Getting this message "File Integrity checks found files that did not match the system-provided manifest. See splunkd.log for details."
Anyone seen this before? Any idea what it's about?
Seeing this in the splunkd.log:
09-24-2016 11:12:26.554 -0400 WARN InstalledFilesHashChecker - An installed file="/opt/splunk/etc/log.cfg" did not pass hash-checking due to reason="content mismatch"
I'm using log-local.cfg so I'm wondering what I messed up here.
Using Splunk 6.5 (clustered environment) here and also getting the messages.
At https://[your_splunk]:8089/services/server/status//installed-file-integrity you can find an overview of the files that did not match the system-provided manifest.
Looks like default files that were changed.
is there a search head cluster involved?
SHC is being used and it appears this is only happening there now. Checking if the config over there is good. Running on 6.5.0.
Is there already a solution to this error? I'm getting the same messages and the splunkd.log is not informative.