All Apps and Add-ons

"No spec file" errors when trying to deploy Splunk Add-on for VMware from the index master node

keio_splunk
Splunk Employee
Splunk Employee

VMware data collection is working fine but when pushing out Splunk Add-on for VMware from the index master node the following warnings are reported:
[Not Critical]No spec file for: /app/splunk/etc/master-apps/Splunk_TA_esxilogs/default/eventgen.conf
[Not Critical]No spec file for: /app/splunk/etc/master-apps/Splunk_TA_vcenter/default/eventgen.conf

alt text

splunkd.log:
WARN CMBundleMgr - Bundle validation warnings bundle=/app/splunk/var/run/splunk/cluster/remote-bundle/2ea968f32581661ba4910e8e0322176f-1542938006.bundle, err=[Not Critical]No spec file for: /app/splunk/etc/master-apps/Splunk_TA_esxilogs/default/eventgen.conf\n;[Not Critical]No spec file for: /app/splunk/etc/master-apps/Splunk_TA_vcenter/default/eventgen.conf\n

Why are the warnings generated?

0 Karma
1 Solution

keio_splunk
Splunk Employee
Splunk Employee

The warnings thrown by the cluster master is expected behavior and can be safely ignored.
The eventgen.conf in Splunk_TA_esxilogs and Splunk_TA_vcenter are used for generating dummy data along with SA-Eventgen which will provide the spec file(eventgen.conf.spec).

View solution in original post

keio_splunk
Splunk Employee
Splunk Employee

The warnings thrown by the cluster master is expected behavior and can be safely ignored.
The eventgen.conf in Splunk_TA_esxilogs and Splunk_TA_vcenter are used for generating dummy data along with SA-Eventgen which will provide the spec file(eventgen.conf.spec).

Get Updates on the Splunk Community!

Index This | Why did the turkey cross the road?

November 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...