Installation

First Time Running Error - Mac OS.

wcgage
Path Finder

Trying to install and run for the first time on my Mac Mini.

Here is my error:

Williams-Mac-mini:bin williamgage$ ./splunk start --accept-license

This appears to be your first time running this version of Splunk.
Moving '/Applications/Splunk/share/splunk/search_mrsparkle/modules.new' to '/Applications/Splunk/share/splunk/search_mrsparkle/modules'.

An unforeseen error occurred:

Exception: <type 'exceptions.OSError'>, Value: [Errno 1] Operation not permitted: '/Applications/Splunk/share/splunk/search_mrsparkle/modules.new'

Traceback (most recent call last):
File "/Applications/Splunk/lib/python2.7/site-packages/splunk/clilib/cli.py", line 1157, in main
parseAndRun(argsList)
File "/Applications/Splunk/lib/python2.7/site-packages/splunk/clilib/cli.py", line 1004, in parseAndRun
retVal = cList.getCmd(command, subCmd).call(argList, fromCLI = True)
File "/Applications/Splunk/lib/python2.7/site-packages/splunk/clilib/cli.py", line 280, in call
return self.func(args, fromCLI)
File "/Applications/Splunk/lib/python2.7/site-packages/splunk/clilib/control_api.py", line 30, in wrapperFunc
return func(dictCopy, fromCLI)
File "/Applications/Splunk/lib/python2.7/site-packages/splunk/clilib/_internal.py", line 172, in firstTimeRun
comm.moveItem(migration.PATH_UI_MOD_NEW, migration.PATH_UI_MOD_ACTIVE)
File "/Applications/Splunk/lib/python2.7/site-packages/splunk/clilib/cli_common.py", line 942, in moveItem
ensureDeletable(src)
File "/Applications/Splunk/lib/python2.7/site-packages/splunk/clilib/cli_common.py", line 979, in ensureDeletable
os.chmod(oneItem, os.stat(oneItem).st_mode | stat.S_IWRITE)
OSError: [Errno 1] Operation not permitted: '/Applications/Splunk/share/splunk/search_mrsparkle/modules.new'

Please file a case online at http://www.splunk.com/page/submit_issue

I've checked file permissions, and made sure that everything is Read/Write for myself and the admins.

Would love to know what's going on!!!

Labels (1)
0 Karma
1 Solution

wcgage
Path Finder

chown the splunk directory for Admins

View solution in original post

wcgage
Path Finder

chown the splunk directory for Admins

zakxu8
New Member

hi, i have same problem, but my splunk directory is already Admins. so anyone solution for me? thx

0 Karma

Raghav2384
Motivator

Please chown the directory to the user:group and try to do what you were doing.

Thanks,
Raghav

wcgage
Path Finder

Once I chown for the admin group, all is well!

0 Karma

Raghav2384
Motivator

Please accept the answer that helped you, @Mus's or @Raghav2384's 🙂

Hope this helps!

Thanks,
Raghav

0 Karma

MuS
SplunkTrust
SplunkTrust

Is the read/write permission also granted to the user running Splunk? Check /Applications/Splunk/etc/splunk-lauch.conffor the OS_USERsetting to see the user that will run Splunk - most likely it will be splunk

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

How much can you really learn in 3 minutes?

Observability can certainly be hard to understand – there's a lot of jargon and buzzwords and it seems to ...

Event Series: The Agentic SOC: Trust Before Autonomy

AI is fundamentally changing security operations, but true progress requires more than just automation—it ...

Free Professional Services for .conf26 Attendees

This year at .conf26, we are doing something a little different. We are bringing the best minds from ...