All Apps and Add-ons

Why am I getting "No spec file" errors trying to deploy Splunk App for VMware via cluster-bundle?

mikelanghorst
Motivator

In deploying the VMWare app to clustered indexers, I'm currently getting the following errors, when attempting to "splunk apply cluster-bundle". This is preventing the apply, and halting our progress:

In handler 'clustermastercontrol': No spec file for: /app/splunk/splunk_cm8189/etc/mas ter-apps/SA-Hydra/local/hydra_gateway.conf
;No spec file for: /app/splunk/splunk_cm8189/etc/master-apps/SA-Hydra/local/hydra_node .conf
; Possible typo in stanza [keyindicator] in /app/splunk/splunk_cm8189/et c/master-apps/SA-Utils/local/alert_actions.conf, line 4: title

Anyone see this, or have a resolution? Opening a case, but pasting this here so I can come back later with the resolution.

0 Karma
1 Solution

mikelanghorst
Motivator

After talking with Masa from support, he pointed out the "/local" in my path above, and that it shouldn't be included when deploying from the cluster-master. A co-worker had previously extracted the files into this location and I didn't realize it.

For the lack of a spec file, the option "--skip-validation" is available to allow it to continue to apply the bundle. However this makes me a bit nervous.

I ended up deploying this manually into the regular etc/apps directory for now.

View solution in original post

0 Karma

mikelanghorst
Motivator

After talking with Masa from support, he pointed out the "/local" in my path above, and that it shouldn't be included when deploying from the cluster-master. A co-worker had previously extracted the files into this location and I didn't realize it.

For the lack of a spec file, the option "--skip-validation" is available to allow it to continue to apply the bundle. However this makes me a bit nervous.

I ended up deploying this manually into the regular etc/apps directory for now.

0 Karma
Get Updates on the Splunk Community!

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...