All Apps and Add-ons

An error occurred while installing the app: 500

ralphw_SAIC
Path Finder

Just upgraded Splunk from 7.0.0 to 7.1.0 and now whenever i try to update an app I receive "An error occurred while installing the app: 500" and instead of the app name in the response I get "Note: Updating None from Splunkbase might cause Splunk Enterprise to restart."

The server has internet access with no proxy. Anyone have an idea how to fix?

Tags (1)

sylax
Explorer

An error occurred while installing the app: 500 means that the app you are trying to install from the splunk web have a different file owner/permission from the user being used.

Change the app owner to the owner running splunkd

SSH into the server and chown -R your_splunk_user:your_splunk_group $SPLUNK_HOME/etc/apps/app_name

 

0 Karma

niemesrw
Path Finder

Seeing the same issue here but with 6.6.3. I'm in AWS with my instance, no errors within _internal I can find. I'm going to check VPC flow logs and see if it's making the connection at all.

0 Karma

hortonew
Builder

Are you upgrading the app from the left side app listing, or are you going into manage apps first, then upgrading. I noticed that the app name isn't passed along to the upgrade section if you were on the Splunk home page and trying to upgrade from that screen. You'd have to go into manage apps first, then upgrade. Let me know.

0 Karma

ralphw_SAIC
Path Finder

I have done it both ways. Yes, left side app listing is blank. Trying it from the manage apps does who the name. both ways fail with the same result.

0 Karma

jkat54
SplunkTrust
SplunkTrust

Is it just with one app or all apps you try to upgrade?

0 Karma

ralphw_SAIC
Path Finder

all apps are affected by this.

0 Karma

jkat54
SplunkTrust
SplunkTrust

Are the filesystem permissions correct in /opt/splunk/etc/apps?

Check the owner of the files, compare to the user splunk is running as.

0 Karma

ralphw_SAIC
Path Finder

/opt/splunk and all directories underneath are owned by the user running splunk.

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...