Installation

Cannot start with etc/users directory which has upper case character='.DS_Store'

nlloyd
Engager

Hi all,

I'm getting this error periodically with my local Splunk Enterprise installation in Mac OS. I've resorted to just reinstalling when this happened in the past but I'd like to avoid that and understand the cause / fix. 

Splunk was running but seemed to hand when I tried to restart from the webUI. After that I get this error when trying to start. If I try to stop via CLI I it says splunkd is not running.

Help is very much appreciated as this is getting to be a real pain. 

Labels (3)
0 Karma

terechen
Engager

.DS_Store is a hidden file that macOS automatically creates in directories to store custom attributes and metadata about a folder. These files are specific to macOS and are generally not needed for application functionality. In the Splunk application directory (/Applications/Splunk/etc/users), these .DS_Store files were likely created by Finder when browsing these directories.
Thanks @nlloyd, deleting that file works!

0 Karma

isoutamo
SplunkTrust
SplunkTrust
Which macOS and splunk versions you have? And Intel or Mx series workstation you have? I have never seen this, but neither browse those directories with Finder, I just use cli.
0 Karma

nlloyd
Engager

Quick update: I manually removed '.DS_Store' from the etc/users directory and could then start. I'm not sure why this issue keeps coming up but that's at least an easier fix than reinstalling.

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Agent Mode Engaged! Enchaining Agentic Operations with Splunk AI Assistant 2.0

    Are you ready to transform how your team handles complex data requests? We invite you to our upcoming ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...