Splunk Enterprise Security

Upload failed: Package is too large, must be less than 512 MB

Elbald97
Explorer

Hi,

I am trying to upgrade my ES app to 8.1.1 but when i try to upload i have issue : 

Upload failed: Package is too large, must be less than 512 MB

Howerver i already have max_upload_size = 2048 in my web.conf setting file like this :

[settings]
max_upload_size = 2048

Does anyone know what is happening in my case ?

Thank you.

Labels (1)
0 Karma

livehybrid
SplunkTrust
SplunkTrust

Hi @Elbald97 

Can you please confirm that you have restarted the SH since making these changes to the web.conf?

Please can you validate the output of btool to check that the setting has been set correctly:

$SPLUNK_HOME/bin/splunk cmd btool web list --debug settings

🌟 Did this answer help you? If so, please consider:

  • Adding karma to show it was useful
  • Marking it as the solution if it resolved your issue
  • Commenting if you need any clarification

Your feedback encourages the volunteers in this community to continue contributing

0 Karma

Elbald97
Explorer

There's the output of your btool command :

D:\Splunk\etc\system\local\web.conf   [settings]
D:\Splunk\etc\system\default\web.conf SSOMode = strict
D:\Splunk\etc\system\default\web.conf acceptFrom = *
D:\Splunk\etc\system\default\web.conf allowSslCompression = false
D:\Splunk\etc\system\default\web.conf allowSslRenegotiation = true
D:\Splunk\etc\system\default\web.conf allowSsoWithoutChangingServerConf = 0
D:\Splunk\etc\system\default\web.conf allow_insecure_libraries_toggle = true
D:\Splunk\etc\system\default\web.conf allowableTemplatePaths =
D:\Splunk\etc\system\default\web.conf appNavReportsLimit = 500
D:\Splunk\etc\system\default\web.conf appServerPorts = 8065
D:\Splunk\etc\system\default\web.conf appServerProcessLogStderr = false
D:\Splunk\etc\system\default\web.conf busyKeepAliveIdleTimeout = 12
D:\Splunk\etc\system\default\web.conf cacheBytesLimit = 4194304
D:\Splunk\etc\system\default\web.conf cacheEntriesLimit = 16384
D:\Splunk\etc\system\default\web.conf certBasedUserAuthPivOidList = 1.3.6.1.4.1.311.20.2.3, Microsoft Universal Principal Name, Microsoft User Principal Name
D:\Splunk\etc\system\default\web.conf choropleth_shape_limit = 10000
D:\Splunk\etc\system\default\web.conf cipherSuite = ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-SHA384:ECDHE-RSA-AES256-SHA384:ECDHE-ECDSA-AES128-SHA256:ECDHE-RSA-AES128-SHA256
D:\Splunk\etc\system\default\web.conf cookieSameSite = not_specified
D:\Splunk\etc\system\default\web.conf crossOriginSharingHeaders =
D:\Splunk\etc\system\default\web.conf crossOriginSharingPolicy =
D:\Splunk\etc\system\default\web.conf customFavicon =
D:\Splunk\etc\system\default\web.conf dashboard_html_allow_embeddable_content = false
D:\Splunk\etc\system\default\web.conf dashboard_html_allow_iframes = true
D:\Splunk\etc\system\default\web.conf dashboard_html_allow_inline_styles = true
D:\Splunk\etc\system\default\web.conf dashboard_html_wrap_embed = true
D:\Splunk\etc\system\default\web.conf dedicatedIoThreads = 0
D:\Splunk\etc\system\default\web.conf docsCheckerBaseURL = https://quickdraw.splunk.com/help
D:\Splunk\etc\system\default\web.conf ecdhCurves = prime256v1, secp384r1, secp521r1
D:\Splunk\etc\system\default\web.conf embed_footer = splunk>
D:\Splunk\etc\system\default\web.conf embed_uri =
D:\Splunk\etc\system\default\web.conf enableSearchJobXslt = false
D:\Splunk\etc\system\default\web.conf enableSplunkWebClientNetloc = False
D:\Splunk\etc\system\local\web.conf   enableSplunkWebSSL = 1
D:\Splunk\etc\system\default\web.conf enableWebDebug = False
D:\Splunk\etc\system\default\web.conf enable_autocomplete_login = False
D:\Splunk\etc\system\default\web.conf enable_gzip = True
D:\Splunk\etc\system\default\web.conf enable_insecure_login = False
D:\Splunk\etc\system\default\web.conf enable_insecure_pdfgen = False
D:\Splunk\etc\system\default\web.conf enable_pivot_adhoc_acceleration = True
