Deployment Architecture

splunk validate cluster-bundle fails with "no spec file" but spec exists

droth333
Explorer

Hi!
Why on splunk validate cluster-bundle do I get these errors:

No spec file for: /opt/splunk/etc/master-apps/SA-ldapsearch/local/ldap.conf
No spec file for: /opt/splunk/etc/master-apps/SA-ldapsearch/default/ldap.conf
No spec file for: /opt/splunk/etc/master-apps/SA-ldapsearch/default/logging.conf
No spec file for: /opt/splunk/etc/master-apps/SA-ldapsearch/default/ssl.conf

But the corresponding apps README has:

[splunk@scsplunkdeploy1 README]$ ls -l
total 16
-rwxrwxr-x 1 splunk splunk 3971 Nov 4 11:58 ldap.conf.spec
-rwxrwxr-x 1 splunk splunk 5616 Nov 4 11:58 logging.conf.spec
-rwxrwxr-x 1 splunk splunk 1588 Nov 4 11:58 ssl.conf.spec

How do I fix this?

Thanks,
Dave

0 Karma

jkat54
SplunkTrust
SplunkTrust

Seems awkward. What happens if you remove the spec files? I have a suspicion the warning goes away. In either case it doesn't matter and can be ignored.

0 Karma
Get Updates on the Splunk Community!

Index This | When is October more than just the tenth month?

October 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

What’s New & Next in Splunk SOAR

 Security teams today are dealing with more alerts, more tools, and more pressure than ever.  Join us for an ...