Installation

Splunk upgrade: splunk_monitoring_console has overriding copies of alerts.xml/dashboards.xml/reports.xml

whrg
Motivator

Hello Splunkers,

I just upgraded Splunk from 7.2.5.1 to 7.2.6 on CentOS 7. The migration process gave the following warning:

Checking for possible UI view conflicts...
 App "splunk_monitoring_console" has an overriding copy of the "alerts.xml" view, thus the new version may not be in effect. location=/opt/splunk/etc/apps/splunk_monitoring_console/default/data/ui/views
 App "splunk_monitoring_console" has an overriding copy of the "dashboards.xml" view, thus the new version may not be in effect. location=/opt/splunk/etc/apps/splunk_monitoring_console/default/data/ui/views
 App "splunk_monitoring_console" has an overriding copy of the "reports.xml" view, thus the new version may not be in effect. location=/opt/splunk/etc/apps/splunk_monitoring_console/default/data/ui/views

What does this mean exactly? Where can I find this new version? Or can I ignore this warning?

When I search for alerts.xml then I only find one file:

$ find /opt/splunk/etc/apps/splunk_monitoring_console/ -name '*alerts.xml*'
/opt/splunk/etc/apps/splunk_monitoring_console/default/data/ui/views/alerts.xml

I haven't used or configured the monitoring console on this Splunk server.

 

EDIT 2021-03-19: I just upgraded from 8.1.2 to 8.1.3 on a relatively new Splunk server. I am still seeing these warning messages.

Labels (1)

ccloutier_splun
Splunk Employee
Splunk Employee

Old post, but just wanted to mention I'm also still seeing this (Splunk 8.2.6 to Splunk 9.0.0).  The message implies this might cause a conflict/issue... we might want to either improve it or document what needs to be corrected/checked from the user's part?

0 Karma

rvany
Communicator

It's the same with 7.2.7. Actually I found three files for every name out of dashboards.xml, alerts.xml and reports.xml

192d5302d90ac263139a379f11fa0236b167f3b1198590d383324ee683cc035a  etc/apps/search/default/data/ui/manager/dashboards.xml
76af1d8adf98be3448cc1643208d62adf6c41ad6d6385aab946e19a926409020  etc/apps/search/default/data/ui/views/dashboards.xml
76af1d8adf98be3448cc1643208d62adf6c41ad6d6385aab946e19a926409020  etc/apps/splunk_monitoring_console/default/data/ui/views/dashboards.xml

These files, paths and sums are the same in 7.1.1, 7.2.7 and 7.3.0 (and presumably at least all the versions in between).

The sha256-sums are the same as contained in the manifest file in /opt/splunk so everything seems ok. Still some official statement or opinion would be great.

Also I found some reference to the same "errors" in a 2016-posting regarding v6.4.0.

In v6.2.0 when the DMC was introduced, there are only the two files inside the search app but already with the same sha256sum.

The only reference to the dashboards.xml file is in default/data/ui/nav/default.prod_lite.xml which maybe belongs to an installation of Splunk Light(?).

I did a second run of the migration check after renaming dashboards.xml to my_dashboards.xml and it disappeared from the list of "UI view conflicts".

sloshburch
Splunk Employee
Splunk Employee

Thank you for such a detailed addition!

0 Karma

sloshburch
Splunk Employee
Splunk Employee

Great question! I've also been getting this for years and ignored it but now that you asked I want to see if I can hunt down an official answer.

0 Karma
Get Updates on the Splunk Community!

Introducing Edge Processor: Next Gen Data Transformation

We get it - not only can it take a lot of time, money and resources to get data into Splunk, but it also takes ...

Take the 2021 Splunk Career Survey for $50 in Amazon Cash

Help us learn about how Splunk has impacted your career by taking the 2021 Splunk Career Survey. Last year’s ...

Using Machine Learning for Hunting Security Threats

WATCH NOW Seeing the exponential hike in global cyber threat spectrum, organizations are now striving more for ...