D:\Splunk\etc\system\default\web.conf enable_proxy_write = True
D:\Splunk\etc\system\default\web.conf enable_risky_command_check = true
D:\Splunk\etc\system\default\web.conf enable_risky_command_check_dashboard = true
D:\Splunk\etc\system\default\web.conf enable_secure_entity_move = True
D:\Splunk\etc\system\default\web.conf enabled_decomposers = plot
D:\Splunk\etc\system\default\web.conf engine.autoreload.on = False
D:\Splunk\etc\system\default\web.conf firstTimeLoginMessage =
D:\Splunk\etc\system\default\web.conf firstTimeLoginMessageOption = default
D:\Splunk\etc\system\default\web.conf flash_major_version = 9
D:\Splunk\etc\system\default\web.conf flash_minor_version = 0
D:\Splunk\etc\system\default\web.conf flash_revision_version = 124
D:\Splunk\etc\system\default\web.conf forceHttp10 = auto
D:\Splunk\etc\system\local\web.conf   httpport = 443
D:\Splunk\etc\system\default\web.conf includeSubDomains = false
D:\Splunk\etc\system\local\web.conf   job_default_auto_cancel = 1800
D:\Splunk\etc\system\default\web.conf job_max_polling_interval = 1000
D:\Splunk\etc\system\default\web.conf job_min_polling_interval = 100
D:\Splunk\etc\system\default\web.conf js_logger_mode = None
D:\Splunk\etc\system\default\web.conf js_logger_mode_server_end_point = util/log/js
D:\Splunk\etc\system\default\web.conf js_logger_mode_server_max_buffer = 100
D:\Splunk\etc\system\default\web.conf js_logger_mode_server_poll_buffer = 1000
D:\Splunk\etc\system\default\web.conf jschart_results_limit = 10000
D:\Splunk\etc\system\default\web.conf jschart_series_limit = 100
D:\Splunk\etc\system\default\web.conf jschart_test_mode = False
D:\Splunk\etc\system\default\web.conf jschart_truncation_limit.chrome = 50000
D:\Splunk\etc\system\default\web.conf jschart_truncation_limit.firefox = 50000
D:\Splunk\etc\system\default\web.conf jschart_truncation_limit.ie11 = 50000
D:\Splunk\etc\system\default\web.conf jschart_truncation_limit.safari = 50000
D:\Splunk\etc\system\default\web.conf keepAliveIdleTimeout = 7200
D:\Splunk\etc\system\default\web.conf listenOnIPv6 = no
D:\Splunk\etc\system\default\web.conf log.access_file = web_access.log
D:\Splunk\etc\system\default\web.conf log.access_maxfiles = 5
D:\Splunk\etc\system\default\web.conf log.access_maxsize = 25000000
D:\Splunk\etc\system\default\web.conf log.error_maxfiles = 5
D:\Splunk\etc\system\default\web.conf log.error_maxsize = 25000000
D:\Splunk\etc\system\default\web.conf log.screen = True
D:\Splunk\etc\system\default\web.conf loginBackgroundImageOption = default
D:\Splunk\etc\system\default\web.conf loginCustomBackgroundImage =
D:\Splunk\etc\system\default\web.conf loginCustomLogo =
D:\Splunk\etc\system\default\web.conf loginDocumentTitleOption = default
D:\Splunk\etc\system\default\web.conf loginDocumentTitleText =
D:\Splunk\etc\system\default\web.conf loginFooterOption = default
D:\Splunk\etc\system\default\web.conf loginFooterText =
D:\Splunk\etc\system\default\web.conf loginPasswordHint =
D:\Splunk\etc\system\default\web.conf login_content =
D:\Splunk\etc\system\default\web.conf maxSockets = 0
D:\Splunk\etc\system\default\web.conf maxThreads = 0
D:\Splunk\etc\system\local\web.conf   max_upload_size = 2048
D:\Splunk\etc\system\default\web.conf max_view_cache_size = 1000
D:\Splunk\etc\system\local\web.conf   mgmtHostPort = 10.144.5.24:8089
D:\Splunk\etc\system\default\web.conf minify_css = True
D:\Splunk\etc\system\default\web.conf minify_js = True
D:\Splunk\etc\system\default\web.conf module_dir = share/splunk/search_mrsparkle/modules
D:\Splunk\etc\system\default\web.conf override_JSON_MIME_type_with_text_plain = True
D:\Splunk\etc\system\default\web.conf pdfgen_is_available = 1
D:\Splunk\etc\system\default\web.conf pivot_adhoc_acceleration_mode = Elastic
D:\Splunk\etc\system\default\web.conf preload = false
D:\Splunk\etc\system\local\web.conf   privKeyPath = D:\Splunk\etc\auth\mycerts\Splunk.key
D:\Splunk\etc\system\default\web.conf productMenuLabel = My Splunk
