Newish Splunk server still under Eval. We are looking to capture Exchange events so we loaded that module along with Sideview. When we attempt to open that view, we get the following ...
"Splunk encountered the following unknown module: "SideviewUtils" . The view may not load properly"
We are on Splunk version 4.3 and Sideview 1.3.4 and all addins are enabled. Any help would be appreciated.
Yea, to pick up new UI modules you actually need to restart only the splunkWeb server, and restarting splunkd on the other hand wont have any effect. In general when there's any doubt restart both...
I think it's just that he hasn't restarted. After an app install Splunkd goes to great lengths to tell the user when they need to restart to pick up new eventtypes and whatnot, but I think custom modules are an exception. Since custom modules have nothing to do with splunkd I dont think users are ever prompted to restart.
The sideview_utils directory needs to be in $SPLUNK_HOME/etc/apps - $SPLUNK_HOME is wherever you have installed Splunk. On my Linux system, this is /opt/splunk/etc/apps/sideview_utils. On my Windows system, this is C:\Program Files\Splunk\etc\apps\sideview_utils.
In addition, if you are unpacking the Sideview Utils outside of the Splunk UI, then you need to restart splunk - use "splunk restart" to do this.
Ok, I deleted the folder and re-downloaded, extrated, and copied it up. Still getting the same error. I tried version 1.3.3 as well, same result. It does show up in the Manage Apps and appears properly.