Splunk Enterprise

Splunk Enterprise 9.4.0 Integrity Check warning

Alan_Chan
Explorer

After upgrade from 9.3.1 to 9.4.0 in windows platform, there is a warning shows 41 files that did not match.

Alan_Chan_1-1735870315478.png

After validate files, it shows the following query. How to solve the warning?

C:\Program Files\Splunk\bin>splunk.exe validate files
        Validating installed files against hashes from 'C:\Program Files\Splunk\splunk-9.4.0-6b4ebe426ca6-windows-x64-manifest'
Could not open 'C:\Program Files\Splunk\bin/api-ms-win-core-console-l1-1-0.dll': The system cannot find the file specified.

Could not open 'C:\Program Files\Splunk\bin/api-ms-win-core-datetime-l1-1-0.dll': The system cannot find the file specified.

Could not open 'C:\Program Files\Splunk\bin/api-ms-win-core-debug-l1-1-0.dll': The system cannot find the file specified.

Could not open 'C:\Program Files\Splunk\bin/api-ms-win-core-errorhandling-l1-1-0.dll': The system cannot find the file specified.

Could not open 'C:\Program Files\Splunk\bin/api-ms-win-core-file-l1-1-0.dll': The system cannot find the file specified.

Could not open 'C:\Program Files\Splunk\bin/api-ms-win-core-file-l1-2-0.dll': The system cannot find the file specified.

Could not open 'C:\Program Files\Splunk\bin/api-ms-win-core-file-l2-1-0.dll': The system cannot find the file specified.

Could not open 'C:\Program Files\Splunk\bin/api-ms-win-core-handle-l1-1-0.dll': The system cannot find the file specified.

Could not open 'C:\Program Files\Splunk\bin/api-ms-win-core-heap-l1-1-0.dll': The system cannot find the file specified.

Could not open 'C:\Program Files\Splunk\bin/api-ms-win-core-interlocked-l1-1-0.dll': The system cannot find the file specified.

Could not open 'C:\Program Files\Splunk\bin/api-ms-win-core-libraryloader-l1-1-0.dll': The system cannot find the file specified.

Could not open 'C:\Program Files\Splunk\bin/api-ms-win-core-localization-l1-2-0.dll': The system cannot find the file specified.

Could not open 'C:\Program Files\Splunk\bin/api-ms-win-core-memory-l1-1-0.dll': The system cannot find the file specified.

Could not open 'C:\Program Files\Splunk\bin/api-ms-win-core-namedpipe-l1-1-0.dll': The system cannot find the file specified.

Could not open 'C:\Program Files\Splunk\bin/api-ms-win-core-processenvironment-l1-1-0.dll': The system cannot find the file specified.

Could not open 'C:\Program Files\Splunk\bin/api-ms-win-core-processthreads-l1-1-0.dll': The system cannot find the file specified.

Could not open 'C:\Program Files\Splunk\bin/api-ms-win-core-processthreads-l1-1-1.dll': The system cannot find the file specified.

Could not open 'C:\Program Files\Splunk\bin/api-ms-win-core-profile-l1-1-0.dll': The system cannot find the file specified.

Could not open 'C:\Program Files\Splunk\bin/api-ms-win-core-rtlsupport-l1-1-0.dll': The system cannot find the file specified.

Could not open 'C:\Program Files\Splunk\bin/api-ms-win-core-string-l1-1-0.dll': The system cannot find the file specified.

Could not open 'C:\Program Files\Splunk\bin/api-ms-win-core-synch-l1-1-0.dll': The system cannot find the file specified.

Could not open 'C:\Program Files\Splunk\bin/api-ms-win-core-synch-l1-2-0.dll': The system cannot find the file specified.

Could not open 'C:\Program Files\Splunk\bin/api-ms-win-core-sysinfo-l1-1-0.dll': The system cannot find the file specified.

Could not open 'C:\Program Files\Splunk\bin/api-ms-win-core-timezone-l1-1-0.dll': The system cannot find the file specified.

Could not open 'C:\Program Files\Splunk\bin/api-ms-win-core-util-l1-1-0.dll': The system cannot find the file specified.

Could not open 'C:\Program Files\Splunk\bin/api-ms-win-crt-conio-l1-1-0.dll': The system cannot find the file specified.

