Installation

Cannot start splunkweb.exe after upgrade to 5.0

phillipulberg
Explorer

installed version was 4.3.4, started the 5.0 installer, selected option to let the installer upgrade my current installation. After installer completed the web interface was unavailable, i went and checked the services and "splunkweb" was not running, when I tried to start the service it errored out, here is the error from the application log in the event viewer -

Log Name:      Application
Source:        Splunkweb
Date:          10/30/2012 4:50:24 PM
Event ID:      3
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      ATL-LOGMGMT-01.dtiad.local
Description:
The instance's SvcRun() method failed 
  File "C:\Program Files\Splunk\Python-2.7\Lib\site-packages\win32\win32serviceutil.py", line 785, in SvcRun
    self.SvcDoRun()
  File "C:\Program Files\Splunk\bin\SplunkWebService.py", line 39, in SvcDoRun
    from splunk.appserver.mrsparkle import root
  File "C:\Program Files\Splunk\Python-2.7\Lib\site-packages\splunk\appserver\mrsparkle\root.py", line 556, in <module>
    sys.exit(1) 
<type 'exceptions.SystemExit'>: 1
Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  <System>
    <Provider Name="Splunkweb" />
    <EventID Qualifiers="49152">3</EventID>
    <Level>2</Level>
    <Task>0</Task>
    <Keywords>0x80000000000000</Keywords>
    <TimeCreated SystemTime="2012-10-30T20:50:24.000000000Z" />
    <EventRecordID>2646</EventRecordID>
    <Channel>Application</Channel>
    <Computer>ATL-LOGMGMT-01.dtiad.local</Computer>
    <Security />
  </System>
  <EventData>
    <Data>  File "C:\Program Files\Splunk\Python-2.7\Lib\site-packages\win32\win32serviceutil.py", line 785, in SvcRun
    self.SvcDoRun()
  File "C:\Program Files\Splunk\bin\SplunkWebService.py", line 39, in SvcDoRun
    from splunk.appserver.mrsparkle import root
  File "C:\Program Files\Splunk\Python-2.7\Lib\site-packages\splunk\appserver\mrsparkle\root.py", line 556, in &lt;module&gt;
    sys.exit(1)</Data>
    <Data>&lt;type 'exceptions.SystemExit'&gt;</Data>
    <Data>1</Data>
  </EventData>
</Event>
Tags (1)
1 Solution

malmoore
Splunk Employee
Splunk Employee

Hi,

Take a look at %SPLUNK_HOME%/var/log/splunk/web_service.log and see if there are any errors there.

View solution in original post

malmoore
Splunk Employee
Splunk Employee

Hi,

Take a look at %SPLUNK_HOME%/var/log/splunk/web_service.log and see if there are any errors there.

andrew_garvin
Path Finder

I had the exact same issue upgrading from 4.3.3 to 5.0. Coping TA_Windows_FTR AND TA_Windows_IFrame as Windows_FTR AND Windows_IFrame resolved the issue.

0 Karma

malmoore
Splunk Employee
Splunk Employee

Okay, that's cool. But, if you would, please open a ticket with Splunk support anyway and reference all the information on this page, including what you had to do to get splunkweb to start correctly. Thanks!

0 Karma

phillipulberg
Explorer

I renamed the folder and had to rename another folder in the same path TA_Windows_FTR to Windows_FTR. The splunkweb service now starts correctly.

0 Karma

malmoore
Splunk Employee
Splunk Employee

Okay, can you make a copy of that folder (and all its contents) and rename it to "Windows_IFrame" and let me know what happens?

Were you running the Windows app prior to your upgrade?

phillipulberg
Explorer

the log shows this error -

2012-10-30 16:50:24,191 ERROR [50903d8ff122e33c8] root:555 - [Error 3] The system cannot find the path specified: 'C:\\Program Files\\Splunk\\etc\\apps\\Splunk_TA_windows\\appserver\\modules\\Windows_IFrame/*.*'

The path is correct up to the last folder, the path shows Windows_IFrame, but the folder on the file system is called TA_Windows_IFrame

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...