Installation

Splunk upgrade: splunk_monitoring_console has overriding copies of alerts.xml/dashboards.xml/reports.xml

whrg
Motivator

Hello Splunkers,

I just upgraded Splunk from 7.2.5.1 to 7.2.6 on CentOS 7. The migration process gave the following warning:

Checking for possible UI view conflicts...
 App "splunk_monitoring_console" has an overriding copy of the "alerts.xml" view, thus the new version may not be in effect. location=/opt/splunk/etc/apps/splunk_monitoring_console/default/data/ui/views
 App "splunk_monitoring_console" has an overriding copy of the "dashboards.xml" view, thus the new version may not be in effect. location=/opt/splunk/etc/apps/splunk_monitoring_console/default/data/ui/views
 App "splunk_monitoring_console" has an overriding copy of the "reports.xml" view, thus the new version may not be in effect. location=/opt/splunk/etc/apps/splunk_monitoring_console/default/data/ui/views

What does this mean exactly? Where can I find this new version? Or can I ignore this warning?

When I search for alerts.xml then I only find one file:

$ find /opt/splunk/etc/apps/splunk_monitoring_console/ -name '*alerts.xml*'
/opt/splunk/etc/apps/splunk_monitoring_console/default/data/ui/views/alerts.xml

I haven't used or configured the monitoring console on this Splunk server.

 

EDIT 2021-03-19: I just upgraded from 8.1.2 to 8.1.3 on a relatively new Splunk server. I am still seeing these warning messages.

Labels (1)

ccl0utier
Splunk Employee
Splunk Employee

Old post, but just wanted to mention I'm also still seeing this (Splunk 8.2.6 to Splunk 9.0.0).  The message implies this might cause a conflict/issue... we might want to either improve it or document what needs to be corrected/checked from the user's part?

0 Karma

rvany
Communicator

It's the same with 7.2.7. Actually I found three files for every name out of dashboards.xml, alerts.xml and reports.xml

192d5302d90ac263139a379f11fa0236b167f3b1198590d383324ee683cc035a  etc/apps/search/default/data/ui/manager/dashboards.xml
76af1d8adf98be3448cc1643208d62adf6c41ad6d6385aab946e19a926409020  etc/apps/search/default/data/ui/views/dashboards.xml
76af1d8adf98be3448cc1643208d62adf6c41ad6d6385aab946e19a926409020  etc/apps/splunk_monitoring_console/default/data/ui/views/dashboards.xml

These files, paths and sums are the same in 7.1.1, 7.2.7 and 7.3.0 (and presumably at least all the versions in between).

The sha256-sums are the same as contained in the manifest file in /opt/splunk so everything seems ok. Still some official statement or opinion would be great.

Also I found some reference to the same "errors" in a 2016-posting regarding v6.4.0.

In v6.2.0 when the DMC was introduced, there are only the two files inside the search app but already with the same sha256sum.

The only reference to the dashboards.xml file is in default/data/ui/nav/default.prod_lite.xml which maybe belongs to an installation of Splunk Light(?).

I did a second run of the migration check after renaming dashboards.xml to my_dashboards.xml and it disappeared from the list of "UI view conflicts".

sloshburch
Splunk Employee
Splunk Employee

Thank you for such a detailed addition!

0 Karma

sloshburch
Splunk Employee
Splunk Employee

Great question! I've also been getting this for years and ignored it but now that you asked I want to see if I can hunt down an official answer.

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...