Deployment Architecture

How to resolve error "A script exited abnormally" after updating serverclass.conf?

Hemnaath
Motivator

Hi All, Can anyone guide us in how to fix this problem? We updated the serverclass.conf recently via deployment server and this message started popping out after updating the serverclass.conf in one of the Splunk search head instances.

"A script exited abnormally" input="$SPLUNK_HOME/etc/apps/TEST-ADMIN-all_indexers/bin/install.sh" stanza="default" status="exited with code 127"

When checked in the particular Splunk instance under /opt/splunk/etc/apps/ this particular app detail was missing "TEST-ADMIN-all_indexers" but this app is still there in Splunk Web -- Manage Apps -- TEST-ADMIN-all_indexers still in enable state. So by disabling and restarting the Splunk service, will it fix this issue or we need to try some other method to fix this?

Splunk version 6.2.1

Thanks in advance.

0 Karma
1 Solution

Hemnaath
Motivator

Hi All, we have fixed the issue after disabling and restarting the splunk instance. After this process the message vanished from splunk web portal. The reason behind the message due recent update in serverclass.conf where we have removed this particular app from the splunk instance but app was there enabled still in the splunk web portal.

View solution in original post

0 Karma

Hemnaath
Motivator

Hi All, we have fixed the issue after disabling and restarting the splunk instance. After this process the message vanished from splunk web portal. The reason behind the message due recent update in serverclass.conf where we have removed this particular app from the splunk instance but app was there enabled still in the splunk web portal.

0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...