Splunk Enterprise

After license agree show error

MarioLaul
New Member

Hi,

What can i do wrong or why show me this errors?

Software License Agreement 05022017     1 
Do you agree with this license? [y/n]: y

This appears to be your first time running this version of Splunk.
Moving '/opt/splunk/share/splunk/search_mrsparkle/modules.new' to '/opt/splunk/share/splunk/search_mrsparkle/modules'.

An unforeseen error occurred:

    Exception: <type 'exceptions.OSError'>, Value: [Errno 1] Operation not permitted: '/opt/splunk/share/splunk/search_mrsparkle/modules.new'

Traceback (most recent call last):
  File "/opt/splunk/lib/python2.7/site-packages/splunk/clilib/cli.py", line 1153, in main
    parseAndRun(argsList)
  File "/opt/splunk/lib/python2.7/site-packages/splunk/clilib/cli.py", line 1000, in parseAndRun
    retVal = cList.getCmd(command, subCmd).call(argList, fromCLI = True)
  File "/opt/splunk/lib/python2.7/site-packages/splunk/clilib/cli.py", line 280, in call
    return self.func(args, fromCLI)
  File "/opt/splunk/lib/python2.7/site-packages/splunk/clilib/control_api.py", line 30, in wrapperFunc
    return func(dictCopy, fromCLI)
  File "/opt/splunk/lib/python2.7/site-packages/splunk/clilib/_internal.py", line 176, in firstTimeRun
    comm.moveItem(migration.PATH_UI_MOD_NEW, migration.PATH_UI_MOD_ACTIVE)
  File "/opt/splunk/lib/python2.7/site-packages/splunk/clilib/cli_common.py", line 991, in moveItem
    ensureDeletable(src)
  File "/opt/splunk/lib/python2.7/site-packages/splunk/clilib/cli_common.py", line 1028, in ensureDeletable
    os.chmod(oneItem, os.stat(oneItem).st_mode | stat.S_IWRITE)
OSError: [Errno 1] Operation not permitted: '/opt/splunk/share/splunk/search_mrsparkle/modules.new'


Please file a case online at http://www.splunk.com/page/submit_issue
Tags (1)
0 Karma
1 Solution

harsmarvania57
Ultra Champion

As best practice run splunk as "splunk" user so please create splunk user & group on your server, then change /opt/splunk/ permission globally with below command.

chown -R splunk:splunk /opt/splunk/

And start splunk with "splunk" user.

Let me know if you will face any issue.

View solution in original post

0 Karma

harsmarvania57
Ultra Champion

As best practice run splunk as "splunk" user so please create splunk user & group on your server, then change /opt/splunk/ permission globally with below command.

chown -R splunk:splunk /opt/splunk/

And start splunk with "splunk" user.

Let me know if you will face any issue.

0 Karma

rjollet
New Member

It works once I change to the user Splunk
Thank you for your help

0 Karma

rjollet
New Member

I got the same issue using fedora 26. I install Splunk using the .rpm installer

0 Karma

harsmarvania57
Ultra Champion

From which user you are trying to start splunk and also mention splunk version?

0 Karma

rjollet
New Member

version: Splunk 6.6.3
user: rjollet

0 Karma

harsmarvania57
Ultra Champion

Hi,

It looks like some permission issue on server. Can you please let us know how you installed splunk? Which os? And from which user you are trying to start splunk?

Thanks,
Harshil

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...