All Apps and Add-ons

Splunk App for Unix and Linux 5.0.0 incompatible with *NIX 4.6?

micm
Explorer

As I am missing a lot of views of the "old" app like Log Files and Configs in the new version 5.0.0, I restored the *NIX 4.6 app to use it in parallel with the Splunk App for Unix 5.0.0. When opening the *NIX 4.6 app in the splunk webinterface I get the following error message. In the *NIX 4.6 app all inputs are disabled, so why does it conflict with the splunk add on for *NIX? And more important how can I get rid of the error message as it prevents me from using the app.

The app "Splunk Add-on for *Nix" is
installed on this system.

The Splunk *nix App and the "Splunk
Add-on for *Nix" app cannot exist
together on the same Splunk instance.

Please click on Manage Apps to disable
the conflicting app, then remove
"Splunk Add-on for *Nix" from
$SPLUNK_HOME/etc/apps and restart
Splunk.

0 Karma

micm
Explorer

Thanks Lucas. I checked it but the ids have been different.

Guess I was too tired yesterday as it is rather simple. In unix/appserver/modules/Unix_FTR/Unix_FTR.py there is a variable CONFLICT_APPS that includes Splunk_TA_nix. I removed that as well as the corresponding entry in the Splunk_TA_nix app and it is working now after a restart.

0 Karma

Lucas_K
Motivator

Check and modify the package id stanza in app.conf in each of the app's default dirs.
They need to be different, it doesn't matter than much what you use (as long as they don't conflict with another app). You can just change them so they are unique and the warnings should disappear.

It is quite possible there there is something extra that is checked somewhere as it is a splunk inc. app.

As I don't have the original v4 *nix archive so I can't check the original app.conf myself but we do use multiple different installs of the *nix app this way.

0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...