Splunk Enterprise

After license agree show error

MarioLaul
New Member

Hi,

What can i do wrong or why show me this errors?

Software License Agreement 05022017     1 
Do you agree with this license? [y/n]: y

This appears to be your first time running this version of Splunk.
Moving '/opt/splunk/share/splunk/search_mrsparkle/modules.new' to '/opt/splunk/share/splunk/search_mrsparkle/modules'.

An unforeseen error occurred:

    Exception: <type 'exceptions.OSError'>, Value: [Errno 1] Operation not permitted: '/opt/splunk/share/splunk/search_mrsparkle/modules.new'

Traceback (most recent call last):
  File "/opt/splunk/lib/python2.7/site-packages/splunk/clilib/cli.py", line 1153, in main
    parseAndRun(argsList)
  File "/opt/splunk/lib/python2.7/site-packages/splunk/clilib/cli.py", line 1000, in parseAndRun
    retVal = cList.getCmd(command, subCmd).call(argList, fromCLI = True)
  File "/opt/splunk/lib/python2.7/site-packages/splunk/clilib/cli.py", line 280, in call
    return self.func(args, fromCLI)
  File "/opt/splunk/lib/python2.7/site-packages/splunk/clilib/control_api.py", line 30, in wrapperFunc
    return func(dictCopy, fromCLI)
  File "/opt/splunk/lib/python2.7/site-packages/splunk/clilib/_internal.py", line 176, in firstTimeRun
    comm.moveItem(migration.PATH_UI_MOD_NEW, migration.PATH_UI_MOD_ACTIVE)
  File "/opt/splunk/lib/python2.7/site-packages/splunk/clilib/cli_common.py", line 991, in moveItem
    ensureDeletable(src)
  File "/opt/splunk/lib/python2.7/site-packages/splunk/clilib/cli_common.py", line 1028, in ensureDeletable
    os.chmod(oneItem, os.stat(oneItem).st_mode | stat.S_IWRITE)
OSError: [Errno 1] Operation not permitted: '/opt/splunk/share/splunk/search_mrsparkle/modules.new'


Please file a case online at http://www.splunk.com/page/submit_issue
Tags (1)
0 Karma
1 Solution

harsmarvania57
Ultra Champion

As best practice run splunk as "splunk" user so please create splunk user & group on your server, then change /opt/splunk/ permission globally with below command.

chown -R splunk:splunk /opt/splunk/

And start splunk with "splunk" user.

Let me know if you will face any issue.

View solution in original post

0 Karma

harsmarvania57
Ultra Champion

As best practice run splunk as "splunk" user so please create splunk user & group on your server, then change /opt/splunk/ permission globally with below command.

chown -R splunk:splunk /opt/splunk/

And start splunk with "splunk" user.

Let me know if you will face any issue.

0 Karma

rjollet
New Member

It works once I change to the user Splunk
Thank you for your help

0 Karma

rjollet
New Member

I got the same issue using fedora 26. I install Splunk using the .rpm installer

0 Karma

harsmarvania57
Ultra Champion

From which user you are trying to start splunk and also mention splunk version?

0 Karma

rjollet
New Member

version: Splunk 6.6.3
user: rjollet

0 Karma

harsmarvania57
Ultra Champion

Hi,

It looks like some permission issue on server. Can you please let us know how you installed splunk? Which os? And from which user you are trying to start splunk?

Thanks,
Harshil

0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...