D:\Splunk\etc\system\default\web.conf productMenuUriPrefix = https://splunkcommunities.force.com
D:\Splunk\etc\system\default\web.conf remoteGroupsMatchExact = 0
D:\Splunk\etc\system\default\web.conf remoteGroupsQuoted = False
D:\Splunk\etc\system\default\web.conf remoteUser = REMOTE_USER
D:\Splunk\etc\system\default\web.conf remoteUserMatchExact = 0
D:\Splunk\etc\system\default\web.conf request.show_tracebacks = True
D:\Splunk\etc\system\default\web.conf response.timeout = 7200
D:\Splunk\etc\system\default\web.conf root_endpoint = /
D:\Splunk\etc\system\default\web.conf rss_endpoint = /rss
D:\Splunk\etc\system\default\web.conf sendStrictTransportSecurityHeader = false
D:\Splunk\etc\system\default\web.conf server.thread_pool = 50
D:\Splunk\etc\system\local\web.conf   serverCert = D:\Splunk\etc\auth\mycerts\certnew.cer
D:\Splunk\etc\system\default\web.conf showProductMenu = False
D:\Splunk\etc\system\default\web.conf showUserMenuProfile = False
D:\Splunk\etc\system\default\web.conf show_app_context = true
D:\Splunk\etc\system\default\web.conf simple_error_page = False
D:\Splunk\etc\system\default\web.conf simplexml_dashboard_create_version = 1.1
D:\Splunk\etc\system\local\web.conf   splunkdConnectionTimeout = 3000
D:\Splunk\etc\system\local\web.conf   sslPassword = nothing to see here
D:\Splunk\etc\system\default\web.conf sslVersions = tls1.2
D:\Splunk\etc\system\default\web.conf startwebserver = 1
D:\Splunk\etc\system\default\web.conf staticCompressionLevel = 9
D:\Splunk\etc\system\default\web.conf static_dir = share/splunk/search_mrsparkle/exposed
D:\Splunk\etc\system\default\web.conf static_endpoint = /static
D:\Splunk\etc\system\default\web.conf template_dir = share/splunk/search_mrsparkle/templates
D:\Splunk\etc\system\default\web.conf tools.decode.on = True
D:\Splunk\etc\system\default\web.conf tools.encode.encoding = utf-8
D:\Splunk\etc\system\default\web.conf tools.encode.on = True
D:\Splunk\etc\system\default\web.conf tools.encode.text_only = False
D:\Splunk\etc\system\default\web.conf tools.sessions.forceSecure = False
D:\Splunk\etc\system\default\web.conf tools.sessions.httponly = True
D:\Splunk\etc\system\default\web.conf tools.sessions.on = True
D:\Splunk\etc\system\default\web.conf tools.sessions.restart_persist = True
D:\Splunk\etc\system\default\web.conf tools.sessions.secure = True
D:\Splunk\etc\system\default\web.conf tools.sessions.storage_path = var/run/splunk/sessions
D:\Splunk\etc\system\default\web.conf tools.sessions.storage_type = file
D:\Splunk\etc\system\local\web.conf   tools.sessions.timeout = 30
D:\Splunk\etc\system\default\web.conf trap_module_exceptions = True
D:\Splunk\etc\system\default\web.conf ui_inactivity_timeout = 60
D:\Splunk\etc\system\default\web.conf updateCheckerBaseURL = https://quickdraw.splunk.com/js/
D:\Splunk\etc\system\default\web.conf use_future_expires = True
D:\Splunk\etc\system\default\web.conf userRegistrationURL = https://www.splunk.com/page/sign_up
D:\Splunk\etc\system\default\web.conf verifyCookiesWorkDuringLogin = True
D:\Splunk\etc\system\default\web.conf x_frame_options_sameorigin = True
0 Karma

isoutamo
SplunkTrust
SplunkTrust
And you have restarted this node after this change? Btool shows only what you have configured on disk but not what your currently running splunk process is using.
If you want to see what are parameters in running splunkd you should use "splunk show config web" and look if max_upload_size is there. If not then it's using default value.
0 Karma

Elbald97
Explorer

Yes, max_upload_size = 2048 setting was already been present for a very long time, so the server had already restarted in the meantime.

0 Karma
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

Splunk Decoded: Business Transactions vs Business IQ

It’s the morning of Black Friday, and your e-commerce site is handling 10x normal traffic. Orders are flowing, ...

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...