All Apps and Add-ons

Sideview Utils error on launch

RLFNetworkServi
Explorer

Newish Splunk server still under Eval. We are looking to capture Exchange events so we loaded that module along with Sideview. When we attempt to open that view, we get the following ...
"Splunk encountered the following unknown module: "SideviewUtils" . The view may not load properly"
We are on Splunk version 4.3 and Sideview 1.3.4 and all addins are enabled. Any help would be appreciated.

0 Karma

RLFNetworkServi
Explorer

I rebooted the server, looks like we're good to go. Services alone apparently were not enought. Thanks all.

0 Karma

sideview
SplunkTrust
SplunkTrust

Yea, to pick up new UI modules you actually need to restart only the splunkWeb server, and restarting splunkd on the other hand wont have any effect. In general when there's any doubt restart both...

ahall_splunk
Splunk Employee
Splunk Employee

The error message indicates that Sideview Utils is not installed properly.

sideview
SplunkTrust
SplunkTrust

I think it's just that he hasn't restarted. After an app install Splunkd goes to great lengths to tell the user when they need to restart to pick up new eventtypes and whatnot, but I think custom modules are an exception. Since custom modules have nothing to do with splunkd I dont think users are ever prompted to restart.

ahall_splunk
Splunk Employee
Splunk Employee

The sideview_utils directory needs to be in $SPLUNK_HOME/etc/apps - $SPLUNK_HOME is wherever you have installed Splunk. On my Linux system, this is /opt/splunk/etc/apps/sideview_utils. On my Windows system, this is C:\Program Files\Splunk\etc\apps\sideview_utils.

In addition, if you are unpacking the Sideview Utils outside of the Splunk UI, then you need to restart splunk - use "splunk restart" to do this.

RLFNetworkServi
Explorer

Ok, I deleted the folder and re-downloaded, extrated, and copied it up. Still getting the same error. I tried version 1.3.3 as well, same result. It does show up in the Manage Apps and appears properly.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...