I upgraded Splunk on Splunk and Sideview Utils to the latest versions and now SoS is erroring:
"This instance of Splunk does not have the Sideview Utils app installed."
Clicking the install sideview utils button tells me that I have it installed. Anyone else having this problem?
@dagryph Thank you!! Once i madbe it visible on the search head with SoS, then SoS started working again !!
Got it. I'll see if I can reproduce this in-house.
Ticket 80350.
@tyronetv : Ok this confirms that SVU is present and visible from splunkd's perspective. Could you please open a support case and attach a splunk diag as well as the output of %SPLUNK_HOME%\bin\splunk _internal call /services/apps/local
? Let me know the case number here when you have it.
gettingstarted CONFIGURED ENABLED VISIBLE
launcher CONFIGURED ENABLED VISIBLE
learned UNCONFIGURED ENABLED INVISIBLE
legacy UNCONFIGURED DISABLED INVISIBLE
sample_app UNCONFIGURED DISABLED INVISIBLE
search CONFIGURED ENABLED VISIBLE
sideview_utils UNCONFIGURED ENABLED VISIBLE
sos UNCONFIGURED ENABLED VISIBLE
splunk_datapreview CONFIGURED ENABLED INVISIBLE
SplunkDeploymentMonitor CONFIGURED ENABLED VISIBLE
SplunkForwarder UNCONFIGURED DISABLED INVISIBLE
SplunkLightForwarder UNCONFIGURED DISABLED INVISIBLE
ufx CONFIGURED ENABLED VISIBLE
webmon UNCONFIGURED ENABLED VISIBLE
windows UNCONFIGURED DISABLED VISIBLE
That should not happen if you start your command line session by right-clicking on the "Command Prompt" icon and selecting "run as administrator".
Restart didn't fix it. 😞
For some reason, I can't redirect the output on my windows install. Splunk.exe always spawns a new command window and bypasses my redirect. I will work on getting you those outputs.
Yes please try a restart.
If this doesn't help, could you provide the output of %SPLUNK_HOME%\bin\splunk display app
? Another output that would be interesting to see, although it is a bit longer, is that of %SPLUNK_HOME%\bin\splunk _internal call /services/apps/local
.
Yes. Both the admin account and my personal account each have their TZ set in their user profiles.
I unset (i.e. set it to Default) for Admin but still get the "you need to install..." message screen. Maybe a restart. I don't know. 🙂
This is strange. Just out of curiosity, could you check if the per-user time zone of the admin user (or of any other user) has been set to anything else than "system default" in Manager » Your account
.
I have installed SVU 1.3.4 and SoS 2.1.0 on a Windows 2008 R2 install of Splunk 4.3.1.
Every execution of SoS results in "This instance of Splunk does not have Sideview Utils app installed."
I have done the 'bump' and created $SPUNK_HOME/etc/apps/sideview_utils/local/app.conf with the is_visible = 1 entry to no avail.
Has anyone figured this out yet? Was a ticket ever opened? Do I need to open one?
Make sure the Sideview Utils (SVU) app is visible from the perspective of the UI. If it's invisible, it makes it unavailable to SoS. Once it's made visible on the search head with SoS, then SoS started working again for us.
When SVU has in $SPLUNK_HOME/etc/apps/sideview_utils/local/app.conf
:
[ui]
is_visible = false
...the checks for SVU in SoS will fail and you will see complaints that Sideview is not installed. In contrast, when SVU's app.conf contains :
[ui]
is_visible = true
...then SoS can detect SVU and will work as expected.
This worked for me on 4.2.5. Thanks.
If you are running one of the early version of 4.2, you might need to restart Splunk or to force an app refresh for that change to take effect.
At any rate, if you open a support case please let me know its number.
No Dice for me. in the [ui] section there was no is_visible, I put it in but it didn't work. Will enter a support case soon.
@dagryph : Splendid find, I think you nailed it.
@mcantrell, @dschreck, @bobdoyle : Could you please confirm that this is indeed the issue you are seeing?
@mcantrell : Thank you for the additional information. Let me know what the case # is once it is opened. So, just to be clear, where does this message show up exactly? A screenshot would be great.
I tried the bump and it didn't seem to have any effect. I also noticed that SoS 2.1.0 was available so I upgraded and it still has the problem. I'll open a support case later today and update this thread.
I'm having the same issue. I just upgraded to Splunk 4.3 (on Windows), then went about upgrading my Apps.
I upgraded SoS from 1.x (not sure exactly) to 2.1.0. this did not require restarting Splunk. I then upgraded Sideview Utils from 1.2.4 to 1.2.5, again no restart was required. When I run SoS now i get the error that Sideview Utils is not installed.
I tried the _bump, but it didn't help.
Thank you, I'll try to reproduce your scenario. One other thing I'll ask you to do is to hit the splunkweb static resources endpoint @ http[s]://[splunkweb_host]:[splunkweb_port]/_bump
. Please bump the cache version there and try to access SoS again. If this doesn't work, please open a support case and let me know its number. I'll pick it up and we can address the issue in that fashion.