Deployment Architecture

HTTP Event Collector through Deployment Server

sk314
Builder

I followed the instructions on this page for scenario 3 - http://dev.splunk.com/view/event-collector/SP-CAAAE73#scen3
however, when I try to add the splunk_httpinput app to a new serverclass for my deployment clients - I get an error that I haven't configured app.conf for the app. I tried to add a dummy app.conf and it still fails with the same error.

The exact error: File='/opt/splunk/etc/deployment-apps/splunk_httpinput/local/app.conf', needed for application=splunk_httpinput, not found

I am on v6.5.1

Is this a known issue? Any workaround? What am I missing?

Tags (2)
0 Karma
1 Solution

sk314
Builder

Although the app.conf is not a part of the folder - creating a dummy app.conf seems to have done the trick. I had to change the ownership of app.conf to splunk user and the error vanished.

View solution in original post

0 Karma

sk314
Builder

Although the app.conf is not a part of the folder - creating a dummy app.conf seems to have done the trick. I had to change the ownership of app.conf to splunk user and the error vanished.

0 Karma

somesoni2
Revered Legend

The step3 says this

Copy the entire current $SPLUNK_HOME/etc/apps/splunk_httpinput/ directory into $SPLUNK_HOME/etc/deployment-apps/. (On Windows, copy the entire current %SPLUNK_HOME%\etc\apps\splunk_httpinput\ directory into %SPLUNK_HOME%\etc\deployment-apps\.) This is a one-time step that is necessary on the deployment server.

Did you copy the whole splunk_httpinput app which comes with Splunk Enterprise? This will have all the components required, including valid app.conf.

0 Karma

sk314
Builder

I did indeed. The folder only has an inputs.conf in both default and local folder and the metadata folder.

0 Karma
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...