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/93.0.4577.82 Safari/537.36
  ACCEPT: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9
  SEC-FETCH-SITE: same-origin
  SEC-FETCH-MODE: navigate
  SEC-FETCH-USER: ?1
  SEC-FETCH-DEST: document
  ACCEPT-LANGUAGE: en-US,en;q=0.9
  COOKIE: splunkweb_csrf_token_8000=[REDACTED]5649; session_id_8000=[REDACTED]5b74; token_key=[REDACTED]5649; experience_id=[REDACTED]b0c2; splunkd_8000=[REDACTED]tgchx
  REMOTE-USER: admin
  X-SPLUNKD: SKdIpkhtf8PlfUDwvOLunA== 11626949294704615649 ijbs1HY^4Ms541EE5sF6eqHg^iyD5t6QKZRByWhdMDXkj546^eB1lT6y59b9LewgHbLcz0Xa5SKotHijcl__zWhYqh8MZISrCqYVxuLkY7jijwyyXijSUQ9VAJRlcQA3o7tgchx 0
  Content-Type: multipart/form-data; boundary=----WebKitFormBoundaryO0HdVIPxgJr5HUZN
  Content-Length: 675766277
2021-10-04 19:18:28,029 INFO    [615bb5deed7f2dc4595650] error:333 - POST /en-US/manager/appinstall/_upload 127.0.0.1 8065
2021-10-04 19:18:28,029 INFO    [615bb5deed7f2dc4595650] error:334 - 500 Internal Server Error The server encountered an unexpected condition which prevented it from fulfilling the request.
2021-10-04 19:18:28,029 ERROR   [615bb5deed7f2dc4595650] error:335 - Traceback (most recent call last):
  File "/opt/splunk/lib/python3.7/site-packages/cherrypy/_cprequest.py", line 628, in respond
    self._do_respond(path_info)
  File "/opt/splunk/lib/python3.7/site-packages/cherrypy/_cprequest.py", line 680, in _do_respond
    self.body.process()
  File "/opt/splunk/lib/python3.7/site-packages/cherrypy/_cpreqbody.py", line 982, in process
    super(RequestBody, self).process()
  File "/opt/splunk/lib/python3.7/site-packages/cherrypy/_cpreqbody.py", line 559, in process
    proc(self)
  File "/opt/splunk/lib/python3.7/site-packages/cherrypy/_cpreqbody.py", line 225, in process_multipart_form_data
    process_multipart(entity)
  File "/opt/splunk/lib/python3.7/site-packages/cherrypy/_cpreqbody.py", line 217, in process_multipart
    part.process()
  File "/opt/splunk/lib/python3.7/site-packages/cherrypy/_cpreqbody.py", line 557, in process
    self.default_proc()
  File "/opt/splunk/lib/python3.7/site-packages/cherrypy/_cpreqbody.py", line 717, in default_proc
    self.file = self.read_into_file()
  File "/opt/splunk/lib/python3.7/site-packages/cherrypy/_cpreqbody.py", line 732, in read_into_file
    self.read_lines_to_boundary(fp_out=fp_out)
  File "/opt/splunk/lib/python3.7/site-packages/cherrypy/_cpreqbody.py", line 702, in read_lines_to_boundary
    fp_out.write(line)
OSError: [Errno 28] No space left on device&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As you can see there should be plenty of room for a 670MB upload&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;splunk@splunk-sh1:~/var/log/splunk&amp;gt; df -kh /opt/splunk
Filesystem                 Size  Used Avail Use% Mounted on
/dev/mapper/system-splunk   74G   44G   27G  63% /opt
splunk@splunk-sh1:~/var/log/splunk&amp;gt;&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Web.conf&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;splunk@splunk-sh1:~/var/log/splunk&amp;gt; more ~/etc/system/local/web.conf
[settings]
login_content = &amp;lt;h1&amp;gt; &amp;lt;CENTER&amp;gt;Splunk Dev Search Head&amp;lt;/CENTER&amp;gt; &amp;lt;/h1&amp;gt;
max_upload_size = 1024
enableSplunkWebSSL = 1
privKeyPath = /opt/splunk/etc/auth/splunkweb/com.key
caCertPath = /opt/splunk/etc/auth/splunkweb/expJun2022.crt
splunkdConnectionTimeout = 1400
tools.sessions.timeout = 180
sslVersions = ssl3,tls
cipherSuite = TLSv1+HIGH:TLSv1.2+HIGH:@STRENGTH

splunk@splunk-sh1:~/var/log/splunk&amp;gt;&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So I am confused why it would say that there is no space left of the device.&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;ed&lt;/P&gt;</description>
      <pubDate>Mon, 28 Aug 2023 18:12:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Why-is-pgrade-Failing-with-OSError-type-28/m-p/569684#M10334</guid>
      <dc:creator>edwardrose</dc:creator>
      <dc:date>2023-08-28T18:12:31Z</dc:date>
    </item>
    <item>
      <title>Re: Upgrade Failing with OSError type 28</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Why-is-pgrade-Failing-with-OSError-type-28/m-p/569692#M10335</link>
      <description>&lt;P&gt;I found this article&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.splunk.com/t5/Getting-Data-In/Tutorial-data-upload-error/m-p/214891" target="_blank"&gt;https://community.splunk.com/t5/Getting-Data-In/Tutorial-data-upload-error/m-p/214891&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I reduce the setting as stated to 4800 and the upgrade proceeded just fine.&lt;/P&gt;&lt;P&gt;Weird.&lt;/P&gt;</description>
      <pubDate>Tue, 05 Oct 2021 12:51:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Why-is-pgrade-Failing-with-OSError-type-28/m-p/569692#M10335</guid>
      <dc:creator>edwardrose</dc:creator>
      <dc:date>2021-10-05T12:51:12Z</dc:date>
    </item>
    <item>
      <title>Re: Upgrade Failing with OSError type 28</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Why-is-pgrade-Failing-with-OSError-type-28/m-p/585576#M10622</link>
      <description>&lt;P&gt;Had the same issue.&lt;/P&gt;&lt;P&gt;Cleared /tmp down and worked fine...&lt;/P&gt;&lt;P&gt;Can only assume splunk GUI loads to /tmp&lt;/P&gt;</description>
      <pubDate>Thu, 17 Feb 2022 14:42:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Why-is-pgrade-Failing-with-OSError-type-28/m-p/585576#M10622</guid>
      <dc:creator>smithy001</dc:creator>
      <dc:date>2022-02-17T14:42:46Z</dc:date>
    </item>
    <item>
      <title>Re: Upgrade Failing with OSError type 28</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Why-is-pgrade-Failing-with-OSError-type-28/m-p/655879#M11678</link>
      <description>&lt;P&gt;We managed to resolve the the "type 28 / 500 internal server" Enterprise Security installation error by cleaning out /tmp.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 28 Aug 2023 16:38:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Why-is-pgrade-Failing-with-OSError-type-28/m-p/655879#M11678</guid>
      <dc:creator>computermathguy</dc:creator>
      <dc:date>2023-08-28T16:38:24Z</dc:date>
    </item>
  </channel>
</rss>

