Getting Data In

"No spec file for" errors for the default configuration of Add-on

tom8h
Explorer

When I was about to deploy add-on directory from cluster-master to indexers, I got a lot of "No spec file for" errors.
I didn't change for default configuration so I don't know why I got the errors.

I checked the other environment which is installed same add-on as the above using "splunk btool check --debug" command then I got the same messages.

The error messages were below;

./splunk btool check --debug | grep -v Checking
No spec file for: /opt/splunk/etc/users/admin/splunk_app_db_connect/local/dbx-ui-conn-prefs.conf
No spec file for: /opt/splunk/etc/users/admin/splunk_app_db_connect/local/dbx-ui-prefs.conf
No spec file for: /opt/splunk/etc/users/admin/splunk_app_for_nix/local/nix_view_prefs.conf
No spec file for: /opt/splunk/etc/users/admin/splunk_app_for_nix/local/unix.conf
No spec file for: /opt/splunk/etc/apps/Splunk_TA_jmx/local/jmx_servers.conf
No spec file for: /opt/splunk/etc/apps/Splunk_TA_jmx/local/jmx_tasks.conf
No spec file for: /opt/splunk/etc/apps/Splunk_TA_jmx/local/jmx_templates.conf
...

Please kindly tell me how to resolve the above.

0 Karma

sdesruelles
Explorer

Hi tom8h,

Late reply but I just solve this for us two days ago.
First of all, those are just warnings so no worries.

You can remove that by adding an empty file XXX.spec in the README directory
for the first one, it would be /opt/splunk/etc/users/admin/splunk_app_db_connect/REAMDE/dbx-ui-conn-prefs.conf.spec

Best Regards,
S.

Get Updates on the Splunk Community!

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

🔐 Trust at Every Hop: How mTLS in Splunk Enterprise 10.0 Makes Security Simpler

From Idea to Implementation: Why Splunk Built mTLS into Splunk Enterprise 10.0  mTLS wasn’t just a checkbox ...