All Apps and Add-ons

Deploying Splunk_TA_Windows Add-on to Cluster Errors With "No Spec File"

snowmizer
SplunkTrust
SplunkTrust

I am trying to deploy the latest version of the Splunk_TA_Windows Add-on (from July 30, 2014) to my cluster. When I deploy the bundle I get the messages:

TSTSplunkCM01.int.hlc.com:No spec file for: /opt/splunk/etc/master-apps/Splunk_TA_windows/default/admon.conf

TSTSplunkCM01.int.hlc.com:No spec file for: /opt/splunk/etc/master-apps/Splunk_TA_windows/default/eventgen.conf

...

This same error shows up for the perfmon.conf, regmon-filters.conf, paletteinputs.conf, palettepallettes.conf, palettepanels.conf, palettesearches.conf and splunk_msftapp.conf. These errors prevent the configuration bundle from being distributed.

Has anyone else seen this message and how did you fix it?

Thanks.

alt text

1 Solution

snowmizer
SplunkTrust
SplunkTrust

Actually we figured out that the problem was the "Invalid key..." message from the inputs.conf file. Once I commented out these lines in the default inputs.conf file all messages disappeared.

View solution in original post

snowmizer
SplunkTrust
SplunkTrust

Actually we figured out that the problem was the "Invalid key..." message from the inputs.conf file. Once I commented out these lines in the default inputs.conf file all messages disappeared.

pwmcity
Path Finder

Hey I'm having the exact same issues
(http://answers.splunk.com/answers/154933/no-spec-file-and-invalid-key-in-stanza-when-pushing-windows...)

Are you saying that once you comment out the invalid stanza keys (useEnglishOnly) in the default\inputs.conf (which are disabled anyway), then the other errors (no spec file) are ignored and the apps push to the cluster?

I'm just trying to figure out the minimum changes required to the default app (to preserve upgrade path) that it will deploy without errors.

0 Karma

RicoSuave
Builder

Have you checked your indexers in the cluster to make sure it did not get pushed out? Usually we will just warn about typos in conf files though this shouldn't prevent a bundle from being pushed out.

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...