Deployment Architecture

Why am I unable to start the Splunk Monitoring Console?

bdicarlo
Engager

Every time I try to enable the Splunk Monitoring Console, I get the following error:

User 'splunk-system-user' triggered the 'disable' action on app 'splunk_monitoring_console', and the following objects required a restart: checklist, dmc_alerts, splunk_monitoring_console_assets

It doesn't matter if we try via the API or the config files upon restarting splunk, the application's state in app.conf is set to disabled.

I am running Splunk version 6.5.1.2 with search head clustering enabled. Any ideas on how we can get the app to start?

1 Solution

jcrabb_splunk
Splunk Employee
Splunk Employee

If you are trying to enable it on a Search Head Cluster, it cannot be installed there. Here is the relevant section for our docs:

https://docs.splunk.com/Documentation/Splunk/6.5.2/DMC/WheretohostDMC#In_a_search_head_cluster_envir...

The Monitoring Console cannot be on a search head cluster member. The app is disabled on startup on a search head cluster member.

Here is a guide on where to host it at:

https://docs.splunk.com/Documentation/Splunk/6.5.2/DMC/WheretohostDMC

Jacob
Sr. Technical Support Engineer

View solution in original post

jcrabb_splunk
Splunk Employee
Splunk Employee

If you are trying to enable it on a Search Head Cluster, it cannot be installed there. Here is the relevant section for our docs:

https://docs.splunk.com/Documentation/Splunk/6.5.2/DMC/WheretohostDMC#In_a_search_head_cluster_envir...

The Monitoring Console cannot be on a search head cluster member. The app is disabled on startup on a search head cluster member.

Here is a guide on where to host it at:

https://docs.splunk.com/Documentation/Splunk/6.5.2/DMC/WheretohostDMC

Jacob
Sr. Technical Support Engineer
Get Updates on the Splunk Community!

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer at Splunk .conf24 ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...

Combine Multiline Logs into a Single Event with SOCK: a Step-by-Step Guide for ...

Combine multiline logs into a single event with SOCK - a step-by-step guide for newbies Olga Malita The ...