Splunk Search

6.1 upgrade - can't access search macros

Explorer

Upgraded to 6.1 today on a RHEL system. Free Splunk.

Now, when I try to hit my http:///manager/search/admin/macros page, I get this traceback. Interesting that it's complaining about licensing.. that should not be a licensed feature -- it worked fine yesterday =( Guess who should've tarred up his /opt/splunk before pulling the upgrade trigger....

2014-05-06 13:00:44,230 ERROR [53693f6c007fed5c48ac10] __init__:281 - Mako failed to render: Traceback (most recent call last): File "/opt/splunk/lib/python2.7/site-packages/splunk/appserver/mrsparkle/controllers/__init__.py", line 277, in render_template return templateInstance.render(**template_args) File "/opt/splunk/lib/python2.7/site-packages/mako/template.py", line 283, in render return runtime._render(self, self.callable_, args, data) File "/opt/splunk/lib/python2.7/site-packages/mako/runtime.py", line 575, in _render **_kwargs_for_callable(callable_, data)) File "/opt/splunk/lib/python2.7/site-packages/mako/runtime.py", line 607, in _render_context _exec_template(inherit, lclcontext, args=args, kwargs=kwargs) File "/opt/splunk/lib/python2.7/site-packages/mako/runtime.py", line 633, in _exec_template callable_(context, *args, **kwargs) File "/opt/splunk/share/splunk/search_mrsparkle/templates/layout/base.html", line 18, in render_body <%self:render/> File "/opt/splunk/share/splunk/search_mrsparkle/templates/layout/base.html", line 33, in render_render ## define main HTML wrapper File "/opt/splunk/share/splunk/search_mrsparkle/templates/layout/base.html", line 93, in render_pagedoc <%next:body/> File "/opt/splunk/share/splunk/search_mrsparkle/templates/layout/view.html", line 22, in render_body ${next.body()} File "/opt/splunk/share/splunk/search_mrsparkle/templates/layout/admin.html", line 15, in render_body ${next.body()} File "/opt/splunk/share/splunk/search_mrsparkle/templates/admin/index.html", line 96, in render_body % endif File "/opt/splunk/lib/python2.7/site-packages/mako/runtime.py", line 502, in _include_file callable_(ctx, **_kwargs_for_include(callable_, context._orig, **kwargs)) File "/opt/splunk/share/splunk/search_mrsparkle/templates/admin/list.html", line 332, in render_body <%call expr="genListRows(namespace, uiHelper, entities, endpoint_path, kwargs)"/> File "/opt/splunk/share/splunk/search_mrsparkle/templates/admin/_helpers.html", line 745, in render_genListRows % if not writePerm and 'admin' in auth.listUsers()[auth.getCurrentUser()['name']]['roles']: File "/opt/splunk/lib/python2.7/site-packages/splunk/auth.py", line 99, in listUsers return en.getEntities(uri, **kwargs) File "/opt/splunk/lib/python2.7/site-packages/splunk/entity.py", line 129, in getEntities atomFeed = _getEntitiesAtomFeed(entityPath, namespace, owner, search, count, offset, sort_key, sort_dir, sessionKey, uri, hostPath, **kwargs) File "/opt/splunk/lib/python2.7/site-packages/splunk/entity.py", line 222, in _getEntitiesAtomFeed serverResponse, serverContent = rest.simpleRequest(uri, getargs=kwargs, sessionKey=sessionKey, raiseAllErrors=True) File "/opt/splunk/lib/python2.7/site-packages/splunk/rest/__init__.py", line 502, in simpleRequest raise splunk.LicenseRestriction LicenseRestriction: [HTTP 402] Current license does not allow the requested action 
1 Solution

Splunk Employee
Splunk Employee

This appears to be a bug in Splunk 6.1 for Splunk Free. We are currently looking at it. It affects several of the admin pages.

View solution in original post

Splunk Employee
Splunk Employee

See the workaround in the Splunk Answers posting that dshpritz referred to. This defect will be addressed in an accelerated maintenance release for 6.1.

New Member

This does not fix it. I'm running Splunk free on Debian and the error pops up each time I try and access the following:

Data > inputs > Scripts
Data > inputs > UDP
Data > inputs > monitor

0 Karma

Splunk Employee
Splunk Employee

This appears to be a bug in Splunk 6.1 for Splunk Free. We are currently looking at it. It affects several of the admin pages.

View solution in original post

Splunk Employee
Splunk Employee

Yes, this is a slightly different issue from the enterprise one. We are working on a fix for this too and it is likely to be in an accelerated maintenance release.

Path Finder

Seeing the same issue with my free test instance. This issue on our enterprise test instance though seems to have been resolved with the patch listed in those links.

0 Karma

New Member

Having the same issues working with 6.1 upgrade and Data Inputs, Indexes etc... This does not look like the same thing @cberg was identifying.

0 Karma

Path Finder

Using enterprise
Have the same issue on several pages in 'settings' but when im using the local admin user instead of my LDAP user everything seems to work fine.

waiting for a fix, seems to be a bug in 6.1.

0 Karma

SplunkTrust
SplunkTrust
0 Karma

Splunk Employee
Splunk Employee

This appears to be a different though possibly related problem.

0 Karma

Explorer

I'm afraid it isn't just Splunk Free, because our Enterprise installation has similar issues:

  File "/opt/splunk/share/splunk/search_mrsparkle/templates/admin/_helpers.html", line 738, in render_genListRows
    % if role == '*' or role in auth.listUsers()[auth.getCurrentUser()['name']]['roles']:
  File "/opt/splunk/lib/python2.7/UserDict.py", line 23, in __getitem__
    raise KeyError(key)
KeyError: u'cjb'

This is also running on RHEL.

0 Karma