All Apps and Add-ons

Splunk AI Toolkit / Splunk_SA_Scientific_Python - challenging upgrade

NullZero
Communicator

IHAC with a C13 SVA instance, I recently upgraded them from Splunk MLTK 5.x to Splunk AI Toolkit 6.0.2 to modernise and neutralise the recently published CVE exposure. Splunk Enterprise is on version 10.2.6 on RHEL 8 so all recent and properly up-to-date. You also have a dependency of the 'Splunk_SA_Scientific_Python_linux_x86_64'  with this new version.

At first there was a problem pushing the large bundle for the SA from the SH Deployer to the SHC, and I received the following error which is easily solvable in the same way that a large ES image install is fixed:

Error while deploying apps to target=https://<server>:8089 with members=3: Error while updating app=Splunk_SA_Scientific_Python_linux_x86_64 on target=https://<server>:8089: Non-200/201 status_code=413; {\"messages\":[{\"type\":\"ERROR\",\"text\":\"Content-Length of 2147496687 too large (maximum is 2147483648)\"}]}, Error while updating app=Splunk_SA_Scientific_Python_linux_x86_64 on target=https://<server>:8089: Non-200/201 status_code=413; {\"messages\":[{\"type\":\"ERROR\",\"text\":\"Content-Length of 2147496687 too large (maximum is 2147483648)


Fix 1: Updated the Search Head TA and pushed this from the deployer after temporarily removing the SA from the deployment folder. I ended up making the changes on the deployer and the SH as it didn't work the first time and nothing lost

web.conf
[settings]
max_upload_size = 4096

 
This change got me further forward but it would still not allow the large push and I saw a new error. I also noted the the size on disk on the Deployer was approx. 3.6GB and on the SHC 1.5GB.

Error while deploying apps to target=https://<server>:8089 with members=3: Error while updating app=Splunk_SA_Scientific_Python_linux_x86_64 on target=https://<server>:8089: Error in JSON response: Unexpected EOF, Error while updating app=Splunk_SA_Scientific_Python_linux_x86_64 on target=https://<server>:8089: Error in JSON response: Unexpected EOF

Fix 2: update server.conf and http stanza:

server.conf
[httpServer]
max_content_length = 5000000000

 I did make a silly mistake here and had a zero missing making it 0.5GB upload as opposed to 5GB. After that the push worked and the error message on the dependency in the UI went away (the message related to the requirement for the Splunk_SA_Scientific_Python).

Final problem:
I am unable to see any models in the UI, my understanding is that the models are just the .csv files in the lookups folder in the AI toolkit app, but I have not personally been the end user.

- I updated app.conf on the deployer for the AI toolkit and added:
deployer_lookups_push_mode =always_overwrite
- This did push the updated csv's and I can see all the dates match.
- I have checked the docs and I can only see remediation action required for windows
- It could conceivably be related to RBAC, but I've change one item and I'm not seeing a difference as an admin.
- I have also just noticed that there is a new version as of 25 August, I will upgrade to that to eliminate possible problems: Splunk AI Toolkit | Splunkbase

Labels (1)
Tags (1)
0 Karma
1 Solution

Coach_CND
Engager

Looking at that error I would recommend reviewing if the roles that need the ability to list machine learning models have the list_models capability.

Solution: You must have thelist_models capability turned on to view available machine learning models when you upgrade to AITK version 6.0.2. The Audit - MLTK models saved search is configured to run under the admin namespace, so you must turn on the list_models capability for the admin user.

Troubleshoot upgrading AI Toolkit in Splunk Enterprise Security | Platform (last updated 2026-09-01T...

View solution in original post

0 Karma

Coach_CND
Engager

Looking at that error I would recommend reviewing if the roles that need the ability to list machine learning models have the list_models capability.

Solution: You must have thelist_models capability turned on to view available machine learning models when you upgrade to AITK version 6.0.2. The Audit - MLTK models saved search is configured to run under the admin namespace, so you must turn on the list_models capability for the admin user.

Troubleshoot upgrading AI Toolkit in Splunk Enterprise Security | Platform (last updated 2026-09-01T...

0 Karma

NullZero
Communicator

Thanks @Coach_CND this capability "list_models" was indeed the fix. 

0 Karma

NullZero
Communicator

For the benefit of the community I found this further data:

Troubleshoot upgrading AI Toolkit in Splunk Enterprise Security

Machine learning models not displayed upon upgrade

Issue: Splunk Enterprise Security version 8.7 is compatible with Splunk AI Toolkit (AITK) version 6.0.2 and Python Scientific Computing (PSC) version 3.3.3. However, after upgrading to AITK 6.0.2, you can't view machine learning models by default. The Machine learning models table on the Machine learning audit dashboard is empty and custom searches that list machine learning models stop working.

Cause: The list_models capability must be turned on for roles that need the ability to list machine learning models.

Solution: You must have thelist_models capability turned on to view available machine learning models when you upgrade to AITK version 6.0.2. The Audit - MLTK models saved search is configured to run under the admin namespace, so you must turn on the list_models capability for the admin user.


I would note that the capability is not listed generally in Splunk by default:

Define roles on the Splunk platform with capabilities - Splunk 10.4

 

0 Karma

NullZero
Communicator

Still no improvement with the updated version from Splunkbase

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Supercharging Windows Security Detection Performance: Introducing Hybrid Field ...

Windows event logs—from Security auditing and Sysmon to PowerShell script blocks—form the operational backbone ...

Ditch the Manual Grind: Building AI Agents with Splunk

Ditch the Manual Grind: Building AI Agents with Splunk Let’s be real: your team’s time is being eaten alive. ...

Cisco Data Fabric from Architecture to Investigation, Better SOC Visibility, and More ...

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...