Splunk Enterprise

After license agree show error

MarioLaul
New Member

Hi,

What can i do wrong or why show me this errors?

Software License Agreement 05022017     1 
Do you agree with this license? [y/n]: y

This appears to be your first time running this version of Splunk.
Moving '/opt/splunk/share/splunk/search_mrsparkle/modules.new' to '/opt/splunk/share/splunk/search_mrsparkle/modules'.

An unforeseen error occurred:

    Exception: <type 'exceptions.OSError'>, Value: [Errno 1] Operation not permitted: '/opt/splunk/share/splunk/search_mrsparkle/modules.new'

Traceback (most recent call last):
  File "/opt/splunk/lib/python2.7/site-packages/splunk/clilib/cli.py", line 1153, in main
    parseAndRun(argsList)
  File "/opt/splunk/lib/python2.7/site-packages/splunk/clilib/cli.py", line 1000, in parseAndRun
    retVal = cList.getCmd(command, subCmd).call(argList, fromCLI = True)
  File "/opt/splunk/lib/python2.7/site-packages/splunk/clilib/cli.py", line 280, in call
    return self.func(args, fromCLI)
  File "/opt/splunk/lib/python2.7/site-packages/splunk/clilib/control_api.py", line 30, in wrapperFunc
    return func(dictCopy, fromCLI)
  File "/opt/splunk/lib/python2.7/site-packages/splunk/clilib/_internal.py", line 176, in firstTimeRun
    comm.moveItem(migration.PATH_UI_MOD_NEW, migration.PATH_UI_MOD_ACTIVE)
  File "/opt/splunk/lib/python2.7/site-packages/splunk/clilib/cli_common.py", line 991, in moveItem
    ensureDeletable(src)
  File "/opt/splunk/lib/python2.7/site-packages/splunk/clilib/cli_common.py", line 1028, in ensureDeletable
    os.chmod(oneItem, os.stat(oneItem).st_mode | stat.S_IWRITE)
OSError: [Errno 1] Operation not permitted: '/opt/splunk/share/splunk/search_mrsparkle/modules.new'


Please file a case online at http://www.splunk.com/page/submit_issue
Tags (1)
0 Karma
1 Solution

harsmarvania57
Ultra Champion

As best practice run splunk as "splunk" user so please create splunk user & group on your server, then change /opt/splunk/ permission globally with below command.

chown -R splunk:splunk /opt/splunk/

And start splunk with "splunk" user.

Let me know if you will face any issue.

View solution in original post

0 Karma

harsmarvania57
Ultra Champion

As best practice run splunk as "splunk" user so please create splunk user & group on your server, then change /opt/splunk/ permission globally with below command.

chown -R splunk:splunk /opt/splunk/

And start splunk with "splunk" user.

Let me know if you will face any issue.

0 Karma

rjollet
New Member

It works once I change to the user Splunk
Thank you for your help

0 Karma

rjollet
New Member

I got the same issue using fedora 26. I install Splunk using the .rpm installer

0 Karma

harsmarvania57
Ultra Champion

From which user you are trying to start splunk and also mention splunk version?

0 Karma

rjollet
New Member

version: Splunk 6.6.3
user: rjollet

0 Karma

harsmarvania57
Ultra Champion

Hi,

It looks like some permission issue on server. Can you please let us know how you installed splunk? Which os? And from which user you are trying to start splunk?

Thanks,
Harshil

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Index This | What travels the world but is also stuck in place?

April 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Discover New Use Cases: Unlock Greater Value from Your Existing Splunk Data

Realizing the full potential of your Splunk investment requires more than just understanding current usage; it ...

Continue Your Journey: Join Session 2 of the Data Management and Federation Bootcamp ...

As data volumes continue to grow and environments become more distributed, managing and optimizing data ...