All Apps and Add-ons

Deploying Splunk_TA_Windows Add-on to Cluster Errors With "No Spec File"

snowmizer
Communicator

I am trying to deploy the latest version of the Splunk_TA_Windows Add-on (from July 30, 2014) to my cluster. When I deploy the bundle I get the messages:

TSTSplunkCM01.int.hlc.com:No spec file for: /opt/splunk/etc/master-apps/Splunk_TA_windows/default/admon.conf

TSTSplunkCM01.int.hlc.com:No spec file for: /opt/splunk/etc/master-apps/Splunk_TA_windows/default/eventgen.conf

...

This same error shows up for the perfmon.conf, regmon-filters.conf, paletteinputs.conf, palettepallettes.conf, palettepanels.conf, palettesearches.conf and splunk_msftapp.conf. These errors prevent the configuration bundle from being distributed.

Has anyone else seen this message and how did you fix it?

Thanks.

alt text

1 Solution

snowmizer
Communicator

Actually we figured out that the problem was the "Invalid key..." message from the inputs.conf file. Once I commented out these lines in the default inputs.conf file all messages disappeared.

View solution in original post

snowmizer
Communicator

Actually we figured out that the problem was the "Invalid key..." message from the inputs.conf file. Once I commented out these lines in the default inputs.conf file all messages disappeared.

pwmcity
Path Finder

Hey I'm having the exact same issues
(http://answers.splunk.com/answers/154933/no-spec-file-and-invalid-key-in-stanza-when-pushing-windows...)

Are you saying that once you comment out the invalid stanza keys (useEnglishOnly) in the default\inputs.conf (which are disabled anyway), then the other errors (no spec file) are ignored and the apps push to the cluster?

I'm just trying to figure out the minimum changes required to the default app (to preserve upgrade path) that it will deploy without errors.

0 Karma

RicoSuave
Builder

Have you checked your indexers in the cluster to make sure it did not get pushed out? Usually we will just warn about typos in conf files though this shouldn't prevent a bundle from being pushed out.

0 Karma
Get Updates on the Splunk Community!

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...