Could not open 'C:\Program Files\Splunk\bin/api-ms-win-crt-convert-l1-1-0.dll': The system cannot find the file specified.

Could not open 'C:\Program Files\Splunk\bin/api-ms-win-crt-environment-l1-1-0.dll': The system cannot find the file specified.

Could not open 'C:\Program Files\Splunk\bin/api-ms-win-crt-filesystem-l1-1-0.dll': The system cannot find the file specified.

Could not open 'C:\Program Files\Splunk\bin/api-ms-win-crt-heap-l1-1-0.dll': The system cannot find the file specified.

Could not open 'C:\Program Files\Splunk\bin/api-ms-win-crt-locale-l1-1-0.dll': The system cannot find the file specified.

Could not open 'C:\Program Files\Splunk\bin/api-ms-win-crt-math-l1-1-0.dll': The system cannot find the file specified.

Could not open 'C:\Program Files\Splunk\bin/api-ms-win-crt-multibyte-l1-1-0.dll': The system cannot find the file specified.

Could not open 'C:\Program Files\Splunk\bin/api-ms-win-crt-private-l1-1-0.dll': The system cannot find the file specified.

Could not open 'C:\Program Files\Splunk\bin/api-ms-win-crt-process-l1-1-0.dll': The system cannot find the file specified.

Could not open 'C:\Program Files\Splunk\bin/api-ms-win-crt-runtime-l1-1-0.dll': The system cannot find the file specified.

Could not open 'C:\Program Files\Splunk\bin/api-ms-win-crt-stdio-l1-1-0.dll': The system cannot find the file specified.

Could not open 'C:\Program Files\Splunk\bin/api-ms-win-crt-string-l1-1-0.dll': The system cannot find the file specified.

Could not open 'C:\Program Files\Splunk\bin/api-ms-win-crt-time-l1-1-0.dll': The system cannot find the file specified.

Could not open 'C:\Program Files\Splunk\bin/api-ms-win-crt-utility-l1-1-0.dll': The system cannot find the file specified.

Could not open 'C:\Program Files\Splunk\bin/ucrtbase.dll': The system cannot find the file specified.

 

Labels (1)
0 Karma

Foolish_Rogue
Engager

Hello, I received this same error in upgrading from 9.3 to 9.4 versions of Splunk Enterprise.  I found a helpful article posted by Splunk Support that resolved my issue.  Please see the link below.

 

http://splunk.my.site.com/customer/s/article/File-Integrity-checks-found-41-files-that-did-not-match... 

0 Karma

rishabhshah
Path Finder

You can disable those integrity checks as well if your Splunk environment is working fine after upgrade. To disable the file integrity check, edit the installed_files_integrity setting in the limits.conf file

0 Karma

dural_yyz
Motivator

Which Windows OS?

0 Karma

Alan_Chan
Explorer

The Windows version is Windows 11 Pro 23H2

0 Karma

dural_yyz
Motivator

Please keep in mind that Splunk docs no longer specify support for Windows 10/11, only specifically server version.  Something may have impacted the install extraction process.

0 Karma

kiran_panchavat
SplunkTrust
SplunkTrust

@Alan_Chan

I have upgraded Splunk from version 9.3.1 to 9.4.0 on a Linux platform and observed this warning. However, Splunk is functioning properly, and no issues have been noticed post-upgrade. I believe the warning can be safely removed. 

I hope this helps, if any reply helps you, you could add your upvote/karma points to that reply, thanks.

Did this help? If yes, please consider giving kudos, marking it as the solution, or commenting for clarification — your feedback keeps the community going!
0 Karma

Alan_Chan
Explorer

The Splunk Enterprise is running in the customer environment, and I can't simply disable the integrity check and claim that it has no impact on Splunk's functionality

marnall
Motivator

I don't have Splunk running on a windows machine so I can't comment on whether those files are necessary or not, but if you find that your splunk installation is working well without those files and then you would like to just disable the warning, then you can remove the related lines in the manifest file in your splunk directory to disable the integrity checking on them.

0 Karma
Get Updates on the Splunk Community!

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...

Announcing the Migration of the Splunk Add-on for Microsoft Azure Inputs to ...

Announcing the Migration of the Splunk Add-on for Microsoft Azure Inputs to Officially Supported Splunk ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI! Discover how Splunk’s agentic AI ...