Installation

How can I regenerate my package manifest file?

bohanlon_splunk
Splunk Employee
Splunk Employee

Note: This question is about the package manifest file (NOT the bucket manifest file).

Scenario: I accidentally deleted my package manifest files after upgrading between versions.
e.g. Upgraded from version 6.4.1 to 6.4.3.
Install directory = /opt/splunk
Action = I accidentally deleted both manifest from splunk-6.4.1-somenumbers-linux-2.6-x86_64-manifest and splunk-6.4.3-somenumbers-linux-2.6-x86_64-manifest from /opt/splunk/

Error: I am now getting error of this form when I start splunk;
"Cannot find any course of hashes. Manifest file '(null)' not present?"

How can I regenerate these?

Labels (1)
1 Solution

bohanlon_splunk
Splunk Employee
Splunk Employee

Workaround: If use the same install package (e.g. 6.4.3) used in upgrade, install in a temp area. Then, just grab the manifest file in the temp area. It should be the same as the one you want to recover.

Example:
-Your "live" instance (i.e. the one you deleted the file from) is in /opt/splunk
-Install a "new" instance to /opt/splunk2
-Grab the manifest file from /opt/splunk2, copy it into /opt/splunk
-Start /opt/splunk and observe error goes away and is replaced with message of the form:
"Validating installed files against hashes from '/opt/splunk/splunk-versionnumber-ID-platform-manifest'. All installed files intact"

View solution in original post

bohanlon_splunk
Splunk Employee
Splunk Employee

Workaround: If use the same install package (e.g. 6.4.3) used in upgrade, install in a temp area. Then, just grab the manifest file in the temp area. It should be the same as the one you want to recover.

Example:
-Your "live" instance (i.e. the one you deleted the file from) is in /opt/splunk
-Install a "new" instance to /opt/splunk2
-Grab the manifest file from /opt/splunk2, copy it into /opt/splunk
-Start /opt/splunk and observe error goes away and is replaced with message of the form:
"Validating installed files against hashes from '/opt/splunk/splunk-versionnumber-ID-platform-manifest'. All installed files intact"

Get Updates on the Splunk Community!

Splunk Training for All: Meet Aspiring Cybersecurity Analyst, Marc Alicea

Splunk Education believes in the value of training and certification in today’s rapidly-changing data-driven ...

Investigate Security and Threat Detection with VirusTotal and Splunk Integration

As security threats and their complexities surge, security analysts deal with increased challenges and ...

Observability Highlights | January 2023 Newsletter

 January 2023New Product Releases Splunk Network Explorer for Infrastructure MonitoringSplunk unveils Network ...