Installation

Cannot start with etc/users directory which has upper case character='.DS_Store'

nlloyd
Engager

Hi all,

I'm getting this error periodically with my local Splunk Enterprise installation in Mac OS. I've resorted to just reinstalling when this happened in the past but I'd like to avoid that and understand the cause / fix. 

Splunk was running but seemed to hand when I tried to restart from the webUI. After that I get this error when trying to start. If I try to stop via CLI I it says splunkd is not running.

Help is very much appreciated as this is getting to be a real pain. 

Labels (3)
0 Karma

terechen
Engager

.DS_Store is a hidden file that macOS automatically creates in directories to store custom attributes and metadata about a folder. These files are specific to macOS and are generally not needed for application functionality. In the Splunk application directory (/Applications/Splunk/etc/users), these .DS_Store files were likely created by Finder when browsing these directories.
Thanks @nlloyd, deleting that file works!

0 Karma

isoutamo
SplunkTrust
SplunkTrust
Which macOS and splunk versions you have? And Intel or Mx series workstation you have? I have never seen this, but neither browse those directories with Finder, I just use cli.
0 Karma

nlloyd
Engager

Quick update: I manually removed '.DS_Store' from the etc/users directory and could then start. I'm not sure why this issue keeps coming up but that's at least an easier fix than reinstalling.

Get Updates on the Splunk Community!

Splunk at Cisco Live 2025: Learning, Innovation, and a Little Bit of Mr. Brightside

Pack your bags (and maybe your dancing shoes)—Cisco Live is heading to San Diego, June 8–12, 2025, and Splunk ...

Splunk App Dev Community Updates – What’s New and What’s Next

Welcome to your go-to roundup of everything happening in the Splunk App Dev Community! Whether you're building ...

The Latest Cisco Integrations With Splunk Platform!

Join us for an exciting tech talk where we’ll explore the latest integrations in Cisco + Splunk! We’ve ...